<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Cyber Solicitor: AI Governance]]></title><description><![CDATA[Everything on AI]]></description><link>https://www.thecybersolicitor.com/s/ai-gov</link><image><url>https://substackcdn.com/image/fetch/$s_!T4HV!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png</url><title>The Cyber Solicitor: AI Governance</title><link>https://www.thecybersolicitor.com/s/ai-gov</link></image><generator>Substack</generator><lastBuildDate>Tue, 28 Apr 2026 19:44:13 GMT</lastBuildDate><atom:link href="https://www.thecybersolicitor.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Mahdi Assan]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[thecybersolicitor@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[thecybersolicitor@substack.com]]></itunes:email><itunes:name><![CDATA[Mahdi Assan]]></itunes:name></itunes:owner><itunes:author><![CDATA[Mahdi Assan]]></itunes:author><googleplay:owner><![CDATA[thecybersolicitor@substack.com]]></googleplay:owner><googleplay:email><![CDATA[thecybersolicitor@substack.com]]></googleplay:email><googleplay:author><![CDATA[Mahdi Assan]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[AI will make privacy great again]]></title><description><![CDATA[This is how consumer AI survives]]></description><link>https://www.thecybersolicitor.com/p/ai-will-make-privacy-great-again</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-will-make-privacy-great-again</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 24 Apr 2026 08:02:46 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!q80m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q80m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q80m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!q80m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!q80m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!q80m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q80m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg" width="1456" height="996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:996,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:300935,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/195284556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q80m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!q80m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!q80m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!q80m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23a3c235-9463-4654-9630-06efffff8bc6_2736x1872.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Privacy is going to have a renaissance in the age of AI.</p><p>Privacy and data protection will need to be built into AI apps and tools such that they become integral parts of the user experience.</p><p>They will become indispensable. Not add-ons or after-thoughts. Top priority requirements.</p><p>This view is not easy to appreciate because most people see privacy and data protection as relics of a distant past. As our digital world evolves, the concept of responsible and ethical use of people&#8217;s data falls further into a black hole of data maximisation, function creep and invisible processing.</p><p>Companies grab whatever data they can, use it for whatever purposes they want and all without the data subject&#8217;s knowledge.</p><p>This is the current state of affairs when it comes to privacy and data protection - nobody seems to really care.</p><p>But this is not entirely true.</p><p>In terms of the different attitudes towards privacy data and protection, you can broadly fit companies into three categories:</p><ol><li><p><strong>Those that care but struggle with it.</strong> They want to be compliant but find the frameworks burdensome, expensive, fragmented, and unpredictable.</p></li><li><p><strong>Those that don&#8217;t care because they&#8217;ve made a rational calculation.</strong> They&#8217;ve looked at the expected cost of non-compliance (probability of enforcement multiplied by severity of penalty), compared it to the opportunity cost of diverting resources from product to compliance, and concluded that privacy and data protection is not worth prioritising yet. They&#8217;re not necessarily opposed to compliance; they just don&#8217;t think it&#8217;s material at their stage.</p></li><li><p><strong>Those that don&#8217;t care because privacy and data protection have never been made to feel important.</strong> These companies haven&#8217;t even run the calculation of the second group. Compliance exists in a category of things they&#8217;ve filed under &#8220;boring, abstract, probably not relevant to me right now.&#8221; It&#8217;s homework. Nobody does homework voluntarily.</p></li></ol><p>There are not many companies in the first group, there are slightly more in the second, but a lot are in the third group.</p><p>And you might think AI will only continue this trend. AI development has so far encouraged norms and practices that vanquish basic data protection principles, including purpose limitation, data minimisation and so on.</p><p>But this might be about to change.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-will-make-privacy-great-again">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[AI slop is a choice]]></title><description><![CDATA[It is your job to keep the human in the machine]]></description><link>https://www.thecybersolicitor.com/p/ai-slop-is-a-choice</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-slop-is-a-choice</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 17 Apr 2026 08:02:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5n1T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5n1T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5n1T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5n1T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg" width="1456" height="996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:996,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:225158,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/194446873?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5n1T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5n1T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec9d311-1e7d-4abb-9b0b-d5920a0e32f6_2736x1872.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>I changed my mind on AI. And you probably should too.</p><p>When ChatGPT first came out and was blowing up, I wasn&#8217;t all that impressed. I tried it a few times and thought it was cool but did not see the value in talking to a chatbot apart from asking random useless questions.</p><p>I had come across these GPTs before. They came up during some research I was doing on how security and intelligence agencies were using AI for their operations. A <a href="https://static.rusi.org/ai-national-security-final-web-version.pdf">2020 report</a> by the Royal United Services Institute detailed how AI could be used by such agencies for &#8216;cognitive automation&#8217; in which AI can help analyse large volumes of data. It mentioned in this context OpenAI&#8217;s GPT-2 and how this model could be used for language analytics purposes, including for analysing transcriptions of captured audio. But not much else was written on the matter, and so I never looked into these language models any further at the time.</p><p>And then a short time later in 2022 when a wave of generative products came crashing in, including DALL-E 2, Midjourney and of course ChatGPT, I was wholly sceptical. Suddenly there was lots of talk about artificial general intelligence, AI safety, the prospect of AI taking all of our jobs and so on. But my understanding and interest remained fairly limited, and so I interpreted much of this as hype that should not be taken all that seriously.</p><p>And this is the attitude I had for a long time, barely using the tools whilst I stood to the side and criticised. I would read about AI but hardly use it myself.</p><p>It is the classic move for most people working in tech law and policy - dealing with the object of that to be governed at arms length and with only a minimal understanding of its mechanics. It is like the difference between static and dynamic analysis of an application. Legal professionals tend to be stuck constantly doing the former and therefore largely ignorant to how these AI systems work in real-world environments.</p><p>And there is little motivation to see it any other way. Legal experts are relied on for their risk-aversion and being able to see the worst case scenarios so that they can be mitigated against or avoided. Seeing AI this way is not particularly inspirational and certainly does not encourage one to actually want to test out these systems for themselves.</p><p>Eventually my passivity passed though and I decided that instead of sitting on the sidelines, I was going to get stuck in.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MSd8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MSd8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MSd8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2666803,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/194446873?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MSd8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!MSd8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3af58741-f6d2-425d-bf5b-7e2c0b9d355f_1920x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is when I started experimenting with AI for tasks that I wanted to either offload or make much easier to do.</p><p>Among these experimentations included building an AI workflow for GDPR vendor reviews, a rather tedious and time-consuming task. I was able to work out the appropriate instructions and harnessing, with safeguards for reducing hallucinations whilst also making verification straightforward.</p><p>At this point I was no longer just talking about AI from a distance. I was enhancing my understanding through hands-on experience, something most legal professionals would not think to do.</p><p>The challenge I have ran into now, however, is not a technical one. Using AI is something I feel far more comfortable with now, and my experimentation with it will no doubt continue.</p><p>The challenge I now face is whether my increased use of AI is actually a good thing.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-slop-is-a-choice">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The quiet principles behind quality AI adoption]]></title><description><![CDATA[Slow down. Think first. Then build.]]></description><link>https://www.thecybersolicitor.com/p/the-quiet-principles-behind-quality</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-quiet-principles-behind-quality</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 10 Apr 2026 08:01:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5Ana!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Ana!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Ana!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Ana!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg" width="1456" height="996" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:996,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:360749,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/193490632?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Ana!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5Ana!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0a1048-259a-4047-897f-571c5056fc98_2736x1872.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>People often get distracted by the shiny new object.</p><p>The evidence that this is happening with AI is undeniable at this point.</p><p>CEOs and senior leaders get dazzled by the stories told by the frontier labs. Predictions are abound that these AI systems are so capable that they will replace <em>all</em> knowledge workers. New models or features get released and SaaS stocks tank. Some companies go as far as engaging in massive layoffs, thinking that large chunks of the workforce can be replaced by an army of cheaper AI agents.</p><p>AI has many advantageous of course. Despite being a legal professional and trained to see things with a more risk-averse eye, I can still see the various ways that AI can boost productivity, help make sense of unstructured information and uncover blindspots in my thinking.</p><p>But I can also see that AI does not solve all problems at once. It is not a silver bullet.</p><p>Like any other piece of technology, AI has its limitations. Hallucinations, getting stuck in recursive loops and all the quirks that come with operating large, non-deterministic systems programmed implicitly.</p><p>We are still in the very early days in terms of AI diffusion and adoption. Most people are not heavy users of AI, and therefore a minority know how to use it well.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7p64!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7p64!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7p64!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7p64!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg" width="1280" height="1486" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1486,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:242107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/193490632?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7p64!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 424w, https://substackcdn.com/image/fetch/$s_!7p64!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 848w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!7p64!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82e7a189-19f5-4fcc-be18-a1a4a471d192_1280x1486.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And it is because of this that most people do not understand what AI is and what it is not.</p><p>It is not this magical machine that you can one-line prompt and it will immediately give you everything you need.</p><p>Yet some people basically have this perception of AI, probably because of the way it gets hyped by its developers. This mistaken perception leads to AI being treated as a solution looking for a problem.</p><p>The erroneous thinking here is something like this:</p><blockquote><p><em>Because AI is apparently so amazing, and because everyone is using it, then surely I or our organisation can also use and benefit from it too?</em></p></blockquote><p>This is a trap driven by FOMO and exacerbated by clouded judgment.</p><p>However, this is not just a case of misunderstanding the technology that AI is. I think there are other important aspects at play here.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-quiet-principles-behind-quality">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[What really comes with ads inside ChatGPT]]></title><description><![CDATA[The monetisation of cognition is here]]></description><link>https://www.thecybersolicitor.com/p/what-really-comes-with-ads-inside</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/what-really-comes-with-ads-inside</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 27 Mar 2026 09:00:45 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/24b60325-9fee-4fb6-9458-b1969bcb4809_3186x1794.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Technology is not neutral.</p><p>The way a piece of technology is built and and how it works is always downstream of the incentives, opinions and choices of its builders and the context they are operating in. This is an obvious point that is often forgotten.</p><p>That technology is not neutral sometimes allows us to trace the impacts of technology back to the actions and thinking of its builders. Understanding the incentives, opinions and choices of these people is key for understanding why technology develops in a certain way or why it has certain impacts.</p><p>This backdrop is important when thinking about how the internet and digital products and services look today. Many of the products and services we have become accustomed to over the years are available for no upfront monetary cost for users. Search engines, social media platforms, and now AI chatbots all have free versions that essentially anyone with an internet connection can use.</p><p>But much of this free internet as we know it has been powered by ads. Google was one of the first companies to really work out how to build a business model that enabled its product to be free to use whilst still generating revenue. It figured out how to make revenue-generation essentially invisible to users yet still providing and updating a useful product.</p><p>And now OpenAI is doing the same by introducing ads to ChatGPT. The AI provider is currently rolling this out to ChatGPT free and Go users, with advertisers <a href="https://www.reuters.com/business/media-telecom/openai-expand-ads-chatgpt-all-free-low-cost-users-information-reports-2026-03-21/">reportedly</a> committing between $50,000 to $100,000 in ad spend.</p><p>The reasoning for implementing ads is similar to the constraints that Google and others had to face in the journey to profitability. However, I think the nature of its implementation for AI systems like ChatGPT will be different.</p><p>OpenAI&#8217;s pivot to ads is a sign of the reality they face - they need a reliable way to generate revenue. The company needs a way to cope with the immense increases in infrastructure spend on top of the high level of investments it has secured over the years. It would seem that subscriptions and enterprise deals are not sufficient.</p><p>Maybe OpenAI&#8217;s mission is still to build AGI eventually. But it may not survive to achieve this feat unless it develops a workable business model in the meantime to fund and power its efforts toward this grand milestone.</p><p>Google faced a similar problem in its early days. It bulked up its ad businesses due to pressure from investors and the need to somehow make money from its product.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;50733dff-5a3e-4d33-a9e2-7da475dcae81&quot;,&quot;caption&quot;:&quot;Bubbles pop eventually.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;This is what happens when the AI bubble pops&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-12-05T09:02:24.225Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:179728534,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>When it comes to ads on Google, these are aligned to inferences made about users based on what the queries they enter into the search engine. On social media platforms, these inferences are derived from a wider range of user activity, including the people they follow and the content they engage with.</p><p>Ads in AI chatbots will be aligned to something different, something much deeper and higher-resolution than the data points that search engines or social media platforms can utilise.</p><p>AI ads will be aligned to a user&#8217;s actual thoughts, something very distinct from the search queries, social graphs and engagement metrics of yesteryears.</p><p>In this newsletter I go through this argument and explore:</p><ul><li><p>How AI systems sit closer to user intentions than any other system</p></li><li><p>Why AI ads are inevitable</p></li><li><p>What happens to data rights</p></li></ul>
      <p>
          <a href="https://www.thecybersolicitor.com/p/what-really-comes-with-ads-inside">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[What you missed from Anthropic's fight with Trump]]></title><description><![CDATA[The power inversion, illusory guardrails and state surveillance]]></description><link>https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 20 Mar 2026 09:02:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Sy6k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Sy6k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Sy6k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1085013,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/191517288?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Sy6k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!Sy6k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2abaf4c-5c45-48d5-93bd-ac6fa280e361_1280x720.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image from <em><a href="https://www.yahoo.com/news/articles/anthropic-pentagon-showdown-drawing-silicon-153122475.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAALYWM5ONYvWL0FQUC8Mo71QrsNs3arzlsbVM1e-FZfAie0_pm395Z2Is7MEyZtLXh1XnG9LqPCP_qqcMTUTeNNW1V6NRlrYPkJbwSCGwUqOpQnVhhB31q3em51ltZAlA2OyYDWm7CG3rtEE4pvXCWYsLYLgA8BnKAEYw2_vfv58F">Yahoo! News</a></em></figcaption></figure></div><p>The conflict between Anthropic and the US Government is a big deal, but not in the way that most people think.</p><p>It is not just a contract disagreement or an AI ethics debate. I think it represents something bigger.</p><p>To give a very simplified overview of what happened between Anthropic and the US Department of War:</p><ul><li><p>In mid&#8209;2025, the Pentagon awards large multi&#8209;year AI contracts (up to about 200 million dollars each) to several firms, including Anthropic, to help build out military AI capabilities</p></li><li><p>As the government builds an internal generative&#8209;AI ecosystem (often described as GenAI.mil), negotiations focus on how broadly military users can deploy Anthropic&#8217;s models</p></li><li><p>The Department insists on &#8220;all lawful uses&#8221; language; Anthropic agrees except for two red&#8209;lines: no mass domestic surveillance and fully autonomous lethal weapons - these safety guardrails become the core of the dispute</p></li><li><p>The administration publicly hardens its stance, promoting an &#8220;AI&#8209;first&#8221; warfighting strategy and rebranding rhetoric around the Pentagon as the &#8220;Department of War,&#8221; signaling a more aggressive doctrine</p></li><li><p>In late February 2026, defense officials issue Anthropic an ultimatum: remove the contractual bans on mass domestic surveillance and autonomous lethal weapons or risk severe consequences</p></li><li><p>Anthropic refuses before the deadline, reiterating that those uses are outside what its models can safely or ethically support</p></li><li><p>After talks break down, the administration orders federal agencies to stop using Anthropic&#8217;s AI tools and begin transitioning away over several months</p></li><li><p>The Department of War designates Anthropic a &#8220;supply chain risk to national security,&#8221; a label normally associated with foreign adversaries; this effectively bars defense contractors from using Anthropic products in government work</p></li><li><p>Anthropic publicly rejects the designation as unlawful and politically motivated, arguing it is being punished for insisting on safety guardrails</p></li><li><p>In March 2026, Anthropic files suit against the U.S. government, challenging the supply&#8209;chain&#8209;risk classification and seeking to protect its right to limit high&#8209;risk military uses of its AI</p></li></ul><p>I&#8217;ve read good takes on the situation by various writers here on Substack. You shoudl also check out the coverage from <a href="https://insights.priva.cat/p/anthropic-will-probably-survive-trumps">Privacat</a>, <a href="https://jasmi.news/p/ai-pentagon">Jasmine Sun</a> and <a href="https://www.hyperdimensional.co/p/clawed">Dean W. Ball</a>, just to name a few.</p><p>When reading all of this commentary, what came to mind was an overarching set of themes that could be threaded together.</p><p>In fact, the fight between Anthropic and USG felt quite familiar to me. My gateway into tech law and policy was state surveillance and the Snowden revelations in 2013. I became fascinated with the way technology and law collided together, a convergence of forces that advance and organise our societies.</p><p>This for me signalled one of the most important questions of our time (for which I have quoted Jamie Susskind, author of <em>Future Politics: Living Together in a World Transformed by Tech</em>, many times before because he puts it far me eloquently than I have):</p><blockquote><p><em>To what extent should builders of powerful digital systems be concerned with data rights, and what does this look like in practice?</em></p></blockquote><p>What I see here with <em>Anthropic vs USG</em> are three converging patterns:</p><ol><li><p>The state depends on private tech firms more than the reverse, and this will only continue in the future</p></li><li><p>Safety guardrails for LLMs are somewhat of a technical illusion that creates a big governance gap</p></li><li><p>LLMs could bring surveillance, whether by the state or other entities, to a whole new level</p></li></ol><p>In this newsletter, I cover these three conversing ideas (power inversion, safety guardrails and the evolution in surveillance) and how <em>Anthropic vs USG</em> is a glimpse at the defining tension of the 21st century.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/what-you-missed-from-anthropics-fight">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This is why your AI governance policy sucks]]></title><description><![CDATA[And this is how to fix it]]></description><link>https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 13 Mar 2026 09:02:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/bf3f1df2-75ab-445d-bf52-73293794a163_960x554.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Lots of organisations are yet to sort out their AI governance.</p><p>Many might be excited about adopting AI, or anxious that not doing so will leave them far behind the competition.</p><p>So they start ideating and brainstorming about how these systems could be used to improve internal processes or create better products for customers.</p><p>In doing so, some will have the foresight to think about the importance of governance - there should be a focus on building the thing the right way and not just building anything.</p><p>But then this is where organisations make the biggest mistake when starting their AI governance journey.</p><p>They start by drafting a policy.</p><p>Maybe they look for a template online. Or maybe they even use AI to generate one for them.</p><p>They draft it, put is somewhere on their intranet, and then that&#8217;s it. They think they have completed governance and now they can just focus on building or using their AI systems however they like.</p><p>Simple, right?</p><p>Well not really.</p><p>Policies are just words. They might represent the principles, rules, guardrails and standards you want to follow when building or using AI. But these things alone are simply not enough.</p><p>These things just represent intentions.</p><p>And while crystallising intentions in a formal document that everyone agrees to follow is important, starting your governance journey with a policy means that your policy will not be:</p><ol><li><p>Aligned with how your organisation is using and/or developing AI systems</p></li><li><p>Backed up by practical measures that implement the policy</p></li><li><p>Actually known, understood and respected by staff</p></li></ol><p>Without these things, your AI governance framework just never really gets going.</p><p>If you want to get AI governance right, do not start by writing a policy. You need to do other things alongside the drafting of the policy that will make your AI governance framework actually work.</p><p>You need to at least:</p><ul><li><p>Understand the state of play in your organisation</p></li><li><p>Develop an AI strategy</p></li><li><p>Build and implement the right measures (organisational, technical and legal)</p></li><li><p>Establish feedback loops</p></li></ul><p>In this newsletter, I go through each of these steps, including why they are needed and what they entail. If you like this content, make sure to share it with others who might also benefit.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/this-is-why-your-ai-governance-policy">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Tasteful AI governance]]></title><description><![CDATA[Yes, there is such a thing. And this is what it looks like.]]></description><link>https://www.thecybersolicitor.com/p/tasteful-ai-governance</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/tasteful-ai-governance</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 06 Mar 2026 09:01:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Mviz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mviz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mviz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 424w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 848w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mviz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8694896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189814918?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mviz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 424w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 848w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1272w, https://substackcdn.com/image/fetch/$s_!Mviz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4c7c16a2-68fa-4c52-bfde-daa3cb343333_3840x2160.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Linus Zoll &amp; Google DeepMind / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>If you have been paying attention to the AI rhetoric these days, you will have likely heard a lot of people talk about &#8216;taste&#8217;.</p><p>I myself started seeing this concept being banded around for a while, and an increasing amount at the beginning of the year with all the craze around Claude Code.</p><p>Claude Code opens the door for everyone to build (almost) anything. And this opportunity is not just available to those who know how to code - you simply need natural language to get going. Explain what you want built, and the coding agent will do the rest.</p><p>But with AI taking away the expense and friction of execution, focus has now moved to the other parts of problem-solving with code. Because in a world where you can now build (almost) anything, what matters more than ever is building the right thing in the right way.</p><p>And this got me thinking; there seems to be such a thing as having good taste in AI development and deployment, which I do think is genuinely important. But what about having good taste when it comes AI governance? Is there even such a thing?</p><p>Initially, I thought this was a silly idea. Taste connotes creativity, imagination and novelty. These are not words that people think of when they think of governance. On the contrary they might instead think: onerous, tedious and a blocker.</p><p>However, the more I thought about it, the more I realised that taste in governance is not only real, but crucial.</p><p>Governance without taste fulfils the dreary perception that most have about the field.</p><p>Governance with taste fulfils legal requirements but also helps unlock the full potential of AI.</p><p>Tasteful governance melts the idea that legal professionals are mere luddites who stifle products and demonstrates a way to balance the engineering and lawyerly incentives.</p><h1>What tasteful governance actually means</h1><p>For me, taste is essentially a filtering mechanism.</p><p>Over time, you accumulate various bits of knowledge from the work you do. You build an understanding of the different problems that you or your clients face as well as the appropriate solutions to them.</p><p>These problems and corresponding solutions are compressed into retrievable principles and samples that can be applied to new sets of problems you encounter later on.</p><p>Taste is therefore a way of deciding how to sample from that knowledge base. It is about selecting the learned principles and samples from previous work that are most appropriate for the present work.</p><p>This is how taste works in other domains too, whether it be music, movies or people. Of all the music one has listened to, of all the movies one has watched, and of all the people one has interacted with, they know how to pick well by using a learned criteria that helps distinguish between the good, the decent and the bad.</p><p>Taste is therefore the ability to pattern-match, abstract and see the signal in the noise in various situations based on past learnings.</p><p>To apply this to governance, taste is not just about knowing what the law says. That is the easier bit really. You look up the correct rules for a client&#8217;s given situation and interpret their meaning accurately.</p><p>It is the next bit where taste is important - knowing <em>how</em> to implement the rules. And this task requires creativity, context-sensitivity and commercial awareness to not merely come up with <em>a</em> solution, but <em>the</em> solution. That is tasteful governance in a nutshell.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/tasteful-ai-governance">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Why Your AI System Might Not Contain Personal Data (Even Though It Does)]]></title><description><![CDATA[A compliance strategy based on ignorance]]></description><link>https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 27 Feb 2026 09:01:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NVdt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NVdt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NVdt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NVdt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:994150,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NVdt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NVdt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F969d9756-bacf-46f8-a3c8-624deb610187_2560x1440.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Anne Fehres and Luke Conroy &amp; AI4Media / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>The idea that LLMs &#8216;contain&#8217; personal data was always an ambitious take.</p><p>Probably.</p><p>When I first looked at this topic a little over a year ago, I was not sure where I stood. I thought that the implications of concluding that models did not include personal data were simpler, thereby making that conclusion much more attractive. You can read my newsletter on this here:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;012829a2-c642-449c-8d67-c28660cb5b86&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about whether large language models (LLMs) store personal data they may have been trained on. It looks at how LLMs work, the definition of personal data under the GDPR and the various arguments around this issue.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Do LLMs store personal data?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2024-10-25T08:01:11.992Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ySu3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849f6431-05b8-4950-af53-c41745ffc41c_3840x2743.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/do-llms-store-personal-data&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:150681988,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:8,&quot;comment_count&quot;:7,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>If you have no idea what I am talking about, I explain everything in the newsletter linked above. But this is the gist:</p><ul><li><p>LLMs are trained on lots of data, much of which is scraped from the internet</p></li><li><p>In that training data is lots information that would constitute personal data under the EU&#8217;s GDPR</p></li><li><p>There is an argument that, if that personal data is used for training the model, the resulting trained model &#8216;contains&#8217; the personal data it was trained on</p></li><li><p>If the model contains personal data, and that model is used by another entity, then that entity may be processing personal data</p></li><li><p>The point made in my previous newsletter on this is that this is all quite complicated and I was never convinced one way or another; whether models do or do not contain personal data</p></li></ul><p>But now my thoughts have evolved since the decision by the Court of Justice of the European Union (CJEU) in <em>EDPS vs SRB</em>, which I have also written about (twice):</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e3a9a1a9-020f-4674-83fe-a17378dc0316&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about a pseudonymisation and personal data. It looks at a recent AG opinion on the matter and the implications this has for on-device processing and encryption.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is pseudonymised data personal data?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-02-14T09:02:42.110Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!Zf7i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba15688-2a77-44da-b9b4-2b97398a7b3e_2560x1270.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/is-pseudonymised-data-personal-data&quot;,&quot;section_name&quot;:&quot;Data Rights&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:157088951,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:1,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;ace812ad-2585-4318-8782-aefd232d0fc7&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about a decision by the Court of Justice of the European Union (CJEU) in EDPS v SRB. It looks at the Court's view on how the GDPR applies to pseudonymised data and the implications this has for certain data processing activities.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Is pseudonymised data personal data? (Part 2)&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-09-12T08:02:37.163Z&quot;,&quot;cover_image&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/863189fc-4a81-46dd-8a9c-a18264f0c20d_2560x1663.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/is-pseudonymised-data-personal-data-3af&quot;,&quot;section_name&quot;:&quot;Data Rights&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:173384842,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>That decision feels like a significant juncture in the development of EU data protection law that has ramifications for a number of data processing operations, including those pertaining to AI.</p><p>The <em>SRB</em> case clarified a point that even I thought was not up for debate: not all pseudonymised data is personal data. Even when I wrote about the Advocate General&#8217;s opinion on the case prior to the Court&#8217;s decision, I thought this might be one of the rare instances in which the CJEU would diverge from the AG.</p><p>I was wrong.</p><p>It turns out that there is nuance in data protection after all. Not all of it is rigid and strictly interpreted, and it allows for a flexibility that makes it workable in different contexts.</p><p>Perhaps this is a better way - such an approach to pseudonymisation probably makes sense.</p><p>If you encrypt some data, and share the cipher text with another entity without a copy of the cryptographic keys, the receiving entity does not have personal data in GDPR terms.</p><p>They have something that has been pseudonymised, but if they have no means to decrypt it, reverse engineer or otherwise transform the cipher text into its original form, then they just have unintelligible gibberish. Or at least they have information that could not be linked to any person and therefore identify a particular person. There is no personal data there.</p><p>There are some who might say that this opens the door for compliance escapism. If the information I have received cannot be used to identify a person, even if indirectly, then I don&#8217;t need to bother with GDPR obligations. Why would I when the information is not personal data?</p><p>From this perspective, <em>SRB</em> opens up a new gateway for avoiding the perceived compliance headaches of one the EU&#8217;s flagship regulations. And this gateway may be something that deployers of AI system take full advantage of.</p><p>Here is what I am getting at: if we take the principle from <em>SRB</em> and apply it to the question of whether AI models contain personal data, the answer is...still complicated.</p><p>If you look under the hood of a model, you could point to some parts and say, &#8216;yep, that is definitely personal data.&#8217; But then there might be other parts where this is not the case.</p><p>The reason for this is because AI models <em>are not like databases</em>. It is not the internet indexed and searchable through a chat interface. Not at all.</p><p>The way model&#8217;s &#8216;store&#8217; information is much different. If you look under the hood, you will see a probability distribution with fragments of words with their embeddings all numerically represented with no obvious organisation or structure.</p><p>The only way you could possibly argue that there is personal data anywhere in that mess is if you can demonstrate that the model has memorised verbatim some of its training data and that memorised training data is personal data.</p><p>This is not a crazy idea. Systems like ChatGPT have previously shown the tendency to do this kind of memorising and spit out personal data buried deep in its massive text corpus. This includes phone numbers, email address, physical addresses and more.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;d8b6e27d-fbc4-453d-b706-2ce02d8a037c&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on attacks against large language models (LLMs) that can reveal personal data in its training data. This comes from a 2020 paper authored by researchers and engineers from Google, OpenAI, Apple and several universities.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-03-10T19:51:31.667Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!fPB6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa196cedb-d718-468a-a7f5-e866d2a860e4_582x648.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:107670484,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;7f7e3dd0-0a3a-41f1-8353-3a866ed8ef24&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on a 2023 paper by Carlini et al looking at the factors that cause large language models (LLMs) to memorize their training data verbatim and thus increase the risk of privacy leakage where that data consists of personal data.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;More Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-11-17T09:00:31.525Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!eNZ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8332595-4793-40f7-afc1-7b1c0ae52b67_1170x706.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/more-notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:138741038,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>But to expose this vulnerability, you need the right prompt. You need a specific prompt attack that reveals the relevant personal data that the model may have memorised.</p><p>This leads to the critical next question - what are the prompts that do this? Or in <em>SRB</em> terms, what means would a deployer of AI systems have to extract and process the personal data contained in the system? How does a deployer know which personal data have been memorised and therefore can be extracted with the right prompt?</p><p>If you could not tell by now, this post is a very nerdy data-protection-crosses-technical-realities deep dive akin to what I did when I first looked at this issue of model&#8217;s containing personal data.</p><p>So all the details may not be all that exciting, but if you are a deployer of AI systems, whether its ChatGPT, Claude, Grok or others, then the thrust of this piece is highly relevant:</p><blockquote><p><em>The SRB decision invites a compliance strategy based on ignorance; AI system deployers intentionally depriving themselves of the means to &#8216;re-identify&#8217; any personal data in the model they are using.</em></p></blockquote><p>It is a big take, but nevertheless a realistic one that is worth exploring. And in the remainder of this post, I attempt to explain it in the simplest way possible so that you can really understand both the point I am making, why I am making it and the implications it has for organisations using AI systems built by others.</p><p>As always, if you find this content useful, share it.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p>Let&#8217;s dive in.</p><h1>The <em>SRB</em> principle</h1><p>Pseudonymised data is not always personal data.</p><p>Now I think it is first of all worth explaining the concept of &#8216;personal data&#8217; and what it <em>actually</em> means in the world of GDPR.</p><p>Simply put, &#8216;personal data&#8217; means information that can be used to identify a person.</p><p>So personal data is not information that might be considered, in some colloquial sense, personal or sensitive. Sometimes when I hear people talking about personal data, they put emphasis on the <em>personal</em> so as to mean information that is particularly special, unique or intimate for the person it belongs to.</p><p>It certainly can be, but the concept of personal is much wider than that.</p><p>To really understand this, it is important to break the definition of personal data down into its constituent parts:</p><ul><li><p>any information</p></li><li><p>relating to</p></li><li><p>identified or identifiable</p></li><li><p>natural person</p></li></ul><p>Any information literally means any information, and this can be objective or subjective information about someone. Think names, email addresses, phone numbers but also opinions, assessments or even predictions about a person.</p><p>To be personal data, that information needs to be about an individual. This means that either the content, purpose or effect of the information must be linked to a particular person:</p><ul><li><p>The content element is satisfied if the information itself is about an individual, such as the exam result of a student</p></li><li><p>The purpose element is satisfied if the information can be used to evaluate or analyse an individual</p></li><li><p>The effect element is satisfied if the use of the information has an impact on an individual&#8217;s rights or interests</p></li></ul><p>To be identified or identifiable is about whether the entity holding the information can use it to single out a person from other people. I will come back to this later on.</p><p>Finally, a natural person is just a legal term for a person. So personal data does not include information about a corporation or organisation or anything that is not a human. The GDPR also does not apply to deceased persons.</p><p>With a sufficient understanding of personal data, we can then turn to the concept of pseudonymised data.</p><p>Generally, a pseudonym can be thought of as a cover name or a replacement for a true value or a kind of derivative of some original information. Pseudonymisation is therefore the process of taking data and applying some transformation to it that turns it into pseudonymised data.</p><p>Let&#8217;s say you have an email address: <code>mahdiassan@email.com</code>. If you wanted to pseudonymise this piece of information, there a couple a different ways you could do it.</p><p>You could pseudonymise the email address using a technique called masking whereby you simply replace certain characters in the address:</p><pre><code><code># masking_example 

original_data = mahdiassan@email.com

pseudo_data = m********n@email.com
</code></code></pre><p>A more complicated way to pseudonymise the data is encrypt it whereby a cryptographic protocol is applied to the email which outputs some cipher text:</p><pre><code><code># encryption_example

original_data = mahdiassan@email.com

pseudo_data = 92edfa8361b7af3e637
</code></code></pre><p>This is where I want to return to the idea of identifiability.</p><p>Identifiability exists on a spectrum. On the one end, you have data points that directly identifies a specific individual (like a name) and on the other end you have data points that only indirectly identify individuals (like a userID). It is important to remember two things here though:</p><ul><li><p>Indirect identifiability includes data points that can be linked to <em>a person</em> even if it is not known exactly who that person is</p></li><li><p>Anonymity is the complete opposite of direct identifiability - this where data cannot be linked to any person at all (as can be the case with aggregated statistics)</p></li></ul><p>Pseudonymisation is about reducing the identifiability of personal data. It reduces the identifiability of data such that it can no longer be used to identify a specific individual. In other words, without the use additional information, it would be difficult to identify exactly who the pseduonymised data relates to.</p><p>Let&#8217;s go back to the encryption example above. When you encrypt data, you produce cipher text but also a set of cryptographic keys. These keys can be used to encrypt as well as decrypt the data. So if I encrypted some data and shared <em>only</em> the cipher text with someone else, and I kept the keys to myself, it would be very difficult for that person to use that data to identify someone - all they have is a hash value that bascially looks like a bunch of gibberish (<code>92edfa8361b7af3e637</code>).</p><p>However, a question one may have is, even if the person I shared the data with only has the cipher text, is that cipher text still personal data? After all, the keys to decrypt the data, and turn it back into its original form (<code>mahdiassan@email.com</code>), are still in my hands and therefore I still have the ability to see the personal data that has been encrypted. But regarding the third party I have shared only the cipher text with, what are they holding?</p><p>There are two different approaches to this question: a strict approach and a relative approach.</p><p>Under the strict approach, the cipher text in the hands of the third party is still personal data. That the cryptographic keys are in still existence, and therefore could be used by me to decrypt the data and link it to an individual, means that the encrypted data is still ultimately personal data. The means of identification are still there.</p><p>The relative approach, however, adds some nuance to this. Though the means for identification exist, it does not mean that the person that the data relates to is always identifiable. This depends on the means available to the person holding the information in question.</p><p>For a while, the strict approach seemed to be a dominate view among the data protection community. But a judgment from the CJEU in <em>EDPS vs SRB</em> last year has declared something different; that the relative approach should be taken regarding the concept of personal data.</p><p>I will not go over the case details again in this post; you can read all that in my previous post on the topic. But what I will reiterate here are the principles that can be derived from <em>SRB</em>.</p><p>Using my encrypted data example again, if I share only the encrypted data with the third party, and that third party has no access to the cryptographic keys, then, from the perspective of that third party, they are not holding personal data. This is as long as the following is true:</p><ol><li><p>The third party cannot &#8216;lift&#8217; the pseudonymisation (or in this case the encryption) preventing re-identification</p></li><li><p>The third party cannot perform re-identification through cross-checking with other available information it may have access to (including information it can search on the internet)</p></li><li><p>The risk of identification is insignificant considering the cost, time and the technology available</p></li></ol><p>Accordingly, from the position of the third party with whom I share the encrypted data with, they are not holding personal data because:</p><ul><li><p>They do not have the cryptographic keys to decrypt the data</p></li><li><p>There is no other information they can use to perform re-identification using the cipher text only (i.e., they cannot reverse-engineer the cipher text)</p></li><li><p>If I use a sufficiently complex cryptographic protocol, they cannot reproduce the cryptographic keys needed to decrypt the data (maybe barring access to a sufficiently powerful quantum computer)</p></li></ul><p>The key thing to understand from <em>SRB</em> is that the nature of personal data&#8217;s relativity ultimately depends on the entity holding it. In essence, whether pseudonymised is personal data depends on who is looking at it and what they can do with it, not just on the data&#8217;s inherent properties.</p><h1>Applying <em>SRB</em> to AI systems</h1><p>I used the example of encrypted data earlier because it has a particular relevance to the second part of my thesis, which is about what is inside an LLM.</p><p>LLMs are giant prediction machines. They take your natural language input and spit out something that they think you need.</p><p>But if you look under the hood of an LLM, it is complex to say the least. It consists of tokenisers, embedding layers, positional encoders, transformer blocks and a probability distribution.</p><p>If you want a detailed explanation of how LLMs work, you can go back to my previous post:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;10463f3f-7d98-4c71-b10f-240922a0c236&quot;,&quot;caption&quot;:&quot;TL;DR This newsletter is about whether large language models (LLMs) store personal data they may have been trained on. It looks at how LLMs work, the definition of personal data under the GDPR and the various arguments around this issue.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Do LLMs store personal data?&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2024-10-25T08:01:11.992Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!ySu3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F849f6431-05b8-4950-af53-c41745ffc41c_3840x2743.jpeg&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/do-llms-store-personal-data&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:150681988,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:8,&quot;comment_count&quot;:7,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>But for now, the key point I make in that post is that the type of information that LLMs &#8216;store&#8217; and the nature of that storage is not like how we traditionally think of data stored in databases.</p><p>When an LLM is being trained, internally it is building something called a vocabulary (or a <code>vocab</code>). This part of the model contains all the tokens it has come across in its training. A token represents a word of a fragment of a word in a numerical form (e.g., &#8216;computer&#8217; might be tokenised to <code>2886</code>). Additionally, each token will have assigned to it a word embedding, which encodes the tokens relationship with all the other tokens in the vocabulary.</p><p>So every time you give a model a prompt, it will refer to its <code>vocab</code> and work out the probability of each token being the appropriate tokens for the response to the prompt. And then it will select those tokens that are more likely to form the right output.</p><p>This <code>vocab</code> consists of a matrix that does kind of look like a table:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BZY1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BZY1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 424w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 848w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1272w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BZY1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png" width="1456" height="666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:666,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:380592,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BZY1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 424w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 848w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1272w, https://substackcdn.com/image/fetch/$s_!BZY1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41146a7a-7264-4545-b011-9de55cf0aa25_1456x666.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Caption: From &#8216;How large language models work, a visual intro to transformers | Chapter 5, Deep Learning&#8217; by <em>3Blue1Brown</em> on <a href="https://youtu.be/wjZofJX0v4M?si=27daqL-CRkBvbuDK&amp;t=746">YouTube</a>. Note that in this video the tokens are represented as whole words but in reality tokens will represent fragments of words. But <em>3Blue1Brown</em> explains it this way for the sake of convenience.</figcaption></figure></div><p>An LLM&#8217;s <code>vocab</code> can be very large - tens of thousands worth of tokens. This means that the matrix could have tens of thousands of columns representing each token along with tens of thousands of rows of values representing the word embeddings for each token.</p><p>But this matrix is not a database. The information in the <code>vocab</code> consists of values for the parameters that are learned during training, and those values codify the relationships between all the tokens that the model comes across during training (and this is in addition to the weights stored in the neural networks of each transformer block).</p><p>So altogether then, an LLM stores:</p><ul><li><p>All the tokens it comes across during training</p></li><li><p>The embedding vectors for each token</p></li><li><p>The weights for the neural networks in each transformer block</p></li></ul><p>This information does not itself relate to an <em>identifiable</em> natural person. It is a bunch of numbers that humans cannot comprehend. And even if we could comprehend these numbers, linking that back to particular people whose personal data may be in the training data would still be incredibly difficult.</p><p>In effect, all you have inside an LLM is a matrix of seemingly random numbers that are only readily interpretable to the LLM.</p><p>Looking inside an LLM to identify the personal data contained in there is no use. However, deconstructing the black box that is an LLM is not how most people interact with such digital artefacts. Most people interact with LLMs by prompting the text box on their screen.</p><p>Now this is where the encryption analogy comes in.</p><p>LLMs sometimes memorise verbatim the data they comes across during training. This does not happen with all the data points, but there is research out there showing that they are capable of doing this.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;0c6e6100-da8c-4037-8096-1b51d275a9e9&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on attacks against large language models (LLMs) that can reveal personal data in its training data. This comes from a 2020 paper authored by researchers and engineers from Google, OpenAI, Apple and several universities.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-03-10T19:51:31.667Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!fPB6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa196cedb-d718-468a-a7f5-e866d2a860e4_582x648.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:107670484,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;e49642a7-6abe-4937-a16a-73c68379f998&quot;,&quot;caption&quot;:&quot;TL;DR These notes are on a 2023 paper by Carlini et al looking at the factors that cause large language models (LLMs) to memorize their training data verbatim and thus increase the risk of privacy leakage where that data consists of personal data.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;More Notes on LLMs and privacy leakage&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22246793-7185-4e99-b80b-882e9a90f91e_654x654.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2023-11-17T09:00:31.525Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!eNZ7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8332595-4793-40f7-afc1-7b1c0ae52b67_1170x706.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/more-notes-on-llms-and-privacy-leakage&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:138741038,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>After training on a large dataset of text, the LLM has an understanding of language in the sense that it understands the correlations and patterns between words. However, the model does not necessarily learn factual information about the language it learns.</p><p>Any &#8220;factual knowledge&#8221; that the model is able to produce is merely derived from its understanding of language and the correlations between different words (or tokens). So by understanding language, it is possible for LLMs to &#8220;learn&#8221; factual information.</p><p>In particular, such factual information could be learned if the relevant patterns appear frequently enough in the training dataset. The more often the model comes across a certain pattern during training, the more prominently that pattern will be represented in its parameters.</p><p>Whenever the model then receives an input containing text relating to that more frequent pattern, it will rely on that pattern to produce its response. In doing so, the model could produce data that it has essentially &#8216;memorised&#8217; from its training data.</p><p>So while the information contained within LLMs is not intelligible to humans, the personal data that is in there somewhere and has been memorised by the model could be extracted by prompting the model in certain ways.</p><p>If I ask ChatGPT when Donald Trump was born, it says he was born on 14 June 1946:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GL0M!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GL0M!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GL0M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png" width="1456" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:477803,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GL0M!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!GL0M!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe0a3c04a-4bd0-4ca6-a4c6-225ef9f3fc58_2116x1578.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>But if I ask ChatGPT who was born on 14 June 1946, I get this:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZZOA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZZOA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png" width="1456" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:611896,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/189055358?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZZOA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 424w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 848w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1272w, https://substackcdn.com/image/fetch/$s_!ZZOA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf61a136-cce6-40cd-847e-b420f7220cb0_2116x1578.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Clearly ChatGPT has learned from is training data that &#8220;14 June 1946&#8221; and &#8220;born&#8221; and &#8220;Donald Trump&#8221; are all strongly associated with each other, hence why I get the outputs I do.</p><p>Obviously though the prompts for extracting this information are pretty straight forward here given that Donald Trump, or any other public figure, will likely feature multiple times in the training data. This increases the propensity of the LLM to memorise certain information about such figures and therefore increases the ease of which such information can be extracted through prompting.</p><p>But the point here is that personal data that has been memorised by the model can be transformed from an unreadable to a readable format by using the right prompt. Which is similar to the how encryption works.</p><p>Recall that with encryption, you have:</p><ul><li><p>The original data</p></li><li><p>The cryptographic protocol applied to the data</p></li><li><p>The generation of the encrypted data</p></li><li><p>A set of cryptographic keys that can decrypt the encrypted data back to the original data</p></li></ul><p>And you could describe LLMs and personal data extraction in a similar way:</p><ul><li><p>Personal data is contained in the large training datasets consisting of data scraped from the internet</p></li><li><p>That data are tokenised and mapped to word embeddings</p></li><li><p>The data are therefore converted into a bunch of values representing these tokens and embeddings and organised into a matrix</p></li><li><p>With the right prompt, that unintelligible bunch of numbers can effectively be converted into readable text that may constitute personal data</p></li></ul><p>With this logic, the information you have inside LLMs is pseduonymised data. The tokens and word embeddings are in a pseudonymised form as a result of model training, and then transformed into intelligible personal data if the right prompt is used with the model at inference.</p><p>Extending this, if a developer takes a trained LLM and incorporates it into a new product, then that developer will not necessarily be holding personal data. Applying the <em>SRB</em> principle, the developer is only holding personal data extractable from the model if they use the means to extract it, which would be the prompts.</p><p>But if the developer does not know what those prompts are and does not use them, then that extractable, memorised personal data remains pseudonymised. The GDPR obligations that would therefore otherwise apply (selecting an appropriate legal basis, adhering purpose limitation and data minimisation etc) are not of concern to the developer regarding the pseudonymised personal data &#8216;inside&#8217; the model it is incorporating into its product.</p><p>I would argue that this perspective on the matter is reinforced by a compliance strategy that has been implicitly endorsed - a strategy based on ignorance.</p><h1>Compliance based on ignorance</h1><p>I want to be clear about a couple of things here before I go on explaining this take.</p><p>Firstly, I am not saying that this potential compliance strategy is right in the sense of it is a good thing. But I do predict that this will be a strategy that many developers will be tempted towards because it makes their compliance work simpler.</p><p>Secondly, this potential compliance strategy does not absolve developers of <em>all</em> of their data protection responsibilities. This only absolves them from the needing to address data protection issues arising from the use of the model or building on top of it - the personal data contained in these models is not their responsibility. However, the way that the system they are building using the model processes personal data is still their problem, and data protection responsibilities definitely still apply there. This is the case regarding personal data used to develop the system or personal data collected when people use the system, but neither of these processing operations are the subject of this post.</p><p>The compliance strategy explored in this piece specifically concerns developers using trained models to build new products - do those products already contain personal data by using a model trained with lots of personal data that might be &#8216;stored&#8217; in the model?</p><p>I argued in the last section that these models do not necessarily contain personal data. In this section, I look at how developers could go about demonstrating this by essentially remaining ignorant about the details of the models they are using.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/why-your-ai-system-might-not-contain">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[You are not vibe-coding properly if you are not doing this]]></title><description><![CDATA[How to build with Claude Code responsibly]]></description><link>https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 13 Feb 2026 09:00:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pJLZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fpbs.substack.com%2Fmedia%2FG_V2kvLXwAA1nI2.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Yes it is true. Claude Code is pretty cool.</p><p>I started using it properly about a month ago, initially just testing out its competency at one-shot app creation, for which I was careful to manage expectations of course.</p><p>Watching this coding agent work through your request, while keeping you in the loop to check that its work is aligned with your preferences, is quite fascinating. There is something quite magical and intriguing about how this little bot can just take your initial prompt and crank out a full-fledged application. It is equally cool to see how it can carry out various tasks that would otherwise require a decent level of coding proficiency.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/birdabo/status/2014646824079106544?s=46&quot;,&quot;full_text&quot;:&quot;&#8220;rome wasn&#8217;t built in a day&#8221; \n\n&amp;gt; they didn&#8217;t have claude code. &quot;,&quot;username&quot;:&quot;birdabo&quot;,&quot;name&quot;:&quot;sui dev &#9732;&#65039;&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1991760919513403392/cCbWHb5A_normal.jpg&quot;,&quot;date&quot;:&quot;2026-01-23T10:30:07.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/G_V2kvLXwAA1nI2.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/eCEH2vB94O&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:119,&quot;retweet_count&quot;:315,&quot;like_count&quot;:5832,&quot;impression_count&quot;:117157,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:false}" data-component-name="Twitter2ToDOM"></div><p>I have found a lot of inspiration from a number of Substack newsletters on the joys of using Claude Code, including from <a href="http://insights.priva.cat/p/i-built-an-ai-powered-futures-forecasting">Privacat</a>, <a href="https://www.interconnects.ai/p/claude-code-hits-different">Nathan Lambert</a> and <a href="http://jasmi.news/p/claude-code">Jasmine Sun</a>.</p><p>The interesting thing about Claude Code is that, despite it being a coding agent and therefore seemingly only of interest to coders or those more technically capable, it is capturing the attention of those outside the AI bubble. Even the <em>Wall Street Journal</em> is writing about Claude Code, so it must be something cool even among the normies.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tJrq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tJrq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 424w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 848w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1272w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tJrq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png" width="677" height="818" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dfd362b5-a71a-4ead-894d-604e245831e9_677x818.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:818,&quot;width&quot;:677,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:175534,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/187229909?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tJrq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 424w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 848w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1272w, https://substackcdn.com/image/fetch/$s_!tJrq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdfd362b5-a71a-4ead-894d-604e245831e9_677x818.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">From <a href="https://www.wsj.com/tech/ai/anthropic-claude-code-ai-7a46460e">The Wall Street Journal</a></figcaption></figure></div><p>As fun as all this has been (and maybe even a little addicting), my experience with Claude Code did alert me to something which I think could very easily be overlooked for those who have been &#8216;Claude-pilled.&#8217;</p><p>Products like Claude Code make it easier and cheaper than ever to build software solutions. And if these codings agents continue to improve, so it is quite striking to think of the possibilities down the line.</p><p>The temptation that this fuels is to just build a bunch of new stuff. If all you need is a bit of natural language prompting and a machine will just turn your idea into reality with a little further input from you, then think of all the ideas that do not need to be just ideas anymore. Imagine all the things you could build. Maybe you really are just one weekend away from a building the next killer app that makes you a fortune in a week.</p><p>The obvious problem here is that as people get carried away with the magic of Claude Code, they start to forget the fundamental questions about what they are doing. They forget about the aspects of building that AI cannot necessarily do for them.</p><p>AI can do many things, but it cannot do everything.</p><p>In the midst of your Claude psychosis, you may forgo why you are even building the thing in the first place as well as the principles for building it well.</p><p>And this is crucial, because if you end up building the wrong thing in the wrong way, and then deploy it for other people to use, you may disappoint your users at best or even harm them at worse.</p><p>To avoid this, you need to think about what it will take to actually build things properly with products like Claude Code:</p><ul><li><p><strong>Taste.</strong> Are you solving a real problem that actually needs solving?</p></li><li><p><strong>Distribution.</strong> How do you get people to care about your solution to the problem?</p></li><li><p><strong>Trust.</strong> Does your solution actually work well?</p></li></ul><p>Trust is particularly important. In a sea of new apps being built and deployed everyday by eager vibe-coders leveraging the power of agents, why should people use your app? What makes it so much better than the rest?</p><p>Even if your app solves a problem that others are struggling with, and even if you have an audience willing to use it, if it does not deliver on the promises, then you just get a high churn rate. And all your late nights with Claude Code will go to waste.</p><p>Alternatively, if you take the time to build a solid solution that works well, then you have a much better chance of gaining trust. And this thens feed into the other factors; the more people believe in your product, the more they share it with others which leads to more users and therefore more feedback on how well your app is doing.</p><p>The key to gaining this trust is embracing governance.</p><p>Governance is not just about legal compliance. Fundamentally, governance is about implementing measures that help you build more reliable products.</p><p>You should think of governance as an enabler. If you get it right from the start, then not only do deal with any compliance issues, but you also give people another reasons to trust your product. And you feed the growth flywheel.</p><p>To get governance right when building with Claude Code, I think you need to start by managing three things: quality, data and risk.</p><p>Get these three things right and you will be well on your way to establishing a unique selling point for your product and a moat that most will not think to work on until it is too late.</p><p>In this post, I walk through the steps and prompts for quality, data and risk management when using Claude Code. If you are building apps with Claude Code that you plan to release into the wild, then this is essential reading.</p><p>If you find this content valuable, make sure to share it with others.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/you-are-not-vibe-coding-properly">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[You've just used ChatGPT, but do you know where your data goes?]]></title><description><![CDATA[The journey your information takes when using AI]]></description><link>https://www.thecybersolicitor.com/p/what-happens-to-your-data-when-you</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/what-happens-to-your-data-when-you</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 30 Jan 2026 09:02:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bbHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bbHT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bbHT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bbHT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg" width="1456" height="2058" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2058,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1788965,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/185216400?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bbHT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bbHT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F46b4a298-d7aa-45ba-8740-48a472fc7cff_2560x3619.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Jamillah Knowles &amp; Reset.Tech Australia / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>There a lot of people who do not know where their data goes when using an AI chatbot.</p><p>They will open up ChatGPT or Claude, type in their prompt, maybe attach some files, and watch this seemingly magical artificial entity generate a response that at least aligns with, but preferably exceeds, their expectations.</p><p>But in the midst of being so mesmerised, many will not bother to think what really happens inside that black box.</p><p>Not many people will really think about what happens to their data once they submit it to the machine.</p><p>Some people may say: &#8216;<em>who cares?</em>&#8216;</p><p>And maybe this is a reasonable response. Why care about the journey your information takes when it enters the complex bowels of a language model and gets transformed into new output rendered token-by-token to gradually build a response to your query? Surely all that matters here are the ends, not the means.</p><p>But the mistake with this mindset, if you have it, is that you are making some quite stark assumptions about those means.</p><p>You are assuming that the use of your data is within the realm of your expectations.</p><p>You are assuming that the use of your data is limited to simply running inference on the model to get the answer it thinks you need.</p><p>You are assuming that the the use of your data is sufficiently proper and ethical.</p><p>But what if these assumptions are wrong?</p><p>What if your data is being used for purposes that you did not expect and might even object to?</p><p>What if your data is being shared with other entities you did not even know were involved?</p><p>What if your data is out of your control?</p><p>Here is the painful truth when it comes to navigating our digital word: every time you use a digital service, you give up some data. And when you surrender your data to these digital systems, your agency over it automatically diminishes.</p><p>Moreover, you are giving your data up to systems built and controlled by others with incentives and priorities that may not be conducive to yours.</p><p>And control over your data also means control over your digital experience. Sometimes that experience may be absolutely fine, but the point is that this is not determined by you. It is determined by other people.</p><p>A few weeks ago, OpenAI announced that it would start displaying ads on ChatGPT.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/sama/status/2012253252771824074&quot;,&quot;full_text&quot;:&quot;We are starting to test ads in ChatGPT free and Go (new $8/month option) tiers.\n\nHere are our principles. Most importantly, we will not accept money to influence the answer ChatGPT gives you, and we keep your conversations private from advertisers.\n\nIt is clear to us that a lot&quot;,&quot;username&quot;:&quot;sama&quot;,&quot;name&quot;:&quot;Sam Altman&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1904933748015255552/k43GMz63_normal.jpg&quot;,&quot;date&quot;:&quot;2026-01-16T19:58:55.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{&quot;full_text&quot;:&quot;In the coming weeks, we plan to start testing ads in ChatGPT free and Go tiers.\n\nWe&#8217;re sharing our principles early on how we&#8217;ll approach ads&#8211;guided by putting user trust and transparency first as we work to make AI accessible to everyone.\n\nWhat matters most:\n- Responses in&quot;,&quot;username&quot;:&quot;OpenAI&quot;,&quot;name&quot;:&quot;OpenAI&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1885410181409820672/ztsaR0JW_normal.jpg&quot;},&quot;reply_count&quot;:4938,&quot;retweet_count&quot;:923,&quot;like_count&quot;:10142,&quot;impression_count&quot;:12896121,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>If you have been reading my content over the past few months, you would see how I have talked about such a decision becoming a reality. Investments in AI have been enormous, fuelled by the dramatic promises of generative AI. Companies like OpenAI, with Altman as the prime advocator, have been constantly glamourising their models as magical technologies that would solve so many of humanities great problems and become beacons of growth and progress.</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;3b0be8bd-c7f8-4d90-b179-900573acc54e&quot;,&quot;caption&quot;:&quot;Bubbles pop eventually.&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;This is what happens when the AI bubble pops&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:112131599,&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;bio&quot;:&quot;Privacy pro working on AI and data rights &quot;,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!jbJw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61582ad5-143e-4a5d-9e51-c20145b39d65_1167x1164.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-12-05T09:02:24.225Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai&quot;,&quot;section_name&quot;:&quot;AI Governance&quot;,&quot;video_upload_id&quot;:null,&quot;id&quot;:179728534,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:2,&quot;comment_count&quot;:0,&quot;publication_id&quot;:1200826,&quot;publication_name&quot;:&quot;The Cyber Solicitor&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!T4HV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F276409e9-b16f-4458-aae2-f3c59c484ed3_1110x1110.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>But in the end, when the hype fades away, OpenAI and others were always going to need to demonstrate to their investors how they were going to get returns on their investments. AI developers needed to show how they were actually going to make money with their products.</p><div class="comment" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/home&quot;,&quot;commentId&quot;:201100292,&quot;comment&quot;:{&quot;id&quot;:201100292,&quot;date&quot;:&quot;2026-01-17T14:31:05.841Z&quot;,&quot;edited_at&quot;:null,&quot;body&quot;:&quot;AGI (ad-generated income) &quot;,&quot;body_json&quot;:{&quot;content&quot;:[{&quot;content&quot;:[{&quot;text&quot;:&quot;AGI (ad-generated income) &quot;,&quot;type&quot;:&quot;text&quot;}],&quot;type&quot;:&quot;paragraph&quot;}],&quot;type&quot;:&quot;doc&quot;,&quot;attrs&quot;:{&quot;schemaVersion&quot;:&quot;v1&quot;}},&quot;restacks&quot;:2,&quot;reaction_count&quot;:6,&quot;attachments&quot;:[],&quot;name&quot;:&quot;Mahdi Assan&quot;,&quot;user_id&quot;:112131599,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!jbJw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61582ad5-143e-4a5d-9e51-c20145b39d65_1167x1164.jpeg&quot;,&quot;user_bestseller_tier&quot;:null,&quot;userStatus&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:5,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:5,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[1666375,458709,669567,356913,808767,4328580],&quot;subscriber&quot;:null}}}" data-component-name="CommentPlaceholder"></div><p>In the end, OpenAI has chosen a path that has worked very well for the tech companies before it. Google, Facebook and others turned to surveillance capitalism to strengthen their business models, involving the construction of data extraction systems that turned behavioural insights of users into revenue via targeted advertising. The cycle has simply repeated itself.</p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/signulll/status/2013082071636254889&quot;,&quot;full_text&quot;:&quot;so basically every ~decade we will get giant new internet ad businesses?\n\n2000&#8217;s - google\n2010&#8217;s - facebook\n2020&#8217;s - openai \n\nincredibly fascinating.&quot;,&quot;username&quot;:&quot;signulll&quot;,&quot;name&quot;:&quot;sign&#252;ll&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1717763325692383232/Jk2PKCx6_normal.jpg&quot;,&quot;date&quot;:&quot;2026-01-19T02:52:21.000Z&quot;,&quot;photos&quot;:[],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:133,&quot;retweet_count&quot;:88,&quot;like_count&quot;:3025,&quot;impression_count&quot;:120178,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><p>If OpenAI is doing this, then the question of what actually happens to your data when you use ChatGPT and other tools like it really does become important.</p><p>The first step to solving any problem is to understand the problem really well. And to help with this, in this post I uncover the system that lies behind the chatbots that you are probably well-familiar with or at least heard of.</p><p>I set out the different components that make up the system, how they fit and work together, and how your data moves through the system when you use it. I also look at the data risks involved and some simple steps you can take to better-protect yourself.</p><p>This will be relevant to everyone who uses an AI chatbot. It does not matter if you are using it for throw-away personal questions or if you are part of the &#8216;shadow AI&#8217; clique at work. You need to know what happens to your data when you use a chatbot.</p><p>If you understand the systems you are engaging with, you put yourself in a better position to mitigate the risks. You cannot fully solve a problem unless you really understand the problem.</p><p>Make sure to share this newsletter with others if you find it valuable. And subscribe if you want more insights like this in your inbox every week.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/what-happens-to-your-data-when-you">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[No, AI is not about to delete all jobs. This is what happens instead.]]></title><description><![CDATA[AI presents challenges and opportunities]]></description><link>https://www.thecybersolicitor.com/p/how-you-can-thrive-in-the-age-of</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/how-you-can-thrive-in-the-age-of</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 16 Jan 2026 09:01:33 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/71f9559e-cefb-423f-8a14-84a6bf7b0649_3000x3000.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NoW2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NoW2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 424w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 848w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1272w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NoW2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png" width="595" height="841" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:841,&quot;width&quot;:595,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:105531,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/183140316?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NoW2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 424w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 848w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1272w, https://substackcdn.com/image/fetch/$s_!NoW2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d40c7e9-1951-4986-981f-e9757558cfde_595x841.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>AI will kill all lawyers.</p><p>This was the title of an <a href="https://spectator.com/article/ai-will-kill-all-the-lawyers/">article</a> in the <em>Spectator</em> that I recently read. And it prompted some thoughts. Many thoughts.</p><p>The article gives the views of an anonymous English barrister on AI and legal practice. And the picture he gives is pretty gloomy: AI will &#8216;completely destroy&#8217; the law as we know it.</p><p>Why such a stark warning? It is based on this particular barrister&#8217;s recent experience using AI for legal work, as he explains:</p><blockquote><p>&#8216;Last week we did an experiment, a kind of simulation. We took a real, recent and important case &#8211; a complex civil court appeal which I wrote, and it took me a day and a half. We redacted all identifying details, for anonymity and confidentiality, and we fed the same case to Grok Heavy AI. And then we asked it to do what I did. After some prompting, the end result was&#8230;&#8217; He shakes his head. &#8216;Spectacular. Actually staggering. It did it in 30 seconds, and it was much better than mine. And remember, I am very good at this.&#8217;</p><p>[...]</p><p>&#8216;It was at the level of a truly great KC. The best possible legal document. And all done in seconds for pennies. How can any of us compete? We can&#8217;t.&#8217;</p></blockquote><p>Lawyers belong to one of the most conservative, risk-averse and arguably outdated professions that exist. They are used to holding high positions in society because their services are so necessary; as long as we have societies organised by a large, complex body of rules, we need people who can understand them and provide guidance on how to follow those rules.</p><p>Or do we?</p><p>Because if you read this barrister&#8217;s view on AI and its potential impact on the legal profession, you may think that if AI can do just as good as a qualified legal expert, then what is the point of having these experts?</p><p>You could go further: what is the point of knowledge work done by humans if we can get AI to do it?</p><p>These general-purpose machines, trained on massive amounts of data with huge amounts of computing power, seem capable of pretty much any cognitive task a human could do. Just feed it the right prompt and you have your desired output, produced in seconds or minutes at the most and on the cheap.</p><p>But as I was reading this <em>Spectator</em> article, I could not help but notice a rather glaring omission which reveals why &#8216;AI displacement&#8217; is more complicated than what some people present.</p><p><strong>AI is not about to take everyone&#8217;s job.</strong></p><p>Those who believe in a mass exodus where AI renders human roles completely redundant are not thinking carefully enough about what AI is and the impact it can actually have.</p><p>AI can do many things. And it can do many things really well.</p><p>But it cannot do everything. This is the simple truth.</p><p>This means that AI should really be seen as a force multiplier, not a replacement.</p><p>And this is the case even for the legal profession.</p><p>To thrive in the age of AI is to understand AI&#8217;s limitations as well as its capabilities and the gaps it therefore creates in our society.</p><p>Those gaps are where humans still have an important role to play, whether this is in the legal industry or any other domain where AI is being deployed.</p><p>In this newsletter, I cover three core ideas about how to navigate the trials and tribulations of AI in our modern world:</p><ul><li><p>What AI <em>can</em> do</p></li><li><p>What AI <em>cannot</em> do</p></li><li><p>What <em>you</em> should do</p></li></ul><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.thecybersolicitor.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to this newsletter for reliable information on the legal and societal implications of modern technology sent to your inbox every week</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/how-you-can-thrive-in-the-age-of">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The most important thing for AI in 2026]]></title><description><![CDATA[What is overlooked when building modern machines]]></description><link>https://www.thecybersolicitor.com/p/the-most-important-thing-for-ai-in</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-most-important-thing-for-ai-in</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 12 Dec 2025 09:01:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jIHr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jIHr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jIHr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 424w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 848w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1272w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jIHr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png" width="1456" height="2054" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2054,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:8570819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/181077893?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jIHr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 424w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 848w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1272w, https://substackcdn.com/image/fetch/$s_!jIHr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea3fda25-bad8-4fbd-8837-9cfe9128ebc8_1920x2709.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Lone Thomasky &amp; Bits&amp;B&#228;ume / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>Most people will be focusing on the wrong things when it comes to AI in 2026.</p><p>Most people will be focusing on the emerging paradigms, the new breakthroughs, or the next groundbreaking model claimed to be AGI.</p><p><em><strong>They are wrong</strong></em><strong>.</strong></p><p>What is far more important is something that too often gets overlooked. Something that is lethally ignored until it is too late. Something that, if done well, unlocks the real power of AI in a way that is not only sustainable but beats 99% of the competition.</p><p>To build good AI products, it is a mistake to obsess over the latest and greatest models. Chip Huyen, an experienced computer scientist and author of <em>AI Engineering: Building Applications with Foundation Models</em>, makes this point exactly. <a href="https://www.linkedin.com/posts/chiphuyen_aiapplications-aiengineering-activity-7358971409227792384-y0mf/">For her</a>, the things that actually contribute to better AI products are talking to users, building a more reliable platform, using better data, optimising for end-to-end workflows and writing better prompts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RKTM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RKTM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 424w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 848w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1272w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RKTM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png" width="1456" height="539" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:539,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:297192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/181077893?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RKTM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 424w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 848w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1272w, https://substackcdn.com/image/fetch/$s_!RKTM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb65968e0-b237-46b7-b6f6-e9886c059061_2048x758.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you want customers to invest in your product, they need to be a position to trust your product. When the hype and bravado eventually fade away, trust is the currency that keeps customers around.</p><p>What all this means is that the most important thing for AI developers to focus on in 2026 and beyond is <em>governance</em>.</p><p>This is not because it is required by law. Or because it is a &#8216;nice-to-have&#8217;. Or even because it is good for PR.</p><p>Governance is a business-enabler. It is a way of deepening moats. It is the <a href="https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium">dynamic equilibrium</a> that balances innovation and order.</p><p>Good governance is what underpins good, reliable AI products that actually work, build trust and deliver value.</p><p>As my last newsletter for 2025, I want to look to 2026 and what I think is next for AI from a data rights and governance perspective. I want to share what I think the AI landscape will probably look like, the problems it will produce, and why governance is <em>the</em> way to solve them.</p><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-most-important-thing-for-ai-in">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[This is what happens when the AI bubble pops]]></title><description><![CDATA[After the hype comes the reckoning]]></description><link>https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 05 Dec 2025 09:02:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FFEz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FFEz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FFEz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4173113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/179728534?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FFEz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!FFEz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa345de32-2f4b-46fe-ae22-a295bc388583_2560x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dominika &#268;upkov&#225; &amp; Archival Images of AI + AIxDESIGN / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>Bubbles pop eventually.</p><p>When the dot-com bubble popped in 2000, it caused the <a href="https://www.investopedia.com/terms/d/dotcom-bubble.asp">worst decline</a> in the NASDQ&#8217;s history, dropping by more than 70%. Many companies that had so confidently slapped &#8216;.com&#8217; on the end of their names suddenly had to face a reckoning, and many did not survive.</p><p>They did not survive because aesthetics would only get them so far. The shiny new object, which back then came in the form of a website on the world-wide web, would eventually need to prove its worth.</p><p>A bubble popping represents a reversion back to reality and fundamentals, and that is when the promises and predictions of technology are really tested.</p><p>And one of the more significant players carrying out this testing are investors. Having a cool product with potential is fine on Day 1. But on <a href="https://signull.substack.com/p/day-0-is-loud-day-2-is-real">Day 2</a>, investors are looking at the prospect of their returns. They want to know what they will end up getting out of it all.</p><p>Google was no exception to this.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/this-is-what-happens-when-the-ai">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[AI procurement from first principles]]></title><description><![CDATA[Being careful about the systems you use]]></description><link>https://www.thecybersolicitor.com/p/ai-procurement-from-first-principles</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-procurement-from-first-principles</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 28 Nov 2025 09:01:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kjzI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kjzI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kjzI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kjzI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5336570,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/179723086?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kjzI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 424w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 848w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!kjzI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1e339f3-412d-4422-8c47-f1576052455d_2560x1440.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Jamillah Knowles &amp; Digit / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>With the AI boom and hype comes many AI systems. Some are built for general-purpose use - household names like ChatGPT and Claude may come to mind. Others are designed for more specific use cases, like <a href="https://robinai.com/">RobinAI</a> (for contract review) or <a href="https://cursor.com/">Cursor AI</a> (for writing code).</p><p>The plethora of systems available provide plenty of opportunities for organisations to innovate. AI can help produce new products or services or improve existing processes for building products or services.</p><p>Such opportunity still exists despite organisations needing to resort to the use of systems built by others. It might sometimes be preferable to develop your own system specifically built for your own use case with your own data, giving you a wide range of customisability. However, these systems built by the likes of OpenAI and Anthropic still come with plenty of flexibility. Their models are general-purpose which can be built on top of, fine-tuned or engineered with <a href="https://www.anthropic.com/engineering/effective-context-engineering-for-ai-agents">context</a> and other tools to construct systems for a range of domains.</p><p>But with this opportunity comes risk, and these risks are just not limited to those which are legal in nature. AI development is itself an empirical science, whereby assessing behaviour and performance can only really be done by using models and monitoring them post-deployment. Models are often characterised as black-boxes possessing a level of complexity that renders them opaque and difficult to control. This can mean that AI systems risk failing to meet important business and legal requirements, with potentially significant consequences; poor ROI, user complaints and even regulatory intervention and legal action.</p><p>And so with these risks come responsibility. As Ethan Mollick notes in his book <em>Co-Intelligence: Living and Working with AI</em>, with AI becoming increasingly capable, &#8220;we&#8217;ll need to grapple with the awe and excitement of living with increasingly powerful alien co-intelligence.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>For organisations procuring AI systems, this responsibility comes in the form of being aware of what you buy. In the world of AI, the principle <em>caveat emptor</em> (&#8217;buyer beware&#8217;) is crucial.</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-procurement-from-first-principles">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[AI agents and the AI Act]]></title><description><![CDATA[Is agentic AI even in scope of Europe's AI regulation?]]></description><link>https://www.thecybersolicitor.com/p/ai-agents-and-the-ai-act</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/ai-agents-and-the-ai-act</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 21 Nov 2025 09:02:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6lEp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6lEp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6lEp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 424w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 848w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1272w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6lEp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png" width="1456" height="1052" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1052,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5582868,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/179488040?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6lEp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 424w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 848w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1272w, https://substackcdn.com/image/fetch/$s_!6lEp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d9f9ef0-318f-422e-b06f-ae89a54b8a38_2560x1850.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Nadia Piet  &amp; Archival Images of AI + AIxDESIGN / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>2025 was supposed to be the year of agents.</p><p>Generative AI (genAI), central to the current AI hype cycle, represents a significant leap from the previous generation of AI. It took AI from systems that could recognise patterns and ma&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/ai-agents-and-the-ai-act">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The GDPR and AI exceptionalism]]></title><description><![CDATA[Some initial reflections on the (leaked) proposed changes to the EU GDPR]]></description><link>https://www.thecybersolicitor.com/p/the-gdpr-and-ai-exceptionalism</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-gdpr-and-ai-exceptionalism</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 14 Nov 2025 09:01:45 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OOIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OOIy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OOIy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 424w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 848w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1272w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OOIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png" width="1456" height="2055" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2055,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:13728388,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.thecybersolicitor.com/i/178542964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OOIy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 424w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 848w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1272w, https://substackcdn.com/image/fetch/$s_!OOIy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1f038f5-6ae9-4c79-acc8-2af211d7be8e_2560x3613.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Lone Thomasky &amp; Bits&amp;B&#228;ume / https://betterimagesofai.org / https://creativecommons.org/licenses/by/4.0/</figcaption></figure></div><p>So the European Commission is exploring ways to simplify several different EU laws as part of its &#8216;Omnibus&#8217; reform package, and one of the <a href="https://media.licdn.com/dms/document/media/v2/D4E1FAQEwYB4tX7QQyw/feedshare-document-pdf-analyzed/B4EZpehBTyGYAY-/0/1762522312826?e=1763596800&amp;v=beta&amp;t=8G6MKk0PZNGPKhvnvcG3zrtGv7kfvBE31VWMUBkSM-8">drafts</a> for this was leaked last week.</p><p>There are some interesting things to note from this leak. The part that sto&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-gdpr-and-ai-exceptionalism">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Governance = dynamic equilibrium]]></title><description><![CDATA[Engineering vs lawyerly societies]]></description><link>https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 07 Nov 2025 09:00:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/1c9937c5-3d30-4912-8dfe-aee831238a26_325x500.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I recently started reading Dan Wang&#8217;s book <em>Breakneck</em> and it got me thinking about the role that data rights professionals play in the current tech eco-system.</p><p>Th first chapter is titled &#8216;Engineers vs. Lawyers&#8217; and Wang uses this frame to convey the contrast between progress in China and progress in the US. China is an engineering society, while the US is&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/governance-dynamic-equilibrium">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Why LLMs hallucinate, according to OpenAI]]></title><description><![CDATA[Some thoughts on why AI makes stuff up]]></description><link>https://www.thecybersolicitor.com/p/why-llms-hallucinate-according-to</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/why-llms-hallucinate-according-to</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 31 Oct 2025 09:01:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/030d605a-1c60-41bc-b1ef-98a596abbbbd_2560x3621.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Back in September, OpenAI released a <a href="https://openai.com/index/why-language-models-hallucinate/">research paper</a> that explores why language models hallucinate.</p><p>Hallucinations describe outputs of LLMs that are factually incorrect. It is a common flaw of these models and can be a major <a href="https://techcrunch.com/2025/05/15/anthropics-lawyer-was-forced-to-apologize-after-claude-hallucinated-a-legal-citation/">source of risk</a>.</p><p>But why do LLMs hallucinate? What is the cause of this tendency to generate incorrect responses?</p><p>The abstract of OpenA&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/why-llms-hallucinate-according-to">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Why AI requires its own governance]]></title><description><![CDATA[The difference between AI systems and other computer systems]]></description><link>https://www.thecybersolicitor.com/p/why-ai-requires-its-own-governance</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/why-ai-requires-its-own-governance</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 24 Oct 2025 08:01:53 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/f8c8b92f-b739-4401-8697-2a701f02ac0b_2560x3613.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>AI consists of technologies designed to mimic human behaviour. It therefore covers a range of different technologies and techniques, and among them is machine learning.</p><p>Machine learning is about building machines that fit mathematical models to observed data to produce a desired output. And a deep neural network is a type of machine learning model.</p><p>So wha&#8230;</p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/why-ai-requires-its-own-governance">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The EU AI Act and sensitive data]]></title><description><![CDATA[One of the key ways that AI governance and data protection intersect]]></description><link>https://www.thecybersolicitor.com/p/the-eu-ai-act-and-sensitive-data</link><guid isPermaLink="false">https://www.thecybersolicitor.com/p/the-eu-ai-act-and-sensitive-data</guid><dc:creator><![CDATA[Mahdi Assan]]></dc:creator><pubDate>Fri, 10 Oct 2025 08:01:48 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/56d04a28-b853-4236-9b20-7903a6d57059_2560x1779.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>TL;DR</h1><p>This newsletter is about how the AI Act and GDPR intersect regarding the use of sensitive data for AI development. It looks what is required under both pieces of legislation, the potential gaps in the legal framework and what steps developers could take regarding compliance.</p><p>Here are the key takeaways:</p><ul><li><p>Under the GDPR, personal data cannot be processed without an appropriate legal basis, of which are provided under Article 6 of the Regulation. Additionally, sensitive personal data cannot be processed unless one of the exceptions listed under Article 9.2 apply.</p></li><li><p>The AI Act permits, under Article 10.5, the use of sensitive data for the purposes of bias mitigation regarding the development of AI systems. It states that providers may <em>exceptionally</em> process sensitive data &#8220;to the extent strictly necessary for the purpose of ensuring bias detection and correction in relation to the high-risk AI systems.&#8221;</p></li><li><p>Article 10.5 itself cannot be a legal basis for processing sensitive data for AI development. The provision is written in such a way that entertains the possibility of processing sensitive data for AI development, but only for the purpose of bias mitigation <em>and</em> only if its use meets certain other conditions both under the AI Act and the GDPR.</p></li><li><p>Steps that developers can take to help comply with the requirements under the AI Act and GDPR regarding the use of sensitive data for AI development include:</p><ul><li><p>Determining whether sensitive data are needed for the development of the AI system</p></li><li><p>Documenting the justifications/explanations for using sensitive data in a record of processing operation</p></li><li><p>Applying data minimisation to the sensitive data</p></li></ul></li></ul><p></p>
      <p>
          <a href="https://www.thecybersolicitor.com/p/the-eu-ai-act-and-sensitive-data">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>