<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Cyber Solicitor]]></title><description><![CDATA[Covering the intersection between law, technology and society.]]></description><link>https://www.thecybersolicitor.com</link><image><url>https://substackcdn.com/image/fetch/$s_!T4HV!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png</url><title>The Cyber Solicitor</title><link>https://www.thecybersolicitor.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 21 Apr 2026 06:12:11 GMT</lastBuildDate><atom:link href="https://www.thecybersolicitor.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Mahdi Assan]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[thecybersolicitor@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[thecybersolicitor@substack.com]]></itunes:email><itunes:name><![CDATA[Mahdi Assan]]></itunes:name></itunes:owner><itunes:author><![CDATA[Mahdi Assan]]></itunes:author><googleplay:owner><![CDATA[thecybersolicitor@substack.com]]></googleplay:owner><googleplay:email><![CDATA[thecybersolicitor@substack.com]]></googleplay:email><googleplay:author><![CDATA[Mahdi Assan]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[AI slop is a choice]]></title><description><![CDATA[It is your job to keep the human in the machine]]></description><link>https://www.thecybersolicitor.com/p/ai-slop-is-a-choice</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-slop-is-a-choice</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 17 Apr 2026 08:02:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5n1T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5n1T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5n1T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5n1T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg" width="1456" height="996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:996,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:225158,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/194446873?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5n1T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I changed my mind on AI. And you probably should too.</p><p>When ChatGPT first came out and was blowing up, I wasn&#8217;t all that impressed. I tried it a few times and thought it was cool but did not see the value in talking to a chatbot apart from asking random useless questions.</p><p>I had come across these GPTs before. They came up during some research I was doing on how security and intelligence agencies were using AI for their operations. A <a href="https://static.rusi.org/ai-national-security-final-web-version.pdf">2020 report</a> by the Royal United Services Institute detailed how AI could be used by such agencies for &#8216;cognitive automation&#8217; in which AI can help analyse large volumes of data. It mentioned in this context OpenAI&#8217;s GPT-2 and how this model could be used for language analytics purposes, including for analysing transcriptions of captured audio. But not much else was written on the matter, and so I never looked into these language models any further at the time.</p><p>And then a short time later in 2022 when a wave of generative products came crashing in, including DALL-E 2, Midjourney and of course ChatGPT, I was wholly sceptical. Suddenly there was lots of talk about artificial general intelligence, AI safety, the prospect of AI taking all of our jobs and so on. But my understanding and interest remained fairly limited, and so I interpreted much of this as hype that should not be taken all that seriously.</p><p>And this is the attitude I had for a long time, barely using the tools whilst I stood to the side and criticised. I would read about AI but hardly use it myself.</p><p>It is the classic move for most people working in tech law and policy - dealing with the object of that to be governed at arms length and with only a minimal understanding of its mechanics. It is like the difference between static and dynamic analysis of an application. Legal professionals tend to be stuck constantly doing the former and therefore largely ignorant to how these AI systems work in real-world environments.</p><p>And there is little motivation to see it any other way. Legal experts are relied on for their risk-aversion and being able to see the worst case scenarios so that they can be mitigated against or avoided. Seeing AI this way is not particularly inspirational and certainly does not encourage one to actually want to test out these systems for themselves.</p><p>Eventually my passivity passed though and I decided that instead of sitting on the sidelines, I was going to get stuck in.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MSd8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MSd8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MSd8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2666803,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/194446873?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MSd8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is when I started experimenting with AI for tasks that I wanted to either offload or make much easier to do.</p><p>Among these experimentations included building an AI workflow for GDPR vendor reviews, a rather tedious and time-consuming task. I was able to work out the appropriate instructions and harnessing, with safeguards for reducing hallucinations whilst also making verification straightforward.</p><p>At this point I was no longer just talking about AI from a distance. I was enhancing my understanding through hands-on experience, something most legal professionals would not think to do.</p><p>The challenge I have ran into now, however, is not a technical one. Using AI is something I feel far more comfortable with now, and my experimentation with it will no doubt continue.</p><p>The challenge I now face is whether my increased use of AI is actually a good thing.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-slop-is-a-choice">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The quiet principles behind quality AI adoption]]></title><description><![CDATA[Slow down. Think first. Then build.]]></description><link>https://www.thecybersolicitor.com/p/the-quiet-principles-behind-quality</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-quiet-principles-behind-quality</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 10 Apr 2026 08:01:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5Ana!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Ana!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Ana!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Ana!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg" width="1456" height="996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:996,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:360749,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/193490632?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Ana!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>People often get distracted by the shiny new object.</p><p>The evidence that this is happening with AI is undeniable at this point.</p><p>CEOs and senior leaders get dazzled by the stories told by the frontier labs. Predictions are abound that these AI systems are so capable that they will replace <em>all</em> knowledge workers. New models or features get released and SaaS stocks tank. Some companies go as far as engaging in massive layoffs, thinking that large chunks of the workforce can be replaced by an army of cheaper AI agents.</p><p>AI has many advantageous of course. Despite being a legal professional and trained to see things with a more risk-averse eye, I can still see the various ways that AI can boost productivity, help make sense of unstructured information and uncover blindspots in my thinking.</p><p>But I can also see that AI does not solve all problems at once. It is not a silver bullet.</p><p>Like any other piece of technology, AI has its limitations. Hallucinations, getting stuck in recursive loops and all the quirks that come with operating large, non-deterministic systems programmed implicitly.</p><p>We are still in the very early days in terms of AI diffusion and adoption. Most people are not heavy users of AI, and therefore a minority know how to use it well.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7p64!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7p64!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7p64!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7p64!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg" width="1280" height="1486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1486,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:242107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/193490632?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7p64!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7p64!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And it is because of this that most people do not understand what AI is and what it is not.</p><p>It is not this magical machine that you can one-line prompt and it will immediately give you everything you need.</p><p>Yet some people basically have this perception of AI, probably because of the way it gets hyped by its developers. This mistaken perception leads to AI being treated as a solution looking for a problem.</p><p>The erroneous thinking here is something like this:</p><blockquote><p><em>Because AI is apparently so amazing, and because everyone is using it, then surely I or our organisation can also use and benefit from it too?</em></p></blockquote><p>This is a trap driven by FOMO and exacerbated by clouded judgment.</p><p>However, this is not just a case of misunderstanding the technology that AI is. I think there are other important aspects at play here.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-quiet-principles-behind-quality">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Fragmented surveillance at scale]]></title><description><![CDATA[How do data rights cope with doorbell cameras and recording glasses?]]></description><link>https://www.thecybersolicitor.com/p/fragmented-surveillance-at-scale</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/fragmented-surveillance-at-scale</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 03 Apr 2026 08:00:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tqN7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tqN7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tqN7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 424w, https://substackcdn.com/image/fetch/$s_!tqN7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 848w, https://substackcdn.com/image/fetch/$s_!tqN7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 1272w, https://substackcdn.com/image/fetch/$s_!tqN7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tqN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2831805,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/192522991?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tqN7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 424w, https://substackcdn.com/image/fetch/$s_!tqN7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 848w, https://substackcdn.com/image/fetch/$s_!tqN7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 1272w, https://substackcdn.com/image/fetch/$s_!tqN7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb3025de-ec14-42b8-95a7-b0a68ea27da4_2560x1707.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Reihaneh Golpayegani / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>It is becoming much easier for individuals to monitor each other at scale.</p><p>I remember a time when doorbell cameras were a rarity, and were even perhaps met with a natural reaction to mediums designed to capture data about you. Unnecessary, excessive, creepy.</p><p>But now as I walk through most neighbourhoods, doorbell cameras are everywhere. It is becoming rare to see a house that does not have one of these devices slapped onto or next to a front door, gawking at you as you walk past.</p><p>What has happened here? How have these devices, once frowned upon, now become almost an imperative for every household?</p><p>I think this trend reveals something interesting about how people view privacy.</p><p>Many people often acquiesce to convenience, despite the preferences, values or ethics that they might claim to hold. This is ultimately context-dependent, but it is fair to say that people&#8217;s boundaries are dynamic such that they may be willing to buy particular products or engage in certain activities which they may have previously disregarded.</p><p>We can observe across many different domains in our digital age. Social media is an obvious one, and AI chatbots are probably the next.</p><p>But there is something particularly intriguing that the rise of doorbell cameras reveal about the attitudes people have toward privacy, whether their own or that of others.</p><p>One norm that seems to be emerging is that if one places themselves in some sort of public realm or area, whether physical or digital, then the collection of their data is basically free game.</p><p>There is sometimes a perception that if a person has a public social media account, and posts content on that account that essentially anybody can view, the collection and use of that data is completely legitimate. If it is public, and anybody can see it, then surely anybody can use it? If you didn&#8217;t want people to use your content, then don&#8217;t post it in a public space.</p><p>But this misses an important point about data rights and their purpose. That data are public may mean that the level of privacy one can expect is reduced, but it is not zero and, in any case, the publicity of the data cannot be taken as some sort of implied consent for its endless use by others.</p><p>This applies in the physical domain too. Just because you record someone who happens to walk past your property does not mean you can do whatever you want with that recording.</p><p>The use of data ought to be dictated by the legitimacy and necessity of its use, as well as be used only for that purpose and accordingly limited in term of its nature and volume.</p><p>These principles I think are being respected by individuals less and less. We can talk about certain companies and the poor data practices that they follow. But at an individual level, I think the respect for privacy is getting weaker.</p><p>And maybe doorbell cameras are not the strongest example to demonstrate this with. There are some people who simply use them as a deterrent, and do not even bother to use the full range of their functionalities or might even admit if questioned that the damn thing doesn&#8217;t even work (or they don&#8217;t know how to work it).</p><p>So another perhaps more consequential piece of privacy-invasive hardware to cite here is recording glasses. A surveillance device dressed as a fashion accessory.</p><p>These are devices that enable a more ambient form of passive data collection. They can basically record anything you see in any location that you go.</p><p>The same emerging cultural dynamics are at play here: if you are in a public space where someone happens to be filming with their recording glasses, that is on you.</p><p>The thing about both doorbell cameras and recording glasses is that it takes away the agency of the surveilled in terms of whether their data are captured. They have no choice - if someone has one of these devices and you enter their periphery, then your data is collected. No opportunity to consent, to know what it might be used for or who it might be shared with. It is already in the hands of someone else.</p><p>And people may not even know that this is happening. The indicators that someone is wearing recording glasses are subtle and very difficult to spot at a distance.</p><p>Such devices contribute to a sort of fragmented surveillance at scale.</p><p>The question is whether data rights are built for this.</p><p>I think our legal frameworks were mostly built to deal with more centralised forms of surveillance, initially by states but then by companies. You regulated singular entities carrying out processing activities concerning lots of people; an easily identifiable bottleneck that can be addressed in one swoop.</p><p>But when the means of surveillance are fragmented across the population, giving individuals the ability to monitor lots of other people at scale, what recourse do those being surveilled have?</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/fragmented-surveillance-at-scale?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/fragmented-surveillance-at-scale?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/fragmented-surveillance-at-scale">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[What really comes with ads inside ChatGPT]]></title><description><![CDATA[The monetisation of cognition is here]]></description><link>https://www.thecybersolicitor.com/p/what-really-comes-with-ads-inside</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/what-really-comes-with-ads-inside</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 27 Mar 2026 09:00:45 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/24b60325-9fee-4fb6-9458-b1969bcb4809_3186x1794.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Technology is not neutral.</p><p>The way a piece of technology is built and and how it works is always downstream of the incentives, opinions and choices of its builders and the context they are operating in. This is an obvious point that is often forgotten.</p><p>That technology is not neutral sometimes allows us to trace the impacts of technology back to the actions and thinking of its builders. Understanding the incentives, opinions and choices of these people is key for understanding why technology develops in a certain way or why it has certain impacts.</p><p>This backdrop is important when thinking about how the internet and digital products and services look today. Many of the products and services we have become accustomed to over the years are available for no upfront monetary cost for users. Search engines, social media platforms, and now AI chatbots all have free versions that essentially anyone with an internet connection can use.</p><p>But much of this free internet as we know it has been powered by ads. Google was one of the first companies to really work out how to build a business model that enabled its product to be free to use whilst still generating revenue. It figured out how to make revenue-generation essentially invisible to users yet still providing and updating a useful product.</p><p>And now OpenAI is doing the same by introducing ads to ChatGPT. The AI provider is currently rolling this out to ChatGPT free and Go users, with advertisers <a href="https://www.reuters.com/business/media-telecom/openai-expand-ads-chatgpt-all-free-low-cost-users-information-reports-2026-03-21/">reportedly</a> committing between $50,000 to $100,000 in ad spend.</p><p>The reasoning for implementing ads is similar to the constraints that Google and others had to face in the journey to profitability. However, I think the nature of its implementation for AI systems like ChatGPT will be different.</p><p>OpenAI&#8217;s pivot to ads is a sign of the reality they face - they need a reliable way to generate revenue. The company needs a way to cope with the immense increases in infrastructure spend on top of the high level of investments it has secured over the years. It would seem that subscriptions and enterprise deals are not sufficient.</p><p>Maybe OpenAI&#8217;s mission is still to build AGI eventually. But it may not survive to achieve this feat unless it develops a workable business model in the meantime to fund and power its efforts toward this grand milestone.</p><p>Google faced a similar problem in its early days. It bulked up its ad businesses due to pressure from investors and the need to somehow make money from its product.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;50733dff-5a3e-4d33-a9e2-7da475dcae81&quot;,&quot;caption&quot;:&quot;Bubbles pop eventually.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;This is what happens when the AI bubble pops&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-12-05T09:02:24.225Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:179728534,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>When it comes to ads on Google, these are aligned to inferences made about users based on what the queries they enter into the search engine. On social media platforms, these inferences are derived from a wider range of user activity, including the people they follow and the content they engage with.</p><p>Ads in AI chatbots will be aligned to something different, something much deeper and higher-resolution than the data points that search engines or social media platforms can utilise.</p><p>AI ads will be aligned to a user&#8217;s actual thoughts, something very distinct from the search queries, social graphs and engagement metrics of yesteryears.</p><p>In this newsletter I go through this argument and explore:</p><ul><li><p>How AI systems sit closer to user intentions than any other system</p></li><li><p>Why AI ads are inevitable</p></li><li><p>What happens to data rights</p></li></ul>
      <p>
          <a href="https://www.thecybersolicitor.com/p/what-really-comes-with-ads-inside">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[What you missed from Anthropic's fight with Trump]]></title><description><![CDATA[The power inversion, illusory guardrails and state surveillance]]></description><link>https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 20 Mar 2026 09:02:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Sy6k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sy6k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sy6k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1085013,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/191517288?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Sy6k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image from <em><a href="https://www.yahoo.com/news/articles/anthropic-pentagon-showdown-drawing-silicon-153122475.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAALYWM5ONYvWL0FQUC8Mo71QrsNs3arzlsbVM1e-FZfAie0_pm395Z2Is7MEyZtLXh1XnG9LqPCP_qqcMTUTeNNW1V6NRlrYPkJbwSCGwUqOpQnVhhB31q3em51ltZAlA2OyYDWm7CG3rtEE4pvXCWYsLYLgA8BnKAEYw2_vfv58F">Yahoo! News</a></em></figcaption></figure></div><p>The conflict between Anthropic and the US Government is a big deal, but not in the way that most people think.</p><p>It is not just a contract disagreement or an AI ethics debate. I think it represents something bigger.</p><p>To give a very simplified overview of what happened between Anthropic and the US Department of War:</p><ul><li><p>In mid&#8209;2025, the Pentagon awards large multi&#8209;year AI contracts (up to about 200 million dollars each) to several firms, including Anthropic, to help build out military AI capabilities</p></li><li><p>As the government builds an internal generative&#8209;AI ecosystem (often described as GenAI.mil), negotiations focus on how broadly military users can deploy Anthropic&#8217;s models</p></li><li><p>The Department insists on &#8220;all lawful uses&#8221; language; Anthropic agrees except for two red&#8209;lines: no mass domestic surveillance and fully autonomous lethal weapons - these safety guardrails become the core of the dispute</p></li><li><p>The administration publicly hardens its stance, promoting an &#8220;AI&#8209;first&#8221; warfighting strategy and rebranding rhetoric around the Pentagon as the &#8220;Department of War,&#8221; signaling a more aggressive doctrine</p></li><li><p>In late February 2026, defense officials issue Anthropic an ultimatum: remove the contractual bans on mass domestic surveillance and autonomous lethal weapons or risk severe consequences</p></li><li><p>Anthropic refuses before the deadline, reiterating that those uses are outside what its models can safely or ethically support</p></li><li><p>After talks break down, the administration orders federal agencies to stop using Anthropic&#8217;s AI tools and begin transitioning away over several months</p></li><li><p>The Department of War designates Anthropic a &#8220;supply chain risk to national security,&#8221; a label normally associated with foreign adversaries; this effectively bars defense contractors from using Anthropic products in government work</p></li><li><p>Anthropic publicly rejects the designation as unlawful and politically motivated, arguing it is being punished for insisting on safety guardrails</p></li><li><p>In March 2026, Anthropic files suit against the U.S. government, challenging the supply&#8209;chain&#8209;risk classification and seeking to protect its right to limit high&#8209;risk military uses of its AI</p></li></ul><p>I&#8217;ve read good takes on the situation by various writers here on Substack. You shoudl also check out the coverage from <a href="https://insights.priva.cat/p/anthropic-will-probably-survive-trumps">Privacat</a>, <a href="https://jasmi.news/p/ai-pentagon">Jasmine Sun</a> and <a href="https://www.hyperdimensional.co/p/clawed">Dean W. Ball</a>, just to name a few.</p><p>When reading all of this commentary, what came to mind was an overarching set of themes that could be threaded together.</p><p>In fact, the fight between Anthropic and USG felt quite familiar to me. My gateway into tech law and policy was state surveillance and the Snowden revelations in 2013. I became fascinated with the way technology and law collided together, a convergence of forces that advance and organise our societies.</p><p>This for me signalled one of the most important questions of our time (for which I have quoted Jamie Susskind, author of <em>Future Politics: Living Together in a World Transformed by Tech</em>, many times before because he puts it far me eloquently than I have):</p><blockquote><p><em>To what extent should builders of powerful digital systems be concerned with data rights, and what does this look like in practice?</em></p></blockquote><p>What I see here with <em>Anthropic vs USG</em> are three converging patterns:</p><ol><li><p>The state depends on private tech firms more than the reverse, and this will only continue in the future</p></li><li><p>Safety guardrails for LLMs are somewhat of a technical illusion that creates a big governance gap</p></li><li><p>LLMs could bring surveillance, whether by the state or other entities, to a whole new level</p></li></ol><p>In this newsletter, I cover these three conversing ideas (power inversion, safety guardrails and the evolution in surveillance) and how <em>Anthropic vs USG</em> is a glimpse at the defining tension of the 21st century.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This is why your AI governance policy sucks]]></title><description><![CDATA[And this is how to fix it]]></description><link>https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 13 Mar 2026 09:02:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bf3f1df2-75ab-445d-bf52-73293794a163_960x554.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Lots of organisations are yet to sort out their AI governance.</p><p>Many might be excited about adopting AI, or anxious that not doing so will leave them far behind the competition.</p><p>So they start ideating and brainstorming about how these systems could be used to improve internal processes or create better products for customers.</p><p>In doing so, some will have the foresight to think about the importance of governance - there should be a focus on building the thing the right way and not just building anything.</p><p>But then this is where organisations make the biggest mistake when starting their AI governance journey.</p><p>They start by drafting a policy.</p><p>Maybe they look for a template online. Or maybe they even use AI to generate one for them.</p><p>They draft it, put is somewhere on their intranet, and then that&#8217;s it. They think they have completed governance and now they can just focus on building or using their AI systems however they like.</p><p>Simple, right?</p><p>Well not really.</p><p>Policies are just words. They might represent the principles, rules, guardrails and standards you want to follow when building or using AI. But these things alone are simply not enough.</p><p>These things just represent intentions.</p><p>And while crystallising intentions in a formal document that everyone agrees to follow is important, starting your governance journey with a policy means that your policy will not be:</p><ol><li><p>Aligned with how your organisation is using and/or developing AI systems</p></li><li><p>Backed up by practical measures that implement the policy</p></li><li><p>Actually known, understood and respected by staff</p></li></ol><p>Without these things, your AI governance framework just never really gets going.</p><p>If you want to get AI governance right, do not start by writing a policy. You need to do other things alongside the drafting of the policy that will make your AI governance framework actually work.</p><p>You need to at least:</p><ul><li><p>Understand the state of play in your organisation</p></li><li><p>Develop an AI strategy</p></li><li><p>Build and implement the right measures (organisational, technical and legal)</p></li><li><p>Establish feedback loops</p></li></ul><p>In this newsletter, I go through each of these steps, including why they are needed and what they entail. If you like this content, make sure to share it with others who might also benefit.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Tasteful AI governance]]></title><description><![CDATA[Yes, there is such a thing. And this is what it looks like.]]></description><link>https://www.thecybersolicitor.com/p/tasteful-ai-governance</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/tasteful-ai-governance</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 06 Mar 2026 09:01:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Mviz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mviz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mviz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 424w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 848w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mviz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8694896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189814918?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mviz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 424w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 848w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Linus Zoll &amp; Google DeepMind / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>If you have been paying attention to the AI rhetoric these days, you will have likely heard a lot of people talk about &#8216;taste&#8217;.</p><p>I myself started seeing this concept being banded around for a while, and an increasing amount at the beginning of the year with all the craze around Claude Code.</p><p>Claude Code opens the door for everyone to build (almost) anything. And this opportunity is not just available to those who know how to code - you simply need natural language to get going. Explain what you want built, and the coding agent will do the rest.</p><p>But with AI taking away the expense and friction of execution, focus has now moved to the other parts of problem-solving with code. Because in a world where you can now build (almost) anything, what matters more than ever is building the right thing in the right way.</p><p>And this got me thinking; there seems to be such a thing as having good taste in AI development and deployment, which I do think is genuinely important. But what about having good taste when it comes AI governance? Is there even such a thing?</p><p>Initially, I thought this was a silly idea. Taste connotes creativity, imagination and novelty. These are not words that people think of when they think of governance. On the contrary they might instead think: onerous, tedious and a blocker.</p><p>However, the more I thought about it, the more I realised that taste in governance is not only real, but crucial.</p><p>Governance without taste fulfils the dreary perception that most have about the field.</p><p>Governance with taste fulfils legal requirements but also helps unlock the full potential of AI.</p><p>Tasteful governance melts the idea that legal professionals are mere luddites who stifle products and demonstrates a way to balance the engineering and lawyerly incentives.</p><h1>What tasteful governance actually means</h1><p>For me, taste is essentially a filtering mechanism.</p><p>Over time, you accumulate various bits of knowledge from the work you do. You build an understanding of the different problems that you or your clients face as well as the appropriate solutions to them.</p><p>These problems and corresponding solutions are compressed into retrievable principles and samples that can be applied to new sets of problems you encounter later on.</p><p>Taste is therefore a way of deciding how to sample from that knowledge base. It is about selecting the learned principles and samples from previous work that are most appropriate for the present work.</p><p>This is how taste works in other domains too, whether it be music, movies or people. Of all the music one has listened to, of all the movies one has watched, and of all the people one has interacted with, they know how to pick well by using a learned criteria that helps distinguish between the good, the decent and the bad.</p><p>Taste is therefore the ability to pattern-match, abstract and see the signal in the noise in various situations based on past learnings.</p><p>To apply this to governance, taste is not just about knowing what the law says. That is the easier bit really. You look up the correct rules for a client&#8217;s given situation and interpret their meaning accurately.</p><p>It is the next bit where taste is important - knowing <em>how</em> to implement the rules. And this task requires creativity, context-sensitivity and commercial awareness to not merely come up with <em>a</em> solution, but <em>the</em> solution. That is tasteful governance in a nutshell.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/tasteful-ai-governance">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Why Your AI System Might Not Contain Personal Data (Even Though It Does)]]></title><description><![CDATA[A compliance strategy based on ignorance]]></description><link>https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 27 Feb 2026 09:01:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NVdt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NVdt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NVdt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NVdt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:994150,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NVdt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Anne Fehres and Luke Conroy &amp; AI4Media / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>The idea that LLMs &#8216;contain&#8217; personal data was always an ambitious take.</p><p>Probably.</p><p>When I first looked at this topic a little over a year ago, I was not sure where I stood. I thought that the implications of concluding that models did not include personal data were simpler, thereby making that conclusion much more attractive. You can read my newsletter on this here:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;012829a2-c642-449c-8d67-c28660cb5b86&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about whether large language models (LLMs) store personal data they may have been trained on. It looks at how LLMs work, the definition of personal data under the GDPR and the various arguments around this issue.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Do LLMs store personal data?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2024-10-25T08:01:11.992Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ySu3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849f6431-05b8-4950-af53-c41745ffc41c_3840x2743.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/do-llms-store-personal-data&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:150681988,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:8,&quot;comment_count&quot;:7,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>If you have no idea what I am talking about, I explain everything in the newsletter linked above. But this is the gist:</p><ul><li><p>LLMs are trained on lots of data, much of which is scraped from the internet</p></li><li><p>In that training data is lots information that would constitute personal data under the EU&#8217;s GDPR</p></li><li><p>There is an argument that, if that personal data is used for training the model, the resulting trained model &#8216;contains&#8217; the personal data it was trained on</p></li><li><p>If the model contains personal data, and that model is used by another entity, then that entity may be processing personal data</p></li><li><p>The point made in my previous newsletter on this is that this is all quite complicated and I was never convinced one way or another; whether models do or do not contain personal data</p></li></ul><p>But now my thoughts have evolved since the decision by the Court of Justice of the European Union (CJEU) in <em>EDPS vs SRB</em>, which I have also written about (twice):</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e3a9a1a9-020f-4674-83fe-a17378dc0316&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about a pseudonymisation and personal data. It looks at a recent AG opinion on the matter and the implications this has for on-device processing and encryption.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is pseudonymised data personal data?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-02-14T09:02:42.110Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Zf7i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba15688-2a77-44da-b9b4-2b97398a7b3e_2560x1270.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/is-pseudonymised-data-personal-data&quot;,&quot;section_name&quot;:&quot;Data Rights&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:157088951,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;ace812ad-2585-4318-8782-aefd232d0fc7&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about a decision by the Court of Justice of the European Union (CJEU) in EDPS v SRB. It looks at the Court's view on how the GDPR applies to pseudonymised data and the implications this has for certain data processing activities.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is pseudonymised data personal data? (Part 2)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-09-12T08:02:37.163Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/863189fc-4a81-46dd-8a9c-a18264f0c20d_2560x1663.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/is-pseudonymised-data-personal-data-3af&quot;,&quot;section_name&quot;:&quot;Data Rights&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:173384842,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>That decision feels like a significant juncture in the development of EU data protection law that has ramifications for a number of data processing operations, including those pertaining to AI.</p><p>The <em>SRB</em> case clarified a point that even I thought was not up for debate: not all pseudonymised data is personal data. Even when I wrote about the Advocate General&#8217;s opinion on the case prior to the Court&#8217;s decision, I thought this might be one of the rare instances in which the CJEU would diverge from the AG.</p><p>I was wrong.</p><p>It turns out that there is nuance in data protection after all. Not all of it is rigid and strictly interpreted, and it allows for a flexibility that makes it workable in different contexts.</p><p>Perhaps this is a better way - such an approach to pseudonymisation probably makes sense.</p><p>If you encrypt some data, and share the cipher text with another entity without a copy of the cryptographic keys, the receiving entity does not have personal data in GDPR terms.</p><p>They have something that has been pseudonymised, but if they have no means to decrypt it, reverse engineer or otherwise transform the cipher text into its original form, then they just have unintelligible gibberish. Or at least they have information that could not be linked to any person and therefore identify a particular person. There is no personal data there.</p><p>There are some who might say that this opens the door for compliance escapism. If the information I have received cannot be used to identify a person, even if indirectly, then I don&#8217;t need to bother with GDPR obligations. Why would I when the information is not personal data?</p><p>From this perspective, <em>SRB</em> opens up a new gateway for avoiding the perceived compliance headaches of one the EU&#8217;s flagship regulations. And this gateway may be something that deployers of AI system take full advantage of.</p><p>Here is what I am getting at: if we take the principle from <em>SRB</em> and apply it to the question of whether AI models contain personal data, the answer is...still complicated.</p><p>If you look under the hood of a model, you could point to some parts and say, &#8216;yep, that is definitely personal data.&#8217; But then there might be other parts where this is not the case.</p><p>The reason for this is because AI models <em>are not like databases</em>. It is not the internet indexed and searchable through a chat interface. Not at all.</p><p>The way model&#8217;s &#8216;store&#8217; information is much different. If you look under the hood, you will see a probability distribution with fragments of words with their embeddings all numerically represented with no obvious organisation or structure.</p><p>The only way you could possibly argue that there is personal data anywhere in that mess is if you can demonstrate that the model has memorised verbatim some of its training data and that memorised training data is personal data.</p><p>This is not a crazy idea. Systems like ChatGPT have previously shown the tendency to do this kind of memorising and spit out personal data buried deep in its massive text corpus. This includes phone numbers, email address, physical addresses and more.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d8b6e27d-fbc4-453d-b706-2ce02d8a037c&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on attacks against large language models (LLMs) that can reveal personal data in its training data. This comes from a 2020 paper authored by researchers and engineers from Google, OpenAI, Apple and several universities.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-03-10T19:51:31.667Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!fPB6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa196cedb-d718-468a-a7f5-e866d2a860e4_582x648.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:107670484,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;7f7e3dd0-0a3a-41f1-8353-3a866ed8ef24&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on a 2023 paper by Carlini et al looking at the factors that cause large language models (LLMs) to memorize their training data verbatim and thus increase the risk of privacy leakage where that data consists of personal data.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;More Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-11-17T09:00:31.525Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!eNZ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8332595-4793-40f7-afc1-7b1c0ae52b67_1170x706.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/more-notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:138741038,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>But to expose this vulnerability, you need the right prompt. You need a specific prompt attack that reveals the relevant personal data that the model may have memorised.</p><p>This leads to the critical next question - what are the prompts that do this? Or in <em>SRB</em> terms, what means would a deployer of AI systems have to extract and process the personal data contained in the system? How does a deployer know which personal data have been memorised and therefore can be extracted with the right prompt?</p><p>If you could not tell by now, this post is a very nerdy data-protection-crosses-technical-realities deep dive akin to what I did when I first looked at this issue of model&#8217;s containing personal data.</p><p>So all the details may not be all that exciting, but if you are a deployer of AI systems, whether its ChatGPT, Claude, Grok or others, then the thrust of this piece is highly relevant:</p><blockquote><p><em>The SRB decision invites a compliance strategy based on ignorance; AI system deployers intentionally depriving themselves of the means to &#8216;re-identify&#8217; any personal data in the model they are using.</em></p></blockquote><p>It is a big take, but nevertheless a realistic one that is worth exploring. And in the remainder of this post, I attempt to explain it in the simplest way possible so that you can really understand both the point I am making, why I am making it and the implications it has for organisations using AI systems built by others.</p><p>As always, if you find this content useful, share it.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p>Let&#8217;s dive in.</p><h1>The <em>SRB</em> principle</h1><p>Pseudonymised data is not always personal data.</p><p>Now I think it is first of all worth explaining the concept of &#8216;personal data&#8217; and what it <em>actually</em> means in the world of GDPR.</p><p>Simply put, &#8216;personal data&#8217; means information that can be used to identify a person.</p><p>So personal data is not information that might be considered, in some colloquial sense, personal or sensitive. Sometimes when I hear people talking about personal data, they put emphasis on the <em>personal</em> so as to mean information that is particularly special, unique or intimate for the person it belongs to.</p><p>It certainly can be, but the concept of personal is much wider than that.</p><p>To really understand this, it is important to break the definition of personal data down into its constituent parts:</p><ul><li><p>any information</p></li><li><p>relating to</p></li><li><p>identified or identifiable</p></li><li><p>natural person</p></li></ul><p>Any information literally means any information, and this can be objective or subjective information about someone. Think names, email addresses, phone numbers but also opinions, assessments or even predictions about a person.</p><p>To be personal data, that information needs to be about an individual. This means that either the content, purpose or effect of the information must be linked to a particular person:</p><ul><li><p>The content element is satisfied if the information itself is about an individual, such as the exam result of a student</p></li><li><p>The purpose element is satisfied if the information can be used to evaluate or analyse an individual</p></li><li><p>The effect element is satisfied if the use of the information has an impact on an individual&#8217;s rights or interests</p></li></ul><p>To be identified or identifiable is about whether the entity holding the information can use it to single out a person from other people. I will come back to this later on.</p><p>Finally, a natural person is just a legal term for a person. So personal data does not include information about a corporation or organisation or anything that is not a human. The GDPR also does not apply to deceased persons.</p><p>With a sufficient understanding of personal data, we can then turn to the concept of pseudonymised data.</p><p>Generally, a pseudonym can be thought of as a cover name or a replacement for a true value or a kind of derivative of some original information. Pseudonymisation is therefore the process of taking data and applying some transformation to it that turns it into pseudonymised data.</p><p>Let&#8217;s say you have an email address: <code>mahdiassan@email.com</code>. If you wanted to pseudonymise this piece of information, there a couple a different ways you could do it.</p><p>You could pseudonymise the email address using a technique called masking whereby you simply replace certain characters in the address:</p><pre><code><code># masking_example 

original_data = mahdiassan@email.com

pseudo_data = m********n@email.com
</code></code></pre><p>A more complicated way to pseudonymise the data is encrypt it whereby a cryptographic protocol is applied to the email which outputs some cipher text:</p><pre><code><code># encryption_example

original_data = mahdiassan@email.com

pseudo_data = 92edfa8361b7af3e637
</code></code></pre><p>This is where I want to return to the idea of identifiability.</p><p>Identifiability exists on a spectrum. On the one end, you have data points that directly identifies a specific individual (like a name) and on the other end you have data points that only indirectly identify individuals (like a userID). It is important to remember two things here though:</p><ul><li><p>Indirect identifiability includes data points that can be linked to <em>a person</em> even if it is not known exactly who that person is</p></li><li><p>Anonymity is the complete opposite of direct identifiability - this where data cannot be linked to any person at all (as can be the case with aggregated statistics)</p></li></ul><p>Pseudonymisation is about reducing the identifiability of personal data. It reduces the identifiability of data such that it can no longer be used to identify a specific individual. In other words, without the use additional information, it would be difficult to identify exactly who the pseduonymised data relates to.</p><p>Let&#8217;s go back to the encryption example above. When you encrypt data, you produce cipher text but also a set of cryptographic keys. These keys can be used to encrypt as well as decrypt the data. So if I encrypted some data and shared <em>only</em> the cipher text with someone else, and I kept the keys to myself, it would be very difficult for that person to use that data to identify someone - all they have is a hash value that bascially looks like a bunch of gibberish (<code>92edfa8361b7af3e637</code>).</p><p>However, a question one may have is, even if the person I shared the data with only has the cipher text, is that cipher text still personal data? After all, the keys to decrypt the data, and turn it back into its original form (<code>mahdiassan@email.com</code>), are still in my hands and therefore I still have the ability to see the personal data that has been encrypted. But regarding the third party I have shared only the cipher text with, what are they holding?</p><p>There are two different approaches to this question: a strict approach and a relative approach.</p><p>Under the strict approach, the cipher text in the hands of the third party is still personal data. That the cryptographic keys are in still existence, and therefore could be used by me to decrypt the data and link it to an individual, means that the encrypted data is still ultimately personal data. The means of identification are still there.</p><p>The relative approach, however, adds some nuance to this. Though the means for identification exist, it does not mean that the person that the data relates to is always identifiable. This depends on the means available to the person holding the information in question.</p><p>For a while, the strict approach seemed to be a dominate view among the data protection community. But a judgment from the CJEU in <em>EDPS vs SRB</em> last year has declared something different; that the relative approach should be taken regarding the concept of personal data.</p><p>I will not go over the case details again in this post; you can read all that in my previous post on the topic. But what I will reiterate here are the principles that can be derived from <em>SRB</em>.</p><p>Using my encrypted data example again, if I share only the encrypted data with the third party, and that third party has no access to the cryptographic keys, then, from the perspective of that third party, they are not holding personal data. This is as long as the following is true:</p><ol><li><p>The third party cannot &#8216;lift&#8217; the pseudonymisation (or in this case the encryption) preventing re-identification</p></li><li><p>The third party cannot perform re-identification through cross-checking with other available information it may have access to (including information it can search on the internet)</p></li><li><p>The risk of identification is insignificant considering the cost, time and the technology available</p></li></ol><p>Accordingly, from the position of the third party with whom I share the encrypted data with, they are not holding personal data because:</p><ul><li><p>They do not have the cryptographic keys to decrypt the data</p></li><li><p>There is no other information they can use to perform re-identification using the cipher text only (i.e., they cannot reverse-engineer the cipher text)</p></li><li><p>If I use a sufficiently complex cryptographic protocol, they cannot reproduce the cryptographic keys needed to decrypt the data (maybe barring access to a sufficiently powerful quantum computer)</p></li></ul><p>The key thing to understand from <em>SRB</em> is that the nature of personal data&#8217;s relativity ultimately depends on the entity holding it. In essence, whether pseudonymised is personal data depends on who is looking at it and what they can do with it, not just on the data&#8217;s inherent properties.</p><h1>Applying <em>SRB</em> to AI systems</h1><p>I used the example of encrypted data earlier because it has a particular relevance to the second part of my thesis, which is about what is inside an LLM.</p><p>LLMs are giant prediction machines. They take your natural language input and spit out something that they think you need.</p><p>But if you look under the hood of an LLM, it is complex to say the least. It consists of tokenisers, embedding layers, positional encoders, transformer blocks and a probability distribution.</p><p>If you want a detailed explanation of how LLMs work, you can go back to my previous post:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;10463f3f-7d98-4c71-b10f-240922a0c236&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about whether large language models (LLMs) store personal data they may have been trained on. It looks at how LLMs work, the definition of personal data under the GDPR and the various arguments around this issue.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Do LLMs store personal data?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2024-10-25T08:01:11.992Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ySu3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849f6431-05b8-4950-af53-c41745ffc41c_3840x2743.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/do-llms-store-personal-data&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:150681988,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:8,&quot;comment_count&quot;:7,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>But for now, the key point I make in that post is that the type of information that LLMs &#8216;store&#8217; and the nature of that storage is not like how we traditionally think of data stored in databases.</p><p>When an LLM is being trained, internally it is building something called a vocabulary (or a <code>vocab</code>). This part of the model contains all the tokens it has come across in its training. A token represents a word of a fragment of a word in a numerical form (e.g., &#8216;computer&#8217; might be tokenised to <code>2886</code>). Additionally, each token will have assigned to it a word embedding, which encodes the tokens relationship with all the other tokens in the vocabulary.</p><p>So every time you give a model a prompt, it will refer to its <code>vocab</code> and work out the probability of each token being the appropriate tokens for the response to the prompt. And then it will select those tokens that are more likely to form the right output.</p><p>This <code>vocab</code> consists of a matrix that does kind of look like a table:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BZY1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BZY1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 424w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 848w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1272w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BZY1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png" width="1456" height="666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:666,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:380592,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BZY1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 424w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 848w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1272w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Caption: From &#8216;How large language models work, a visual intro to transformers | Chapter 5, Deep Learning&#8217; by <em>3Blue1Brown</em> on <a href="https://youtu.be/wjZofJX0v4M?si=27daqL-CRkBvbuDK&amp;t=746">YouTube</a>. Note that in this video the tokens are represented as whole words but in reality tokens will represent fragments of words. But <em>3Blue1Brown</em> explains it this way for the sake of convenience.</figcaption></figure></div><p>An LLM&#8217;s <code>vocab</code> can be very large - tens of thousands worth of tokens. This means that the matrix could have tens of thousands of columns representing each token along with tens of thousands of rows of values representing the word embeddings for each token.</p><p>But this matrix is not a database. The information in the <code>vocab</code> consists of values for the parameters that are learned during training, and those values codify the relationships between all the tokens that the model comes across during training (and this is in addition to the weights stored in the neural networks of each transformer block).</p><p>So altogether then, an LLM stores:</p><ul><li><p>All the tokens it comes across during training</p></li><li><p>The embedding vectors for each token</p></li><li><p>The weights for the neural networks in each transformer block</p></li></ul><p>This information does not itself relate to an <em>identifiable</em> natural person. It is a bunch of numbers that humans cannot comprehend. And even if we could comprehend these numbers, linking that back to particular people whose personal data may be in the training data would still be incredibly difficult.</p><p>In effect, all you have inside an LLM is a matrix of seemingly random numbers that are only readily interpretable to the LLM.</p><p>Looking inside an LLM to identify the personal data contained in there is no use. However, deconstructing the black box that is an LLM is not how most people interact with such digital artefacts. Most people interact with LLMs by prompting the text box on their screen.</p><p>Now this is where the encryption analogy comes in.</p><p>LLMs sometimes memorise verbatim the data they comes across during training. This does not happen with all the data points, but there is research out there showing that they are capable of doing this.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;0c6e6100-da8c-4037-8096-1b51d275a9e9&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on attacks against large language models (LLMs) that can reveal personal data in its training data. This comes from a 2020 paper authored by researchers and engineers from Google, OpenAI, Apple and several universities.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-03-10T19:51:31.667Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!fPB6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa196cedb-d718-468a-a7f5-e866d2a860e4_582x648.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:107670484,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e49642a7-6abe-4937-a16a-73c68379f998&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on a 2023 paper by Carlini et al looking at the factors that cause large language models (LLMs) to memorize their training data verbatim and thus increase the risk of privacy leakage where that data consists of personal data.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;More Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-11-17T09:00:31.525Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!eNZ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8332595-4793-40f7-afc1-7b1c0ae52b67_1170x706.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/more-notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:138741038,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>After training on a large dataset of text, the LLM has an understanding of language in the sense that it understands the correlations and patterns between words. However, the model does not necessarily learn factual information about the language it learns.</p><p>Any &#8220;factual knowledge&#8221; that the model is able to produce is merely derived from its understanding of language and the correlations between different words (or tokens). So by understanding language, it is possible for LLMs to &#8220;learn&#8221; factual information.</p><p>In particular, such factual information could be learned if the relevant patterns appear frequently enough in the training dataset. The more often the model comes across a certain pattern during training, the more prominently that pattern will be represented in its parameters.</p><p>Whenever the model then receives an input containing text relating to that more frequent pattern, it will rely on that pattern to produce its response. In doing so, the model could produce data that it has essentially &#8216;memorised&#8217; from its training data.</p><p>So while the information contained within LLMs is not intelligible to humans, the personal data that is in there somewhere and has been memorised by the model could be extracted by prompting the model in certain ways.</p><p>If I ask ChatGPT when Donald Trump was born, it says he was born on 14 June 1946:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GL0M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GL0M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GL0M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png" width="1456" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:477803,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GL0M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But if I ask ChatGPT who was born on 14 June 1946, I get this:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZZOA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZZOA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png" width="1456" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:611896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZZOA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Clearly ChatGPT has learned from is training data that &#8220;14 June 1946&#8221; and &#8220;born&#8221; and &#8220;Donald Trump&#8221; are all strongly associated with each other, hence why I get the outputs I do.</p><p>Obviously though the prompts for extracting this information are pretty straight forward here given that Donald Trump, or any other public figure, will likely feature multiple times in the training data. This increases the propensity of the LLM to memorise certain information about such figures and therefore increases the ease of which such information can be extracted through prompting.</p><p>But the point here is that personal data that has been memorised by the model can be transformed from an unreadable to a readable format by using the right prompt. Which is similar to the how encryption works.</p><p>Recall that with encryption, you have:</p><ul><li><p>The original data</p></li><li><p>The cryptographic protocol applied to the data</p></li><li><p>The generation of the encrypted data</p></li><li><p>A set of cryptographic keys that can decrypt the encrypted data back to the original data</p></li></ul><p>And you could describe LLMs and personal data extraction in a similar way:</p><ul><li><p>Personal data is contained in the large training datasets consisting of data scraped from the internet</p></li><li><p>That data are tokenised and mapped to word embeddings</p></li><li><p>The data are therefore converted into a bunch of values representing these tokens and embeddings and organised into a matrix</p></li><li><p>With the right prompt, that unintelligible bunch of numbers can effectively be converted into readable text that may constitute personal data</p></li></ul><p>With this logic, the information you have inside LLMs is pseduonymised data. The tokens and word embeddings are in a pseudonymised form as a result of model training, and then transformed into intelligible personal data if the right prompt is used with the model at inference.</p><p>Extending this, if a developer takes a trained LLM and incorporates it into a new product, then that developer will not necessarily be holding personal data. Applying the <em>SRB</em> principle, the developer is only holding personal data extractable from the model if they use the means to extract it, which would be the prompts.</p><p>But if the developer does not know what those prompts are and does not use them, then that extractable, memorised personal data remains pseudonymised. The GDPR obligations that would therefore otherwise apply (selecting an appropriate legal basis, adhering purpose limitation and data minimisation etc) are not of concern to the developer regarding the pseudonymised personal data &#8216;inside&#8217; the model it is incorporating into its product.</p><p>I would argue that this perspective on the matter is reinforced by a compliance strategy that has been implicitly endorsed - a strategy based on ignorance.</p><h1>Compliance based on ignorance</h1><p>I want to be clear about a couple of things here before I go on explaining this take.</p><p>Firstly, I am not saying that this potential compliance strategy is right in the sense of it is a good thing. But I do predict that this will be a strategy that many developers will be tempted towards because it makes their compliance work simpler.</p><p>Secondly, this potential compliance strategy does not absolve developers of <em>all</em> of their data protection responsibilities. This only absolves them from the needing to address data protection issues arising from the use of the model or building on top of it - the personal data contained in these models is not their responsibility. However, the way that the system they are building using the model processes personal data is still their problem, and data protection responsibilities definitely still apply there. This is the case regarding personal data used to develop the system or personal data collected when people use the system, but neither of these processing operations are the subject of this post.</p><p>The compliance strategy explored in this piece specifically concerns developers using trained models to build new products - do those products already contain personal data by using a model trained with lots of personal data that might be &#8216;stored&#8217; in the model?</p><p>I argued in the last section that these models do not necessarily contain personal data. In this section, I look at how developers could go about demonstrating this by essentially remaining ignorant about the details of the models they are using.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Privacy does not just mean you have something to hide. That's stupid.]]></title><description><![CDATA[This is what privacy is really about]]></description><link>https://www.thecybersolicitor.com/p/privacy-does-not-mean-you-have-nothing</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/privacy-does-not-mean-you-have-nothing</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 20 Feb 2026 09:01:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!F-KR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F-KR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F-KR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 424w, https://substackcdn.com/image/fetch/$s_!F-KR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 848w, https://substackcdn.com/image/fetch/$s_!F-KR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!F-KR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F-KR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg" width="1456" height="1877" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1877,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2199385,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/187961126?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F-KR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 424w, https://substackcdn.com/image/fetch/$s_!F-KR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 848w, https://substackcdn.com/image/fetch/$s_!F-KR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!F-KR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9a2c74-d5b7-458a-aa31-978f53cbe629_3840x4951.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Bart Fish &amp; Power Tools of AI / https://betterimagesofai.org/ <a href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</a></figcaption></figure></div><p>Most people simply do not realise the purpose of privacy.</p><p>And you are one of those people if you think that you don&#8217;t need to worry about privacy if you have nothing to hide.</p><p>This is a bad take. Ignorant in fact.</p><p>Here&#8217;s the truth.</p><p>Think about the social&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/privacy-does-not-mean-you-have-nothing">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[You are not vibe-coding properly if you are not doing this]]></title><description><![CDATA[How to build with Claude Code responsibly]]></description><link>https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 13 Feb 2026 09:00:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pJLZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fmedia%2FG_V2kvLXwAA1nI2.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Yes it is true. Claude Code is pretty cool.</p><p>I started using it properly about a month ago, initially just testing out its competency at one-shot app creation, for which I was careful to manage expectations of course.</p><p>Watching this coding agent work through your request, while keeping you in the loop to check that its work is aligned with your preferences, is quite fascinating. There is something quite magical and intriguing about how this little bot can just take your initial prompt and crank out a full-fledged application. It is equally cool to see how it can carry out various tasks that would otherwise require a decent level of coding proficiency.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/birdabo/status/2014646824079106544?s=46&quot;,&quot;full_text&quot;:&quot;&#8220;rome wasn&#8217;t built in a day&#8221; \n\n&amp;gt; they didn&#8217;t have claude code. &quot;,&quot;username&quot;:&quot;birdabo&quot;,&quot;name&quot;:&quot;sui dev &#9732;&#65039;&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1991760919513403392/cCbWHb5A_normal.jpg&quot;,&quot;date&quot;:&quot;2026-01-23T10:30:07.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/G_V2kvLXwAA1nI2.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/eCEH2vB94O&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:119,&quot;retweet_count&quot;:315,&quot;like_count&quot;:5832,&quot;impression_count&quot;:117157,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:false}" data-component-name="Twitter2ToDOM"></div><p>I have found a lot of inspiration from a number of Substack newsletters on the joys of using Claude Code, including from <a href="http://insights.priva.cat/p/i-built-an-ai-powered-futures-forecasting">Privacat</a>, <a href="https://www.interconnects.ai/p/claude-code-hits-different">Nathan Lambert</a> and <a href="http://jasmi.news/p/claude-code">Jasmine Sun</a>.</p><p>The interesting thing about Claude Code is that, despite it being a coding agent and therefore seemingly only of interest to coders or those more technically capable, it is capturing the attention of those outside the AI bubble. Even the <em>Wall Street Journal</em> is writing about Claude Code, so it must be something cool even among the normies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tJrq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tJrq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 424w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 848w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1272w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tJrq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png" width="677" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfd362b5-a71a-4ead-894d-604e245831e9_677x818.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:677,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175534,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/187229909?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tJrq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 424w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 848w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1272w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">From <a href="https://www.wsj.com/tech/ai/anthropic-claude-code-ai-7a46460e">The Wall Street Journal</a></figcaption></figure></div><p>As fun as all this has been (and maybe even a little addicting), my experience with Claude Code did alert me to something which I think could very easily be overlooked for those who have been &#8216;Claude-pilled.&#8217;</p><p>Products like Claude Code make it easier and cheaper than ever to build software solutions. And if these codings agents continue to improve, so it is quite striking to think of the possibilities down the line.</p><p>The temptation that this fuels is to just build a bunch of new stuff. If all you need is a bit of natural language prompting and a machine will just turn your idea into reality with a little further input from you, then think of all the ideas that do not need to be just ideas anymore. Imagine all the things you could build. Maybe you really are just one weekend away from a building the next killer app that makes you a fortune in a week.</p><p>The obvious problem here is that as people get carried away with the magic of Claude Code, they start to forget the fundamental questions about what they are doing. They forget about the aspects of building that AI cannot necessarily do for them.</p><p>AI can do many things, but it cannot do everything.</p><p>In the midst of your Claude psychosis, you may forgo why you are even building the thing in the first place as well as the principles for building it well.</p><p>And this is crucial, because if you end up building the wrong thing in the wrong way, and then deploy it for other people to use, you may disappoint your users at best or even harm them at worse.</p><p>To avoid this, you need to think about what it will take to actually build things properly with products like Claude Code:</p><ul><li><p><strong>Taste.</strong> Are you solving a real problem that actually needs solving?</p></li><li><p><strong>Distribution.</strong> How do you get people to care about your solution to the problem?</p></li><li><p><strong>Trust.</strong> Does your solution actually work well?</p></li></ul><p>Trust is particularly important. In a sea of new apps being built and deployed everyday by eager vibe-coders leveraging the power of agents, why should people use your app? What makes it so much better than the rest?</p><p>Even if your app solves a problem that others are struggling with, and even if you have an audience willing to use it, if it does not deliver on the promises, then you just get a high churn rate. And all your late nights with Claude Code will go to waste.</p><p>Alternatively, if you take the time to build a solid solution that works well, then you have a much better chance of gaining trust. And this thens feed into the other factors; the more people believe in your product, the more they share it with others which leads to more users and therefore more feedback on how well your app is doing.</p><p>The key to gaining this trust is embracing governance.</p><p>Governance is not just about legal compliance. Fundamentally, governance is about implementing measures that help you build more reliable products.</p><p>You should think of governance as an enabler. If you get it right from the start, then not only do deal with any compliance issues, but you also give people another reasons to trust your product. And you feed the growth flywheel.</p><p>To get governance right when building with Claude Code, I think you need to start by managing three things: quality, data and risk.</p><p>Get these three things right and you will be well on your way to establishing a unique selling point for your product and a moat that most will not think to work on until it is too late.</p><p>In this post, I walk through the steps and prompts for quality, data and risk management when using Claude Code. If you are building apps with Claude Code that you plan to release into the wild, then this is essential reading.</p><p>If you find this content valuable, make sure to share it with others.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Why Substack is asking for your age now]]></title><description><![CDATA[A primer on the UK Online Safety Act and age assurance]]></description><link>https://www.thecybersolicitor.com/p/why-substack-is-asking-for-your-age</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/why-substack-is-asking-for-your-age</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 06 Feb 2026 09:02:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!a7jd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Late last year, I received this email from Substack:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iT2B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iT2B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 424w, https://substackcdn.com/image/fetch/$s_!iT2B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 848w, https://substackcdn.com/image/fetch/$s_!iT2B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 1272w, https://substackcdn.com/image/fetch/$s_!iT2B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iT2B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png" width="1172" height="1188" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1188,&quot;width&quot;:1172,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:332767,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185105000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iT2B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 424w, https://substackcdn.com/image/fetch/$s_!iT2B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 848w, https://substackcdn.com/image/fetch/$s_!iT2B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 1272w, https://substackcdn.com/image/fetch/$s_!iT2B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F924c2a3d-4640-4b6a-a785-7fcd0d470163_1172x1188.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And then when trying to access the direct messaging feature on the Substack app, I was presented with this:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a7jd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a7jd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 424w, https://substackcdn.com/image/fetch/$s_!a7jd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 848w, https://substackcdn.com/image/fetch/$s_!a7jd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 1272w, https://substackcdn.com/image/fetch/$s_!a7jd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a7jd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png" width="1170" height="2532" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2532,&quot;width&quot;:1170,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:232119,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185105000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a7jd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 424w, https://substackcdn.com/image/fetch/$s_!a7jd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 848w, https://substackcdn.com/image/fetch/$s_!a7jd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 1272w, https://substackcdn.com/image/fetch/$s_!a7jd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24daed4f-8410-4b68-91b1-004e52b5636e_1170x2532.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In fact, if you are in the UK, you may have noticed a number of websites requiring your age to be verified before being able to access the site. Or you may have seen this in the news.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mali!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mali!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 424w, https://substackcdn.com/image/fetch/$s_!mali!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 848w, https://substackcdn.com/image/fetch/$s_!mali!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 1272w, https://substackcdn.com/image/fetch/$s_!mali!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mali!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png" width="1456" height="1281" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1281,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1319200,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185105000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mali!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 424w, https://substackcdn.com/image/fetch/$s_!mali!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 848w, https://substackcdn.com/image/fetch/$s_!mali!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 1272w, https://substackcdn.com/image/fetch/$s_!mali!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3b803b0f-1a9e-4a5e-8840-ede2e79ccd40_1480x1302.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Article from <em><a href="https://www.ft.com/content/dca34551-4828-4677-9a72-ac8966a380cd">The Financial Times</a></em></figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!o1vw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!o1vw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 424w, https://substackcdn.com/image/fetch/$s_!o1vw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 848w, https://substackcdn.com/image/fetch/$s_!o1vw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 1272w, https://substackcdn.com/image/fetch/$s_!o1vw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!o1vw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png" width="1456" height="1140" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a4412c46-f663-472e-853a-197d2c157824_1668x1306.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1140,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1563892,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185105000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!o1vw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 424w, https://substackcdn.com/image/fetch/$s_!o1vw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 848w, https://substackcdn.com/image/fetch/$s_!o1vw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 1272w, https://substackcdn.com/image/fetch/$s_!o1vw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa4412c46-f663-472e-853a-197d2c157824_1668x1306.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Article from <a href="https://www.bbc.co.uk/news/articles/c1k81lj8nvpo">BBC News</a></figcaption></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EPmm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EPmm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 424w, https://substackcdn.com/image/fetch/$s_!EPmm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 848w, https://substackcdn.com/image/fetch/$s_!EPmm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 1272w, https://substackcdn.com/image/fetch/$s_!EPmm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EPmm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png" width="1456" height="604" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:604,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:158143,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185105000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EPmm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 424w, https://substackcdn.com/image/fetch/$s_!EPmm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 848w, https://substackcdn.com/image/fetch/$s_!EPmm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 1272w, https://substackcdn.com/image/fetch/$s_!EPmm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F028719e6-6cca-4127-83df-b58cd166c47e_1730x718.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Article from <a href="https://news.sky.com/story/major-pornography-sites-to-introduce-robust-age-verification-for-uk-users-13388827">Sky News</a></figcaption></figure></div><p>Now this was not just limited to adult websites. Even platforms like X, Reddit and and TikTok have also been introducing some form of age checks. And lots of people have been wondering why.</p><p>The main reason is because of a law in the UK called the Online Safety Act 2023 (OSA). The main purpose of this legislation is to impose obligations on online platform operating in the UK to ensure that they are safe for UK users, especially children.</p><p>In this newsletter, I attempt to explain, in simple terms, why OSA has led to certain websites like Substack asking for your age. I will cover:</p><ul><li><p>What OSA is and what it requires</p></li><li><p>What are the specific requirements regarding age checks</p></li><li><p>The data protection issues with age checks</p></li><li><p>What this all really means</p></li></ul><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/subscribe?"><span>Subscribe now</span></a></p><p></p><h1>What is the Online Safety Act and what does it require of Substack?</h1><p>The main aim of OSA is to provide a regulatory framework for making the use of internet services safer for people in the UK. It does this by:</p><ul><li><p>Imposing duties on certain service providers to identify, mitigate and manage risks of harm from illegal content and activity and content and activity that is harmful to children</p></li><li><p>Conferring certain functions and powers to Ofcom, the UK regulator for broadcasting, internet and telecommunications</p></li></ul><p>Among the service providers caught within the scope of OSA are what are called &#8216;user-to-user services&#8217;, or U2U. Under the Act, a U2U service provider is an internet service that enables and hosts content generated, uploaded or shared by users that other users can also access.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>In its <a href="https://www.ofcom.org.uk/online-safety/illegal-and-harmful-content/guide-for-services">guidance</a>, Ofcom states that a U2U service provider includes the following types of internet services:</p><ul><li><p>Social media sites or apps</p></li><li><p>Photo- or video-sharing services</p></li><li><p>Chat or instant messaging services, including dating apps</p></li><li><p>Online or mobile gaming services</p></li></ul><p>Substack <a href="https://substack.com/about">describes</a> itself in the following way:</p><blockquote><p>...a new media app that connects you with the creators, ideas, and communities you care about most. Here, you can discover world-class video, podcasts, and writing from a diverse set of creators who cover politics, pop culture, food, philosophy, tech, travel, and so much more.</p></blockquote><p>It is pretty clear then that Substack constitutes a U2U service under OSA, which is also implicit in the communications it has been sending out regarding compliance with this law.</p><p>If Substack is a U2U service provider under OSA, then what is it required to do?</p><p>The obligations falling on Substack can be found in Chapter 2 of the legislation, which in the main include the following:</p><ul><li><p>Carry out an assessment that evaluates how likely users are to encounter illegal content on the service<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p></li><li><p>Take measures to mitigate and manage the risk of illegal content existing on the service, including through, among other things, the design of certain functionalities or other features, drafting policies on terms of use, content moderation or other measures<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a></p></li><li><p>Enable users to report illegal content or content that is harmful to children<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a></p></li></ul><h1>What are the specific requirements regarding child safety and age checks?</h1><p>So how do the OSA requirements apply to Substack in such a way that it needs to check the ages of its users?</p><p>If you read Substack&#8217;s <a href="https://support.substack.com/hc/en-us/articles/42995419870100-Substack-18-Content-policy">18+ content policy</a> on its support page, we see the following:</p><blockquote><p>Substack supports a wide range of writing and creative expression, including material intended for adult audiences. In compliance with the <strong><a href="https://www.gov.uk/government/publications/online-safety-act-explainer/online-safety-act-explainer">UK Online Safety Act</a></strong> (&#8220;OSA&#8221;), we are required to provide UK users with a way to report potentially illegal or age-restricted content.</p></blockquote><p>Let&#8217;s unpack this a bit.</p><p>As suggested in Substack&#8217;s policy, the platform allows material to be published for adult audiences and therefore material that may not be suitable for children. Where this is the case, OSA imposes child safety duties on service providers where that service is &#8220;likely to be accessed by children.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a></p><p>The likelihood of a child accessing a service depends on the outcome of a children&#8217;s access assessment.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a> This is an assessment that determines whether it is possible for a child to access the service and whether either a significant number of children use the service or the service likely to attract a significant number of child users.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-7" href="#footnote-7" target="_self">7</a> All U2U service providers, including Substack, are required to carry out this assessment.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-8" href="#footnote-8" target="_self">8</a> Interestingly, OSA explicitly states that if a service has not already implemented age checks for its service, it cannot conclude that its service is not likely to be accessed by children.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-9" href="#footnote-9" target="_self">9</a></p><p>If the service is likely to be accessed by children, then a U2U service provider like Substack will also need to carry out a child risk assessment for its service.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-10" href="#footnote-10" target="_self">10</a> This assessment needs to evaluate how likely child users are to encounter what OSA calls &#8216;primary priority content&#8217; that is harmful to children. In its <a href="https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/statement-protecting-children-from-harms-online/main-document/guidance-on-content-harmful-to-children.pdf?v=395445">guidance</a>, Ofcom has stated that content relating to the following falls in this category:<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-11" href="#footnote-11" target="_self">11</a></p><ul><li><p>Pornography</p></li><li><p>Suicide</p></li><li><p>Self-harm</p></li><li><p>Eating disorders</p></li><li><p>Abuse and hate speech</p></li><li><p>Bullying</p></li><li><p>Violence</p></li><li><p>Harmful substances</p></li><li><p>Dangerous stunts and challenges</p></li></ul><p>In carrying out these risk assessment, Ofcom has specified the characteristics of the service that should be taken into account. Among these characteristics include the ability to send direct messages on the service, on which Ofcom states the following in its <a href="https://www.ofcom.org.uk/siteassets/resources/documents/consultations/category-1-10-weeks/statement-protecting-children-from-harms-online/main-document/childrens-risk-assessment-guidance-and-childrens-risk-profiles.pdf?v=396653">guidance</a>:</p><blockquote><p>Direct messaging can allow users to share content harmful to children in a closed and more targeted manner. While direct messaging can enable users to protect their privacy, our evidence shows direct messaging can enable abuse and hate content, and bullying content behaviours, particularly between two users, that are more likely to go unnoticed by others. This risk may increase when users are able to message other users without the recipient&#8217;s permission. Children can also receive direct messages containing pornographic content, often in the form of hyperlinks and frequently by users they do not know or suspect to be &#8216;bots&#8217;.</p></blockquote><p>As part of the child safety duties under OSA, U2U service providers are required to prevent children from encountering primary priority content as well as protect children from the risk of harm of other content on the service.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-12" href="#footnote-12" target="_self">12</a></p><p>To comply with this duty, OSA requires U2U service providers to use age verification or age estimation (or both) to prevent children encountering harmful content.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-13" href="#footnote-13" target="_self">13</a> In doing so, the service provider must ensure that the age checks are &#8220;highly effective at correctly determining whether or not a particular user is a child.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-14" href="#footnote-14" target="_self">14</a></p><p>OSA is quite specific regarding what counts as age verification or age estimation:</p><ul><li><p>&#8216;Age verification&#8217; means &#8220;any measure designed to verify the exact age of users of a regulated service.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-15" href="#footnote-15" target="_self">15</a></p></li><li><p>&#8216;Age estimation&#8217; means &#8220;any measure designed to estimate the age or age-range of users of a regulated servic.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-16" href="#footnote-16" target="_self">16</a></p></li></ul><p>Accordingly, any measures where a user simply self-declares that they are of a certain age (for example by ticking a box which says that they are 18 or above) is neither considered age verification or estimation for the purposes of OSA.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-17" href="#footnote-17" target="_self">17</a> Such mechanisms are not enough to comply with the law.</p><p>So putting this altogether:</p><ul><li><p>Substack allows material suitable for adults and therefore not suitable for children</p></li><li><p>Substack has probably concluded that its service is likely to be accessed by children</p></li><li><p>Substack&#8217;s child risk assessment likely included the risks of having direct messaging features as part of its service</p></li><li><p>Substack considers itself to be subject to child safety duties under OSA</p></li><li><p>To comply with these duties, Substack has implemented age checks for its service, including for its direct messaging feature</p></li></ul><h1>Data protection and age checks</h1><p>If you have gone ahead and completed the age checks mandated by Substack, you may be wondering how your data is handled as part of this process.</p><p>There are different ways for an internet service to carry out age checks on users:</p><ul><li><p><strong>Verifying ID documents.</strong> This requires uploading a picture of an government-issued ID such as a driving licence or passport. The document is then checked for authenticity and to verify the age of the user presented in the documents.</p></li><li><p><strong>Computer-vision approach.</strong> This is where the service predicts the age of a given user based on an image of their face. With this, users are required to take a selfie using their device from which their age is estimated.</p></li><li><p><strong>Analysing account information.</strong> This involves using data from or generated about a user on the service to predict their age. For example, <a href="https://blog.youtube/news-and-events/extending-our-built-in-protections-to-more-teens-on-youtube/">YouTube</a> applies machine learning for age estimation of its users by relying various signals such as search history and how long an account has existed.</p></li></ul><p>Third party providers are usually preferred by internet services for carrying out the checks. Substack uses <a href="https://help.withpersona.com/articles/huT4RcIBnrAulAHamu6Gz/">Persona</a>, an online identity verification service based in San Francisco. Substack&#8217;s <a href="https://support.substack.com/hc/en-us/articles/42995315367572-Why-is-Substack-asking-to-verify-my-age?__cf_chl_tk=YHdEhv1igNo.Tgo2.f3k453R84aKUy3Xg0RCsGALv8E-1768571380-1.0.1.1-f0jIU84bezbGRTcxKsA3tVmCehVsaBKsitRh6EOio9U#h_01KARWFCKYX94QFYN75BT6PY4E">support page</a> describes how an age check is conducted based initially on a selfie or, failing this, a copy of a government-issued ID document.</p><p>The handling of user data for age checks is something that OSA does anticipate, as it states that the following duty applies to internet services subject to the legislation:<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-18" href="#footnote-18" target="_self">18</a></p><blockquote><p>When deciding on, and implementing, safety measures and policies, a duty to have particular regard to the importance of protecting users from a breach of any statutory provision or rule of law concerning <strong>privacy</strong> that is relevant to the use or operation of a user-to-user service (including, but not limited to, <strong>any such provision or rule concerning the processing of personal data</strong>). (Emphasis added)</p></blockquote><p>OSA does not contain much by way of specific data protection and privacy rules. For this, Ofcom relies on the enforcement activity of the Information Commissioner&#8217;s Office (ICO), as the UK&#8217;s data protection regulator, <a href="https://www.ofcom.org.uk/online-safety/protecting-children/age-checks-for-online-safety--what-you-need-to-know-as-a-user">stating</a>:</p><blockquote><p>We work closely with the ICO and where we have concerns that a provider has not complied with data protection law, we may refer the matter to the ICO.</p></blockquote><p>To that effect, the ICO has published <a href="https://ico.org.uk/about-the-ico/what-we-do/information-commissioners-opinions/age-assurance-for-the-children-s-code/">guidance</a> on the use of age checking technology whilst ensuring compliance with relevant data protection rules, including the UK GDPR. In that guidance, the ICO sets out their expectations for age assurance and compliance with each of the data protection principles.</p><p>There are a few issues here that I think are worth highlighting.</p><p>The first one concerns accuracy. U2U service providers that estimate a user&#8217;s age using computer-vision mechanisms or based on account information are relying on approaches where the likelihood of error is much higher. These errors either result in genuine adults being denied access to the service or part of the service or granting access to children when they should not.</p><p>Sometimes the source of this accuracy is the bias ingrained in the facial estimation systems themselves. These systems utilise machine learning classifiers trained on large datasets of facial images. However, these datasets are not always demographically diverse, resulting in varying performance levels when used for different types of people, including in terms of skin colour and gender.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WjWK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WjWK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 424w, https://substackcdn.com/image/fetch/$s_!WjWK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 848w, https://substackcdn.com/image/fetch/$s_!WjWK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 1272w, https://substackcdn.com/image/fetch/$s_!WjWK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WjWK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png" width="1276" height="482" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:482,&quot;width&quot;:1276,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:381173,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185105000?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefe29c52-f7b0-4662-b417-2748301a9c23_1276x482.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WjWK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 424w, https://substackcdn.com/image/fetch/$s_!WjWK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 848w, https://substackcdn.com/image/fetch/$s_!WjWK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 1272w, https://substackcdn.com/image/fetch/$s_!WjWK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe64cad97-2e0d-48ee-bb6f-fff1233e2b11_1276x482.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">From <a href="https://web.archive.org/web/20250416160357/https://www.yoti.com/wp-content/uploads/2023/10/Facial-age-estimation-fact-sheet.pdf">Yoti&#8217;s Facial Age Estimation Fact Sheet</a>. Mean absolute error (MAE) measures how far off an estimate is from the true age. For example, a MAE of 1.6 means an estimate of a person&#8217;s age is off by 1.6 years.</figcaption></figure></div><p>Additionally, as with any system, there are security risks. Back in July 2024, AU10TIX, an Israeli ID verification company, suffered a data <a href="https://trustcloud.tech/blog/au10tix-case-records-exposed-security-breach-major-apps/">breach</a> which exposed its logging platform containing images of identity documents like driving licences and passports. This provider was used by TikTok, Uber X and other well-known internet services at the time.</p><p>By relying on third party age checking systems, which has become the standard approach, another entity is added to the data processing chain which in turn increases the lack of control one has over their data. These providers may state that they only use the data to verify identity, but from a user perspective it is difficult to verify if this is really true. Once the ID documents or selfies have been sent to their servers, the fate of that sensitive information is essentially in the hands of the service provider. This is especially if those providers are based in another country where data protection laws may be weaker or basically non-existent.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/why-substack-is-asking-for-your-age">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[You've just used ChatGPT, but do you know where your data goes?]]></title><description><![CDATA[The journey your information takes when using AI]]></description><link>https://www.thecybersolicitor.com/p/what-happens-to-your-data-when-you</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/what-happens-to-your-data-when-you</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 30 Jan 2026 09:02:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bbHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bbHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bbHT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bbHT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg" width="1456" height="2058" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2058,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1788965,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185216400?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bbHT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Jamillah Knowles &amp; Reset.Tech Australia / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>There a lot of people who do not know where their data goes when using an AI chatbot.</p><p>They will open up ChatGPT or Claude, type in their prompt, maybe attach some files, and watch this seemingly magical artificial entity generate a response that at least aligns with, but preferably exceeds, their expectations.</p><p>But in the midst of being so mesmerised, many will not bother to think what really happens inside that black box.</p><p>Not many people will really think about what happens to their data once they submit it to the machine.</p><p>Some people may say: &#8216;<em>who cares?</em>&#8216;</p><p>And maybe this is a reasonable response. Why care about the journey your information takes when it enters the complex bowels of a language model and gets transformed into new output rendered token-by-token to gradually build a response to your query? Surely all that matters here are the ends, not the means.</p><p>But the mistake with this mindset, if you have it, is that you are making some quite stark assumptions about those means.</p><p>You are assuming that the use of your data is within the realm of your expectations.</p><p>You are assuming that the use of your data is limited to simply running inference on the model to get the answer it thinks you need.</p><p>You are assuming that the the use of your data is sufficiently proper and ethical.</p><p>But what if these assumptions are wrong?</p><p>What if your data is being used for purposes that you did not expect and might even object to?</p><p>What if your data is being shared with other entities you did not even know were involved?</p><p>What if your data is out of your control?</p><p>Here is the painful truth when it comes to navigating our digital word: every time you use a digital service, you give up some data. And when you surrender your data to these digital systems, your agency over it automatically diminishes.</p><p>Moreover, you are giving your data up to systems built and controlled by others with incentives and priorities that may not be conducive to yours.</p><p>And control over your data also means control over your digital experience. Sometimes that experience may be absolutely fine, but the point is that this is not determined by you. It is determined by other people.</p><p>A few weeks ago, OpenAI announced that it would start displaying ads on ChatGPT.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/sama/status/2012253252771824074&quot;,&quot;full_text&quot;:&quot;We are starting to test ads in ChatGPT free and Go (new $8/month option) tiers.\n\nHere are our principles. Most importantly, we will not accept money to influence the answer ChatGPT gives you, and we keep your conversations private from advertisers.\n\nIt is clear to us that a lot&quot;,&quot;username&quot;:&quot;sama&quot;,&quot;name&quot;:&quot;Sam Altman&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1904933748015255552/k43GMz63_normal.jpg&quot;,&quot;date&quot;:&quot;2026-01-16T19:58:55.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{&quot;full_text&quot;:&quot;In the coming weeks, we plan to start testing ads in ChatGPT free and Go tiers.\n\nWe&#8217;re sharing our principles early on how we&#8217;ll approach ads&#8211;guided by putting user trust and transparency first as we work to make AI accessible to everyone.\n\nWhat matters most:\n- Responses in&quot;,&quot;username&quot;:&quot;OpenAI&quot;,&quot;name&quot;:&quot;OpenAI&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1885410181409820672/ztsaR0JW_normal.jpg&quot;},&quot;reply_count&quot;:4938,&quot;retweet_count&quot;:923,&quot;like_count&quot;:10142,&quot;impression_count&quot;:12896121,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>If you have been reading my content over the past few months, you would see how I have talked about such a decision becoming a reality. Investments in AI have been enormous, fuelled by the dramatic promises of generative AI. Companies like OpenAI, with Altman as the prime advocator, have been constantly glamourising their models as magical technologies that would solve so many of humanities great problems and become beacons of growth and progress.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3b0be8bd-c7f8-4d90-b179-900573acc54e&quot;,&quot;caption&quot;:&quot;Bubbles pop eventually.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;This is what happens when the AI bubble pops&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!jbJw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61582ad5-143e-4a5d-9e51-c20145b39d65_1167x1164.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-12-05T09:02:24.225Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:179728534,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>But in the end, when the hype fades away, OpenAI and others were always going to need to demonstrate to their investors how they were going to get returns on their investments. AI developers needed to show how they were actually going to make money with their products.</p><div class="comment" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/home&quot;,&quot;commentId&quot;:201100292,&quot;comment&quot;:{&quot;id&quot;:201100292,&quot;date&quot;:&quot;2026-01-17T14:31:05.841Z&quot;,&quot;edited_at&quot;:null,&quot;body&quot;:&quot;AGI (ad-generated income) &quot;,&quot;body_json&quot;:{&quot;content&quot;:[{&quot;content&quot;:[{&quot;text&quot;:&quot;AGI (ad-generated income) &quot;,&quot;type&quot;:&quot;text&quot;}],&quot;type&quot;:&quot;paragraph&quot;}],&quot;type&quot;:&quot;doc&quot;,&quot;attrs&quot;:{&quot;schemaVersion&quot;:&quot;v1&quot;}},&quot;restacks&quot;:2,&quot;reaction_count&quot;:6,&quot;attachments&quot;:[],&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;user_id&quot;:112131599,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!jbJw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61582ad5-143e-4a5d-9e51-c20145b39d65_1167x1164.jpeg&quot;,&quot;user_bestseller_tier&quot;:null,&quot;userStatus&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:5,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:5,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[1666375,458709,669567,356913,808767,4328580],&quot;subscriber&quot;:null}}}" data-component-name="CommentPlaceholder"></div><p>In the end, OpenAI has chosen a path that has worked very well for the tech companies before it. Google, Facebook and others turned to surveillance capitalism to strengthen their business models, involving the construction of data extraction systems that turned behavioural insights of users into revenue via targeted advertising. The cycle has simply repeated itself.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/signulll/status/2013082071636254889&quot;,&quot;full_text&quot;:&quot;so basically every ~decade we will get giant new internet ad businesses?\n\n2000&#8217;s - google\n2010&#8217;s - facebook\n2020&#8217;s - openai \n\nincredibly fascinating.&quot;,&quot;username&quot;:&quot;signulll&quot;,&quot;name&quot;:&quot;sign&#252;ll&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1717763325692383232/Jk2PKCx6_normal.jpg&quot;,&quot;date&quot;:&quot;2026-01-19T02:52:21.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:133,&quot;retweet_count&quot;:88,&quot;like_count&quot;:3025,&quot;impression_count&quot;:120178,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>If OpenAI is doing this, then the question of what actually happens to your data when you use ChatGPT and other tools like it really does become important.</p><p>The first step to solving any problem is to understand the problem really well. And to help with this, in this post I uncover the system that lies behind the chatbots that you are probably well-familiar with or at least heard of.</p><p>I set out the different components that make up the system, how they fit and work together, and how your data moves through the system when you use it. I also look at the data risks involved and some simple steps you can take to better-protect yourself.</p><p>This will be relevant to everyone who uses an AI chatbot. It does not matter if you are using it for throw-away personal questions or if you are part of the &#8216;shadow AI&#8217; clique at work. You need to know what happens to your data when you use a chatbot.</p><p>If you understand the systems you are engaging with, you put yourself in a better position to mitigate the risks. You cannot fully solve a problem unless you really understand the problem.</p><p>Make sure to share this newsletter with others if you find it valuable. And subscribe if you want more insights like this in your inbox every week.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/what-happens-to-your-data-when-you">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[You are reading legal docs wrong]]></title><description><![CDATA[A guide for beginners]]></description><link>https://www.thecybersolicitor.com/p/how-to-read-legal-docs</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/how-to-read-legal-docs</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 23 Jan 2026 09:01:32 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8ce0a3d9-a9dd-465a-8325-1bcec8bfae1d_500x333.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Let&#8217;s be honest, reading legal documents sucks.</p><p>When I say legal documents, I am referring to those documents you would have come across or at least heard about before. Think legislation or regulations, codes, contracts, policies and others.</p><p>Reading these documents is often a bit of a drag. I often find this to be the case, even as someone who reads such documents on a regular basis as part of my work. This struggle as three strands to it:</p><ol><li><p><strong>They are not always easy to read and understand.</strong> Legal documents often contain lots of legal jargon and technical terms. I have come to understand many of this, but there are certainly times where I will come across a provision that almost seems like it is written in a foreign language.</p></li><li><p><strong>They are too long.</strong> The length of document depends on the type of document. Legislation tends to be the longest, sometimes containing hundreds of provisions each of which could be several paragraphs long. Combined with the jargon, it can feel like it takes forever to get through a single piece of legislation.</p></li><li><p><strong>They are not always clear.</strong> The extended length combined with the extended jargon sometimes clouds the crux of the document. I will sometimes read provision after provision and lose sight of what the document is ultimately trying to convey and what is therefore important.</p></li></ol><p>That reading legal documents is often a pain is far from ideal.</p><p>These documents are important, as they describe the various rights and obligations that apply to you and others in a given situation. But when that crucial information is buried in a dense packaging of words entangled with alien concepts that take time to decipher, access to that information seems impossible. And this is even before thinking about the more difficult part, which is what actions you can take based on the obligations and rights that apply to you.</p><p>Even so, I think the ability to navigate the most tricky of legal documents is a skill that anybody can learn. There are certain principles you can follow and implement that help you to get through the task and identify the information that is most important for you. It may take a bit of time to get the hang of it, but I think investing the time is worth it given the importance of some of the legal documents you will need to read in your time, especially if you are a legal professional.</p><p>The principles and guidance that I share below are based on the time I have spent researching, writing and working on data rights over the past 10 years, and hopefully they prove valuable for you.</p><p>I should stress though that this newsletter does not constitute legal advice on which you should rely. You must obtain professional or specialist advice before taking, or refraining from, any action on the basis of the content in this newsletter.</p><h1>The big secret when reading legal docs</h1><p>Reading legal text is not the same as reading other types of text.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/how-to-read-legal-docs">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[No, AI is not about to delete all jobs. This is what happens instead.]]></title><description><![CDATA[AI presents challenges and opportunities]]></description><link>https://www.thecybersolicitor.com/p/how-you-can-thrive-in-the-age-of</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/how-you-can-thrive-in-the-age-of</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 16 Jan 2026 09:01:33 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/71f9559e-cefb-423f-8a14-84a6bf7b0649_3000x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NoW2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NoW2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 424w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 848w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1272w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NoW2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png" width="595" height="841" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:841,&quot;width&quot;:595,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105531,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/183140316?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NoW2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 424w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 848w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1272w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI will kill all lawyers.</p><p>This was the title of an <a href="https://spectator.com/article/ai-will-kill-all-the-lawyers/">article</a> in the <em>Spectator</em> that I recently read. And it prompted some thoughts. Many thoughts.</p><p>The article gives the views of an anonymous English barrister on AI and legal practice. And the picture he gives is pretty gloomy: AI will &#8216;completely destroy&#8217; the law as we know it.</p><p>Why such a stark warning? It is based on this particular barrister&#8217;s recent experience using AI for legal work, as he explains:</p><blockquote><p>&#8216;Last week we did an experiment, a kind of simulation. We took a real, recent and important case &#8211; a complex civil court appeal which I wrote, and it took me a day and a half. We redacted all identifying details, for anonymity and confidentiality, and we fed the same case to Grok Heavy AI. And then we asked it to do what I did. After some prompting, the end result was&#8230;&#8217; He shakes his head. &#8216;Spectacular. Actually staggering. It did it in 30 seconds, and it was much better than mine. And remember, I am very good at this.&#8217;</p><p>[...]</p><p>&#8216;It was at the level of a truly great KC. The best possible legal document. And all done in seconds for pennies. How can any of us compete? We can&#8217;t.&#8217;</p></blockquote><p>Lawyers belong to one of the most conservative, risk-averse and arguably outdated professions that exist. They are used to holding high positions in society because their services are so necessary; as long as we have societies organised by a large, complex body of rules, we need people who can understand them and provide guidance on how to follow those rules.</p><p>Or do we?</p><p>Because if you read this barrister&#8217;s view on AI and its potential impact on the legal profession, you may think that if AI can do just as good as a qualified legal expert, then what is the point of having these experts?</p><p>You could go further: what is the point of knowledge work done by humans if we can get AI to do it?</p><p>These general-purpose machines, trained on massive amounts of data with huge amounts of computing power, seem capable of pretty much any cognitive task a human could do. Just feed it the right prompt and you have your desired output, produced in seconds or minutes at the most and on the cheap.</p><p>But as I was reading this <em>Spectator</em> article, I could not help but notice a rather glaring omission which reveals why &#8216;AI displacement&#8217; is more complicated than what some people present.</p><p><strong>AI is not about to take everyone&#8217;s job.</strong></p><p>Those who believe in a mass exodus where AI renders human roles completely redundant are not thinking carefully enough about what AI is and the impact it can actually have.</p><p>AI can do many things. And it can do many things really well.</p><p>But it cannot do everything. This is the simple truth.</p><p>This means that AI should really be seen as a force multiplier, not a replacement.</p><p>And this is the case even for the legal profession.</p><p>To thrive in the age of AI is to understand AI&#8217;s limitations as well as its capabilities and the gaps it therefore creates in our society.</p><p>Those gaps are where humans still have an important role to play, whether this is in the legal industry or any other domain where AI is being deployed.</p><p>In this newsletter, I cover three core ideas about how to navigate the trials and tribulations of AI in our modern world:</p><ul><li><p>What AI <em>can</em> do</p></li><li><p>What AI <em>cannot</em> do</p></li><li><p>What <em>you</em> should do</p></li></ul><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to this newsletter for reliable information on the legal and societal implications of modern technology sent to your inbox every week</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/how-you-can-thrive-in-the-age-of">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The most important thing for AI in 2026]]></title><description><![CDATA[What is overlooked when building modern machines]]></description><link>https://www.thecybersolicitor.com/p/the-most-important-thing-for-ai-in</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-most-important-thing-for-ai-in</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 12 Dec 2025 09:01:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jIHr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jIHr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jIHr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 424w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 848w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1272w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jIHr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png" width="1456" height="2054" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2054,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8570819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/181077893?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jIHr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 424w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 848w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1272w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Lone Thomasky &amp; Bits&amp;B&#228;ume / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>Most people will be focusing on the wrong things when it comes to AI in 2026.</p><p>Most people will be focusing on the emerging paradigms, the new breakthroughs, or the next groundbreaking model claimed to be AGI.</p><p><em><strong>They are wrong</strong></em><strong>.</strong></p><p>What is far more important is something that too often gets overlooked. Something that is lethally ignored until it is too late. Something that, if done well, unlocks the real power of AI in a way that is not only sustainable but beats 99% of the competition.</p><p>To build good AI products, it is a mistake to obsess over the latest and greatest models. Chip Huyen, an experienced computer scientist and author of <em>AI Engineering: Building Applications with Foundation Models</em>, makes this point exactly. <a href="https://www.linkedin.com/posts/chiphuyen_aiapplications-aiengineering-activity-7358971409227792384-y0mf/">For her</a>, the things that actually contribute to better AI products are talking to users, building a more reliable platform, using better data, optimising for end-to-end workflows and writing better prompts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RKTM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RKTM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 424w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 848w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1272w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RKTM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png" width="1456" height="539" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:539,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:297192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/181077893?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RKTM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 424w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 848w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1272w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you want customers to invest in your product, they need to be a position to trust your product. When the hype and bravado eventually fade away, trust is the currency that keeps customers around.</p><p>What all this means is that the most important thing for AI developers to focus on in 2026 and beyond is <em>governance</em>.</p><p>This is not because it is required by law. Or because it is a &#8216;nice-to-have&#8217;. Or even because it is good for PR.</p><p>Governance is a business-enabler. It is a way of deepening moats. It is the <a href="https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium">dynamic equilibrium</a> that balances innovation and order.</p><p>Good governance is what underpins good, reliable AI products that actually work, build trust and deliver value.</p><p>As my last newsletter for 2025, I want to look to 2026 and what I think is next for AI from a data rights and governance perspective. I want to share what I think the AI landscape will probably look like, the problems it will produce, and why governance is <em>the</em> way to solve them.</p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-most-important-thing-for-ai-in">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This is what happens when the AI bubble pops]]></title><description><![CDATA[After the hype comes the reckoning]]></description><link>https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 05 Dec 2025 09:02:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FFEz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FFEz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4173113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/179728534?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FFEz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dominika &#268;upkov&#225; &amp; Archival Images of AI + AIxDESIGN / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>Bubbles pop eventually.</p><p>When the dot-com bubble popped in 2000, it caused the <a href="https://www.investopedia.com/terms/d/dotcom-bubble.asp">worst decline</a> in the NASDQ&#8217;s history, dropping by more than 70%. Many companies that had so confidently slapped &#8216;.com&#8217; on the end of their names suddenly had to face a reckoning, and many did not survive.</p><p>They did not survive because aesthetics would only get them so far. The shiny new object, which back then came in the form of a website on the world-wide web, would eventually need to prove its worth.</p><p>A bubble popping represents a reversion back to reality and fundamentals, and that is when the promises and predictions of technology are really tested.</p><p>And one of the more significant players carrying out this testing are investors. Having a cool product with potential is fine on Day 1. But on <a href="https://signull.substack.com/p/day-0-is-loud-day-2-is-real">Day 2</a>, investors are looking at the prospect of their returns. They want to know what they will end up getting out of it all.</p><p>Google was no exception to this.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[AI procurement from first principles]]></title><description><![CDATA[Being careful about the systems you use]]></description><link>https://www.thecybersolicitor.com/p/ai-procurement-from-first-principles</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-procurement-from-first-principles</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 28 Nov 2025 09:01:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kjzI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kjzI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kjzI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kjzI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5336570,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/179723086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kjzI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Jamillah Knowles &amp; Digit / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>With the AI boom and hype comes many AI systems. Some are built for general-purpose use - household names like ChatGPT and Claude may come to mind. Others are designed for more specific use cases, like <a href="https://robinai.com/">RobinAI</a> (for contract review) or <a href="https://cursor.com/">Cursor AI</a> (for writing code).</p><p>The plethora of systems available provide plenty of opportunities for organisations to innovate. AI can help produce new products or services or improve existing processes for building products or services.</p><p>Such opportunity still exists despite organisations needing to resort to the use of systems built by others. It might sometimes be preferable to develop your own system specifically built for your own use case with your own data, giving you a wide range of customisability. However, these systems built by the likes of OpenAI and Anthropic still come with plenty of flexibility. Their models are general-purpose which can be built on top of, fine-tuned or engineered with <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents">context</a> and other tools to construct systems for a range of domains.</p><p>But with this opportunity comes risk, and these risks are just not limited to those which are legal in nature. AI development is itself an empirical science, whereby assessing behaviour and performance can only really be done by using models and monitoring them post-deployment. Models are often characterised as black-boxes possessing a level of complexity that renders them opaque and difficult to control. This can mean that AI systems risk failing to meet important business and legal requirements, with potentially significant consequences; poor ROI, user complaints and even regulatory intervention and legal action.</p><p>And so with these risks come responsibility. As Ethan Mollick notes in his book <em>Co-Intelligence: Living and Working with AI</em>, with AI becoming increasingly capable, &#8220;we&#8217;ll need to grapple with the awe and excitement of living with increasingly powerful alien co-intelligence.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>For organisations procuring AI systems, this responsibility comes in the form of being aware of what you buy. In the world of AI, the principle <em>caveat emptor</em> (&#8217;buyer beware&#8217;) is crucial.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-procurement-from-first-principles">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[AI agents and the AI Act]]></title><description><![CDATA[Is agentic AI even in scope of Europe's AI regulation?]]></description><link>https://www.thecybersolicitor.com/p/ai-agents-and-the-ai-act</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-agents-and-the-ai-act</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 21 Nov 2025 09:02:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6lEp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6lEp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6lEp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 424w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 848w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1272w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6lEp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5582868,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/179488040?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6lEp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 424w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 848w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1272w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Nadia Piet  &amp; Archival Images of AI + AIxDESIGN / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>2025 was supposed to be the year of agents.</p><p>Generative AI (genAI), central to the current AI hype cycle, represents a significant leap from the previous generation of AI. It took AI from systems that could recognise patterns and ma&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-agents-and-the-ai-act">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The GDPR and AI exceptionalism]]></title><description><![CDATA[Some initial reflections on the (leaked) proposed changes to the EU GDPR]]></description><link>https://www.thecybersolicitor.com/p/the-gdpr-and-ai-exceptionalism</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-gdpr-and-ai-exceptionalism</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 14 Nov 2025 09:01:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OOIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OOIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OOIy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 424w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 848w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1272w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OOIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png" width="1456" height="2055" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2055,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13728388,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/178542964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OOIy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 424w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 848w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1272w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Lone Thomasky &amp; Bits&amp;B&#228;ume / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>So the European Commission is exploring ways to simplify several different EU laws as part of its &#8216;Omnibus&#8217; reform package, and one of the <a href="https://media.licdn.com/dms/document/media/v2/D4E1FAQEwYB4tX7QQyw/feedshare-document-pdf-analyzed/B4EZpehBTyGYAY-/0/1762522312826?e=1763596800&amp;v=beta&amp;t=8G6MKk0PZNGPKhvnvcG3zrtGv7kfvBE31VWMUBkSM-8">drafts</a> for this was leaked last week.</p><p>There are some interesting things to note from this leak. The part that sto&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-gdpr-and-ai-exceptionalism">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Governance = dynamic equilibrium]]></title><description><![CDATA[Engineering vs lawyerly societies]]></description><link>https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 07 Nov 2025 09:00:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1c9937c5-3d30-4912-8dfe-aee831238a26_325x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I recently started reading Dan Wang&#8217;s book <em>Breakneck</em> and it got me thinking about the role that data rights professionals play in the current tech eco-system.</p><p>Th first chapter is titled &#8216;Engineers vs. Lawyers&#8217; and Wang uses this frame to convey the contrast between progress in China and progress in the US. China is an engineering society, while the US is&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>