The surveillance platform that outlived the account
Anthropic banned the account used to engineer Mali’s Lakana 360 surveillance platform. The locally deployed system was unaffected.
Read the essayI write about the decisions behind secure devices, trusted software, and AI systems—and the evidence teams need to get them right.
Latest writing
Anthropic banned the account used to engineer Mali’s Lakana 360 surveillance platform. The locally deployed system was unaffected.
Read the essayOpenAI agents used a public wiki to exchange answers, revise procedures, and preserve shared work. The records reveal coordination across temporary runs—and a control problem that extends beyond any one agent.
Read the essayThe reporting obligation starts this Friday. What OEMs need ready now, and what follows when full product obligations apply on December 11, 2027.
Read the essayFour connected subjects
Practical guides, field notes, and questions for your team. A personal perspective on the decisions that connect these subjects.
Identify, update, isolate, and recover the systems you operate.
Explore this subjectConnect product evidence with what buyers and regulators need.
Explore this subjectFind the dependencies before certificates and algorithms change.
Know what an agent can do, what constrains it, and what can be proved.
Explore this subjectThe dates do not move
The regulatory deadlines and standards transitions reshaping enterprise digital trust between 2026 and 2030. Know what is adopted, who it affects, and what to ask your team.
Manufacturers must report actively exploited vulnerabilities and severe security incidents. Early warning is due within 24 hours of awareness; the next notification is due within 72 hours. Final reports follow separate clocks.
Certain providers of synthetic-content AI systems placed on the market before 2 August 2026 must meet Article 50(2) marking requirements by this date.
New acquisitions for U.S. National Security Systems must be CNSA 2.0 compliant unless an exception applies. Deployment requirements also depend on the relevant validation profile.
Reviewed September 2026 · Quarterly review cadence · Primary sources linked in the full calendar.
Guides & resources
Practical reading from the archive, with questions and frameworks to use in your own environment.
A starting point for testing whether one compromised device can be isolated without disrupting the rest of the fleet.
Find where public certificates are used for client authentication, and identify what needs to change.
A security review framework and reusable prompt for examining an AI coding assistant’s access.
About Tim
I’m Regional Field CTO at DigiCert. My work connects PKI, device identity, software assurance, and AI with the engineering and operating decisions organizations face.
This is my personal publication. Views are my own.
More about my workSpeaking & collaboration
Keynotes, panels, and workshops on device trust, cryptographic change, software assurance, and the authority we give AI systems.
Past speaking includes Embedded World, CES, and RSA Conference.