<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Modular Technology Group</title>
	<atom:link href="https://modtechgroup.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://modtechgroup.com/</link>
	<description></description>
	<lastBuildDate>Fri, 14 Aug 2026 00:15:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>
	<item>
		<title>A framework is not a control. Somebody has to run it.</title>
		<link>https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=a-framework-is-not-a-control-somebody-has-to-run-it</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 00:15:49 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/</guid>

					<description><![CDATA[<p>A framework is not a control. Somebody has to run it.AI Governance, fractional CAIO, AI program office, ~5 min readThere is a moment that arrives a few weeks after a good governance document lands on your desk. You have read it. You agree with all of it. The five principles are sensible, the risk tiers  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/">A framework is not a control. Somebody has to run it.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><strong>A framework is not a control. Somebody has to run it.</strong></h1>
<p>AI Governance, fractional CAIO, AI program office, ~5 min read</p>
<p>There is a moment that arrives a few weeks after a good governance document lands on your desk. You have read it. You agree with all of it. The five principles are sensible, the risk tiers make sense, and you cannot name a single person whose job it is to do any of it by Friday.</p>
<p>That moment is where most AI governance programs quietly stop.</p>
<p>On 29 July the Society of Pension Professionals published <a href="https://www.actuarialpost.co.uk/downloads/cat_1/SPP-Governance-in-the-Age-of-AI-29.7.26.pdf">Governance in the Age of AI: A Practical Framework for Responsible Leadership</a>, aimed at pension scheme trustees and the advisers and administrators who serve them. <a href="https://www.finextra.com/newsarticle/48160/spp-launches-ai-governance-framework-for-pensions-industry">Finextra covered the launch</a> the same week. If you do not work in pensions, read it anyway. Almost nothing in it is specific to pensions, and the argument it makes is the one every department head is about to have.</p>
<h2>What the pensions industry actually said</h2>
<p>The paper&#8217;s central claim is refreshingly unglamorous: AI does not need a new governance regime. It needs the duties that already exist, applied to facts those duties were not written for.</p>
<p>Trustees already owe a duty of prudence. They already have risk registers, service provider oversight, internal controls, and cyber and data governance frameworks. The SPP&#8217;s position is that AI belongs inside all of those, not in a separate binder next to them. The framework sets out five principles: transparency, accountability, proportionality to risk, security by design, and meaningful human oversight. It recommends classifying every AI use as low, medium, or high risk, and keeping an AI register that records current use cases, who owns each one, how it was approved, how often it is reviewed, and what gets reported to the board.</p>
<p>The urgency is in the adoption curve. The SPP&#8217;s own annual surveys found 87% of pension firms using AI in 2025 and 100% in 2026, <a href="https://www.pensionsage.com/pa/SPP-launches-AI-governance-framework-for-pension-schemes.php">as Pensions Age reported</a>. Jo Fellowes, who chairs the SPP&#8217;s administration committee, framed it this way: &#8220;The challenge is therefore not whether AI should be used, but how it can be used safely, transparently and with appropriate oversight.&#8221;</p>
<p>The Pensions Regulator reached the same place in its AI Plan of 20 May 2026, stating that trustees remain accountable for decisions and outcomes even when they delegate activities to providers or advisers. No new obligation was created. An existing one grew a much larger surface area.</p>
<h2>The gap between a principle and a control</h2>
<p>Here is where the paper gets uncomfortable, and where it earns the attention of anyone outside pensions.</p>
<p>&#8220;Meaningful human oversight&#8221; is the principle everyone signs. It is also the one almost nobody can currently evidence. The SPP invokes the Information Commissioner&#8217;s Office, whose draft guidance on automated decision-making went to consultation on 31 March, and the ICO&#8217;s test for meaningful human involvement is unusually concrete. The reviewer has to be trained to understand the system&#8217;s logic, outputs, limits, and risks. They have to hold the authority and the information to reach a different conclusion, not merely endorse the machine&#8217;s. They have to review while the decision can still be changed. And they have to do it every time, because spot checks leave everything else unchecked.</p>
<p>Asked by <a href="https://cfi.co/europe/2026/07/spp-ai-governance-framework-what-human-oversight-now-has-to-mean/">CFI.co</a> whether current administrator and adviser practice would satisfy those criteria, the SPP declined to claim it would. Fellowes said trustees and the industry are still getting to grips with AI uses and how to govern them, so there has not been enough challenge of administrators and advisers to understand what practices they actually have in place.</p>
<p>That is an unusually honest answer from a trade body, and it names the real problem. The distance between writing &#8220;a human reviews the output&#8221; in a policy and being able to prove it under questioning is enormous. It is filled with people, calendars, tooling, records, and someone senior enough to say no.</p>
<h2>Who owns this on Monday</h2>
<p>Every organization I talk to about AI governance is somewhere on the same three-step path, whether they run a pension scheme or a 60-person manufacturer.</p>
<p>They write the policy. That part is fast, and increasingly there is a good published framework to start from, which is exactly what the SPP has just given the pensions industry for free.</p>
<p>Then they discover the policy describes an operating model nobody is operating. There is no register, because building one means asking eleven departments what they are actually using and getting honest answers. There is no risk tiering, because tiering requires someone with the standing to tell a director their favorite tool is high risk. There is no evidence trail, because nobody specified what evidence looks like before the systems went live.</p>
<p>Then they either staff it or they do not. Staffing it properly means a Chief AI Officer, and for most mid-market organizations that role is real but not full-time. That is the gap Modular Technology Group&#8217;s fractional CAIO practice exists to fill: an executive who owns the AI program, writes and maintains the policy, runs the AI register and the sanctioned tool list, tiers the use cases, sets the review cadence, and shows up to the board meeting with the reporting the framework asks for. An AI Program Office behind that keeps the artifacts current between meetings, because a register that is six months stale is worse than none, since it looks like control.</p>
<p>The framework tells you what good looks like. It does not tell you who does it, and it cannot. That part is an org chart decision, and it is the only part that changes anything.</p>
<h2>Your data, your rules, and that includes the AI working on it</h2>
<p>Your AI, your rules. Not the vendor&#8217;s rules, not the model provider&#8217;s terms of service, and not a control that exists in a document and nowhere else.</p>
<p>Ask the three questions the SPP is really asking. Where is AI being used across your operation right now, including the parts nobody approved? Who is accountable for each of those uses by name? If a regulator, a client, or your own board asked you to reconstruct why an AI-assisted decision came out the way it did, could you?</p>
<p>If the answers are uncomfortable, you are in normal company. The SPP just told an entire industry the same thing in writing. The organizations that come out of this well will be the ones that treated the framework as a starting position rather than a finished deliverable, and put a name next to every line of it.</p>
<p>The post <a href="https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/">A framework is not a control. Somebody has to run it.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When compliance is built in, the audit stops being a project</title>
		<link>https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=compliance-built-in-audit-stops-being-a-project</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 00:15:49 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/</guid>

					<description><![CDATA[<p>When compliance is built in, the audit stops being a projectCompliance, compliance-by-architecture, CMMC, ~5 min readAsk a compliance officer what the worst part of the job is and you will rarely hear "the regulations." You will hear about the six weeks before an audit. The scramble to find out which control changed, when, and why.  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/">When compliance is built in, the audit stops being a project</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><strong>When compliance is built in, the audit stops being a project</strong></h1>
<p>Compliance, compliance-by-architecture, CMMC, ~5 min read</p>
<p>Ask a compliance officer what the worst part of the job is and you will rarely hear &#8220;the regulations.&#8221; You will hear about the six weeks before an audit. The scramble to find out which control changed, when, and why. The spreadsheet that was accurate in March. The engineer who has left the company and was the only person who knew how the logging worked.</p>
<p>That scramble is a symptom. It happens because compliance was bolted onto a system after the system existed, and the evidence has to be reassembled by hand every time somebody asks for it.</p>
<p>Pierre Ferran made a version of this argument on Finextra on 29 July, in a piece titled <a href="https://www.finextra.com/blogposting/32405/compliance-is-becoming-infrastructure-not-overhead">Compliance is becoming infrastructure, not overhead</a>. It is written for financial institutions, and the scale he describes is a bank&#8217;s scale. The mechanism he identifies is the same one that breaks a 70-person defense supplier trying to hold CMMC.</p>
<h2>The seam where compliance actually breaks</h2>
<p>Ferran&#8217;s diagnosis is precise, and it is worth quoting the shape of it. The bottleneck in a regulated firm is no longer expertise. Financial institutions employ some of the best regulatory specialists in the world, and they are not confused about what any single rule means.</p>
<p>What breaks is everything sitting between the text and the control. Interpreting the rule for this specific business. Mapping it to the products and processes it touches. Finding the gap in the existing policy. Fixing it. Assigning ownership. And being able to prove all of that later, when an auditor asks in 2027 why a control changed in 2025.</p>
<p>He describes the legacy operating model in a way that will be familiar well outside banking. A guideline is published. Someone in legal reads it and writes a summary. A spreadsheet gets updated. A working group is scheduled for three weeks later. Risk, technology, and product each read the same summary and reach slightly different conclusions about what it means for them, and the reconciliation happens in meetings, months before implementation starts. Then the next consultation closes and the cycle restarts.</p>
<p>By his account, a firm operating across a handful of jurisdictions now faces thousands of regulatory developments a day once you count level-one texts, delegated acts, technical standards, and supervisory guidance. Whether or not that number holds for your sector, the direction is not in dispute. Ferran points to DORA, applicable since January 2025, MiCAR, fully applicable at the end of 2024, and the AI Act phasing in through 2026 and 2027, with an AML package and PSD3 behind them. Regulation stopped being an event and became a flow.</p>
<h2>Security already made this move</h2>
<p>The best part of Ferran&#8217;s argument is the analogy he reaches for. There was a time when a security review happened just before a product went live. Today that would be unthinkable. Security is designed in across the whole build, because managing risk after systems exist is slow and expensive.</p>
<p>The closer precedent, he notes, is internal to compliance itself. GDPR already proved the point inside the discipline. Privacy could not be contained in the legal function. Privacy by design had to reach into product decisions, data protection assessments had to involve engineers, and records of processing depended on data teams keeping them current. That was the first obligation that could not be satisfied by a document.</p>
<p>AI is the next one, and it is less forgiving. An obligation about where personal data may be processed is an architectural question before it is a legal one. If your models run in someone else&#8217;s cloud, in a jurisdiction you did not choose, on infrastructure whose logging you cannot inspect, you are not going to policy your way out of it. The answer to &#8220;where does this data live and who can reach it&#8221; is decided by a purchase order, not a paragraph.</p>
<h2>What building it in looks like</h2>
<p>For a small or mid-sized organization, &#8220;compliance as infrastructure&#8221; is not an abstraction. It is a short list of decisions made in a particular order.</p>
<p>Residency and jurisdiction come first, because they are the hardest to change later. Which physical facility holds the data, under which country&#8217;s law, and who has custody of the keys. Everything downstream inherits from that answer.</p>
<p>Then access, scoped and revocable, with a record. Not a policy that says only authorized personnel may access client data, but a system where unauthorized access is structurally not available and every authorized access leaves a trail nobody can quietly edit.</p>
<p>Then evidence as a byproduct of running, rather than a project that starts eight weeks before the assessor arrives. If your audit trail is generated by the same systems that do the work, the audit stops being an archaeology exercise. You already have the answer to when a control changed, because the change is in the log.</p>
<p>This is what Modular Technology Group means by compliance-by-architecture rather than compliance-by-audit. Private AI infrastructure in a US facility, so residency and jurisdiction are settled facts rather than vendor commitments. Fixed monthly pricing, because a compliance program you cannot budget for is a compliance program that gets deferred. And a program built to satisfy the framework the client is actually held to, whether that is CMMC, NIST 800-171, HIPAA, or FedRAMP alignment, rather than a general posture of being careful.</p>
<p>The economics are the part that usually surprises people. Bolted-on compliance is cheap to start and expensive forever, because every new obligation costs another remediation project. Built-in compliance costs more in month one and then absorbs new requirements as configuration changes. Ferran&#8217;s test for a firm is a good one to steal: how long does it take you, from the day a requirement is published, to know which parts of your operation it touches and who owns the response. If the honest answer is months, the problem is architectural.</p>
<h2>Your data, your rules, from dirt to desktop</h2>
<p>Modular owns the stack from the physical facility through the user interface, which is the only way to answer the residency question without a footnote. One vendor, no handoffs between a cloud provider, a hosting provider, and an AI provider, each of whom can only speak for their own layer.</p>
<p>Compliance has always been the price of operating in a regulated industry. What is changing, and Ferran is right that GDPR started it rather than the AI Act, is that it is turning into the thing that lets you move faster instead of the thing that stops you making mistakes. The firms that get there will not be the ones with the biggest compliance teams. They will be the ones who stopped treating compliance as paperwork and started treating it as plumbing.</p>
<p>The post <a href="https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/">When compliance is built in, the audit stops being a project</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Modular Briefing, August 10, 2026: The Agent Was You</title>
		<link>https://modtechgroup.com/the-agent-was-you/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-agent-was-you</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 13:00:00 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Podcast]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/?p=5915</guid>

					<description><![CDATA[<p>A federal court says the human who points an agent is the one who acted. A stress test says a tired reviewer waves through one dangerous request in three. And a show floor full of agent governance turned out to be mostly dashboards.</p>
<p>The post <a href="https://modtechgroup.com/the-agent-was-you/">The Modular Briefing, August 10, 2026: The Agent Was You</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure class="wp-block-audio"><audio controls src="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-08-10.mp3"></audio><figcaption>The Modular Briefing, August 10, 2026 &middot; 6:27</figcaption></figure>
<p>Cale is back from Ai4 in Las Vegas, and the news wrote his trip report for him. Three stories this week, and one question underneath all of them: when an agent acts, who answers for it?</p>
<h2>In this episode</h2>
<ul>
<li><strong>A federal court says the human who points the agent is the one who acted.</strong> On August 4 the Ninth Circuit vacated the injunction Amazon had won against Perplexity&#8217;s Comet shopping agent. Under the federal anti-hacking law, the court read &#8220;access&#8221; as a person entering a system; software is a tool, and tools do not carry liability. One circuit, an early stage, and Amazon&#8217;s other theories are still live. <a href="https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf" rel="nofollow noopener" target="_blank">Opinion, No. 26-1444 (PDF)</a></li>
<li><strong>&#8220;A human reviews it&#8221; has a measured failure rate.</strong> Belgian developer Alex Wauters built a browser game that flashes real agent permission prompts on a sixty-second clock. Across more than forty thousand rounds, players approved roughly one dangerous request in three. Anthropic&#8217;s own telemetry puts real-world approval around ninety-three percent. <a href="https://www.theregister.com/ai-and-ml/2026/08/06/humans-in-the-loop-miss-a-third-of-dangerous-ai-coding-agent-requests/5284236" rel="nofollow noopener" target="_blank">The Register</a></li>
<li><strong>Half a continent could last one business day.</strong> A survey of 1,500 firms across the UK, France and Germany found 73.9% worried Washington could cut off their access to US technology, and 54.5% said they could operate for a single business day without their cloud services. 44% have a continuity plan they have tested. The survey was commissioned by Proton, which sells the sovereign alternative; weigh it accordingly. <a href="https://www.theregister.com/off-prem/2026/08/06/european-firms-afraid-of-us-tech-kill-switch-but-havent-made-an-escape-plan/5284030" rel="nofollow noopener" target="_blank">The Register</a></li>
</ul>
<h2>Report from the floor: Ai4 2026</h2>
<p>Cale worked more than thirty booths at The Venetian, August 4 to 6. Three things he brought home.</p>
<ul>
<li><strong>The argument won.</strong> A main-stage keynote titled &#8220;From Renting AI to Owning Intelligence.&#8221; Appliance vendors printing &#8220;No tokens. No surprises.&#8221; on their booth walls. The CIO of a NATO procurement agency describing keeping local models close for sensitive work. Owning your AI has stopped being a niche position.</li>
<li><strong>Most &#8220;agent governance&#8221; is a dashboard.</strong> It shows you what your agent did. Far fewer products will stop it, and watching an agent misbehave in real time is not a control. The crowd of new names read like the late nineties; Cale&#8217;s own bet, offered as a bet, is that many are gone within a year. If your oversight lives in a startup&#8217;s dashboard, your controls inherit that startup&#8217;s odds.</li>
<li><strong>Ng and Hinton.</strong> They disagree about where this goes, and Hinton&#8217;s doom ran a little thick for Cale. The take-home fits in two sentences: build now, the way Ng says. Govern like Hinton is right.</li>
</ul>
<h2>The question we asked</h2>
<p>If one of your agents did something wrong yesterday, could you reconstruct what it touched, or would you be guessing? <a href="https://modtechgroup.com/newsletter/?utm_source=podcast&amp;utm_medium=shownotes&amp;utm_campaign=briefing-2026-08-10">Get the Modular Briefing by email</a> and reply to it. A person reads every reply.</p>
<h2>A note on the voices</h2>
<p>Laura and Arthur are AI-generated voices, produced locally on Modular&#8217;s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.</p>
<h2>Transcript</h2>
<details>
<summary>Read the full transcript</summary>
<p><strong>Arthur:</strong> Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I&#8217;m Arthur.</p>
<p><strong>Laura:</strong> And I&#8217;m Laura. When we left you, we said Cale was headed to Ai4 in Las Vegas to see what actually holds up. He&#8217;s back. Three days, thirty booths, two legends on stage, and one sticker from the CIA. What he saw is the story the news wrote while he was there. When an agent acts, who answers for it? A federal court just gave an answer. So did a stress test of human oversight. So did a continent pricing its own dependency.</p>
<p><strong>Arthur:</strong> Story one. On August fourth, the Ninth Circuit Court of Appeals answered the question every AI pilot eventually runs into. When an agent acts, who did it? The case was Amazon against Perplexity, whose Comet shopping agent had been operating on Amazon&#8217;s site on customers&#8217; behalf. Amazon had won an order blocking it back in March. The appeals court threw that order out.</p>
<p><strong>Laura:</strong> And the reasoning is the part your business should care about. Under the federal anti-hacking law, the court said access means a person entering a computer system. Software is a tool. Tools don&#8217;t carry liability. So when your employee points an agent at a system, the one who accessed it is your employee. And behind your employee, your firm. The honest caveats, because the legal press is being careful and so are we. One circuit, an early stage, and Amazon&#8217;s other legal theories are still open. This is not a court declaring agents fine. But it&#8217;s the first appellate word, and it points the accountability at whoever deployed the agent. So the vague question just became specific. Who at your firm may point an agent at what, and is that written down? If nobody wrote it down, then today the answer is everybody. Your data, your rules, and that goes for the AI itself. Your AI, your rules.</p>
<p><strong>Arthur:</strong> Story two. Almost every AI policy written this year leans on one sentence. A human reviews it. This week The Register reported a number for how much weight that sentence holds. A Belgian developer, Alex Wauters, built a browser game that flashes real agent permission prompts, some safe, some dangerous, sixty seconds to approve or deny. Across forty thousand rounds, players approved roughly one dangerous request in three.</p>
<p><strong>Laura:</strong> And before anyone says that&#8217;s just a game, Anthropic&#8217;s own telemetry says real users approve about ninety-three percent of what their agents ask for. Approval fatigue. The more prompts you see, the less you read each one. Cale heard the same conclusion from the defense side at Ai4. On the cybersecurity panel that stuck with him most, Ed Cartagena of Menlo Security laid out the new threat picture, and Cale&#8217;s takeaway was two sentences long. An agent with borrowed credentials behaves like a fast, tireless employee nobody supervises. And attacks move at machine speed, so a human clicking yes on every step was never going to be the control that holds. Your people aren&#8217;t careless. The control was never built to carry the whole load. So layer it. Least access, so a bad yes can&#8217;t reach client files. A boundary the agent can&#8217;t talk its way out of. Let the machines watch the machines, and save the humans for the calls a human should make.</p>
<p><strong>Arthur:</strong> Story three, also from The Register. A survey of fifteen hundred businesses across the UK, France and Germany found nearly three in four are worried the US government could cut off their access to American technology. And more than half said that if they lost their cloud services, they could keep operating for one business day. One.</p>
<p><strong>Laura:</strong> Fair disclosure, the way the reporting makes it. The survey was commissioned by Proton, a Swiss company that sells the sovereign alternative, so weigh it accordingly. But the gap is real, and it isn&#8217;t only European. Fewer than half of those firms have a continuity plan they&#8217;ve actually tested. So here&#8217;s the move. An exit plan is not a migration. It&#8217;s a document. Where does your data live? Who can reach it? What still runs if a vendor stops answering? How long would a move take? You can write the first version in an afternoon. And if you want the stronger position, run the work that matters on infrastructure you control, from dirt to desktop, so the kill switch question never has your name in it. Your data, your rules.</p>
<p><strong>Arthur:</strong> Before we close, the report from the floor. Cale talked to every booth he could get to at Ai4, more than thirty. Infrastructure on one end, agent governance as far as he could see. Cisco. PayPal. Mistral. His read comes in three parts.</p>
<p><strong>Laura:</strong> Part one, the argument won. A main stage keynote was literally titled From Renting AI to Owning Intelligence, appliance vendors are printing no tokens, no surprises on their booth walls, and the CIO of a NATO procurement agency described keeping local models close for the sensitive work. Owning your AI has quit being a niche position. Part two, a warning if you&#8217;re shopping that hall. Most of what&#8217;s sold as agent governance is a dashboard. It shows you what your agent did. Far fewer products will stop it, and watching an agent misbehave in real time is not a control. The crowd of new names reminded Cale of the late nineties, and his honest bet, take it as one, is that many won&#8217;t be around in a year. If your oversight lives in a startup&#8217;s dashboard, your controls inherit that startup&#8217;s odds. Part three, the keynotes. Andrew Ng and Geoffrey Hinton famously disagree about where this goes, and Cale will tell you Hinton&#8217;s doom ran a little thick. His take home fits in two sentences. Build now, the way Ng says. Govern like Hinton is right.</p>
<p><strong>Arthur:</strong> So the thread. The court says an agent&#8217;s actions belong to whoever pointed it. The research says a tired human clicking yes isn&#8217;t ownership. Half a continent just learned that renting everything means owning nothing. And on that show floor, capability was everywhere and enforcement was scarce. Capability is easy to buy. Accountability has to be assigned.</p>
<p><strong>Laura:</strong> Our question this week, and be honest. If one of your agents did something wrong yesterday, could you reconstruct what it touched, or would you be guessing? Reply to the Modular Briefing email and tell us which one you are. A person reads every reply.</p>
<p><strong>Arthur:</strong> Thanks for spending a few minutes with us.</p>
<p><strong>Laura &amp; Arthur:</strong> This has been The Modular Briefing. Your data, your rules. We will see you next time.</p>
</details>
<p><em>Your data, your rules.</em></p>
<p>The post <a href="https://modtechgroup.com/the-agent-was-you/">The Modular Briefing, August 10, 2026: The Agent Was You</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-08-10.mp3" length="9310084" type="audio/mpeg" />

			</item>
		<item>
		<title>Your agents will guess. Permissions decide what that costs you.</title>
		<link>https://modtechgroup.com/your-agents-will-guess-permissions-decide-the-damage/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=your-agents-will-guess-permissions-decide-the-damage</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Sat, 08 Aug 2026 21:45:50 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/your-agents-will-guess-permissions-decide-the-damage/</guid>

					<description><![CDATA[<p>Your agents will guess. Permissions decide what that costs you.Agentic AI, agent governance, permissions, ~5 min readSomebody at your company has already handed an AI agent a credential. Maybe it went through review. Maybe an operations manager wanted invoice reconciliation to stop eating her Fridays, found a tool that promised it, and pasted in a  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/your-agents-will-guess-permissions-decide-the-damage/">Your agents will guess. Permissions decide what that costs you.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><strong>Your agents will guess. Permissions decide what that costs you.</strong></h1>
<p>Agentic AI, agent governance, permissions, ~5 min read</p>
<p>Somebody at your company has already handed an AI agent a credential. Maybe it went through review. Maybe an operations manager wanted invoice reconciliation to stop eating her Fridays, found a tool that promised it, and pasted in a service account key. The agent works. It has been working for six weeks. Nobody wrote down what it is allowed to touch, who owns it, or how you would switch it off at four o&#8217;clock on a Friday.</p>
<p>A piece published on BleepingComputer on 29 July puts the mechanism plainly: <a href="https://www.bleepingcomputer.com/news/security/your-ai-agents-are-guessing-at-scale-permissions-decide-the-damage/">agents guess</a>. They try an action, read what comes back, adapt, and try again. The article is sponsored content from an identity security vendor, so take the product pitch with the usual salt. The diagnosis holds up anyway, and it is the part worth putting in front of your own team.</p>
<h2>Guessing is the job description</h2>
<p>A script does the same thing every time. You can read it, test it, and know what it will do in production because it has no capacity to do anything else. An agent works differently on purpose. You give it an objective, and it decides on the path. That flexibility is why anyone wants one. It is also why you cannot write an allow-list of the actions it will take, because neither you nor the vendor knows what they will be until it takes them.</p>
<p>Most of the safety work being sold right now sits downstream of that. Prompt filters, content policies, behavioral monitoring: all of them inspect what the agent is trying to do after it already holds the keys to do it. The BleepingComputer piece has a good line about the arithmetic there. One percent of infinity is still infinity. An agent making thousands of decisions a week against a filter that catches almost everything will still get through, and when it does, the only thing standing between a wrong guess and a bad outcome is what that agent&#8217;s credential can reach.</p>
<p>So the useful question is not whether the agent will be wrong. It will be wrong. The question is how far a wrong answer travels.</p>
<h2>The math nobody put in the budget</h2>
<p>Palo Alto Networks surveyed 2,930 security leaders for its 2026 Identity Security Landscape report and found <a href="https://www.paloaltonetworks.com/idira/identity-security-landscape-report">109 machine identities for every human identity</a> in the enterprise, up from 82 to 1 the year before. The same research found that 96% of respondents say their human identities already operate with access well beyond what their roles require.</p>
<p>Two more numbers from that report are the ones I would put on a slide. Only 37% of organizations can revoke an AI agent&#8217;s credentials. Only 30% keep immutable audit logging of what those agents did.</p>
<p>Sit with that for a second. A third of companies can turn an agent off. Under a third can reconstruct what it touched. Everyone else has deployed something that acts on their data, at speed, with standing access, and has no mechanism to stop it or to explain it afterward. That is not a technology gap. It is a governance gap wearing a technology costume.</p>
<p>Small and mid-sized organizations tend to assume this is an enterprise problem because the identity counts are enterprise counts. The ratio is the point, not the total. A 45-person company running a handful of agents across email, finance, and a shared drive has the same structural exposure as a bank, minus the identity team that would notice.</p>
<h2>Scope the mandate, not the model</h2>
<p>The fix is old and boring, which is why it works. Treat an agent the way you would treat the person whose work it took over.</p>
<p>That person had a job description. They had a manager. They had access to the systems their job required and not the ones it did not. When they left, IT closed the account, and there was a record of what they had done while they were there. None of that was exotic. It was just applied consistently, because HR and IT had a shared process that made skipping it awkward.</p>
<p>Applied to agents, it comes down to four things you can start this week:</p>
<ul>
<li>Find them. Every organization has more agents running than leadership has approved. Ask each department head what is automated and who set it up, and write the answers down. This is a conversation, not a scan.</li>
<li>Give each one a named human owner and a written mandate. What is this agent for, what data does it need, what is it explicitly not permitted to do. If nobody will put their name on it, that is your answer about whether it should be running.</li>
<li>Scope the credential to the mandate, and make it revocable. Standing broad access is the multiplier that turns a wrong guess into an incident. An agent that reconciles invoices does not need write access to the CRM.</li>
<li>Log what it did, somewhere it cannot edit. When an auditor, a client, or your own board asks why a decision came out the way it did, &#8220;the AI did it&#8221; is not an answer that survives contact with anyone.</li>
</ul>
<p>Notice that none of this requires you to predict the agent&#8217;s behavior. It requires you to bound it. That is the shift the BleepingComputer piece is arguing for, and it is the same shift identity teams made twenty years ago when they stopped trying to trust users and started scoping them.</p>
<h2>Your data, your rules, and that includes the AI working on it</h2>
<p>Your AI, your rules. That means an agent operating inside your walls, on infrastructure you control, with permissions you set and can withdraw, and a record you own of everything it did. Not a promise from a vendor that their filters are good. A boundary you can point at.</p>
<p>At Modular Technology Group we build agent programs this way because the alternative gets expensive in a specific, predictable direction: the day something goes wrong and nobody can say what happened. Modular&#8217;s agent work runs under a written policy from day one, with a named owner per agent, scoped and revocable access, and an audit trail that lives on the client&#8217;s own infrastructure rather than a vendor&#8217;s.</p>
<p>Agents are worth having. Ours run our own operations daily. But an agent is a delegation of authority, and delegation without a mandate is just hoping. Start with the list of what is already running. Most teams find it is longer than they expected, and that discovery alone is worth the afternoon.</p>
<p>The post <a href="https://modtechgroup.com/your-agents-will-guess-permissions-decide-the-damage/">Your agents will guess. Permissions decide what that costs you.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Modular Briefing, July 31, 2026: Is There a Name on It?</title>
		<link>https://modtechgroup.com/is-there-a-name-on-it/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=is-there-a-name-on-it</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Sat, 01 Aug 2026 02:26:31 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Podcast]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/is-there-a-name-on-it/</guid>

					<description><![CDATA[<p>Your team is already using AI in ways nobody approved, real oversight means somebody can say no, and the law is coming looking for a name. Have one ready.</p>
<p>The post <a href="https://modtechgroup.com/is-there-a-name-on-it/">The Modular Briefing, July 31, 2026: Is There a Name on It?</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure class="wp-block-audio"><audio controls src="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-07-31.mp3"></audio><figcaption>The Modular Briefing, July 31, 2026 &middot; 4:46</figcaption></figure>
<p>Three stories this week, and one question underneath all of them: when the AI does something, whose name is on it?</p>
<h2>In this episode</h2>
<ul>
<li><strong>Your team is already using AI outside their job.</strong> An OpenAI analysis of more than 800,000 work messages found 44% of occupation-specific messages involved tasks outside the sender&#8217;s own role. For HR professionals it was 69%, third highest of any group, and the crossover runs highest at small companies. <a href="https://www.hrdive.com/news/hr-uses-chatgpt-complete-non-hr-tasks/826459/" rel="nofollow noopener" target="_blank">HR Dive</a></li>
<li><strong>What real oversight looks like.</strong> The Society of Pension Professionals published a five-principle AI governance framework. Two travel to any industry: tier AI uses by risk instead of writing one blanket rule, and make sure the human reviewing an automated decision has the authority to overturn it. <a href="https://www.finextra.com/newsarticle/48160/spp-launches-ai-governance-framework-for-pensions-industry" rel="nofollow noopener" target="_blank">Finextra</a></li>
<li><strong>&#8220;AI did it&#8221; is not a defense.</strong> After a rogue agent went after another company&#8217;s systems, lawyers were asked who is liable. Nobody knows yet, because the law was built around human decision makers. Liability turns on who designed the system, who set its objectives, what safeguards existed, and how much independence was judged acceptable. <a href="https://www.theregister.com/legal/2026/07/30/excuses-like-ai-did-it-dont-exist-in-the-eyes-of-the-law/5280767" rel="nofollow noopener" target="_blank">The Register</a></li>
</ul>
<h2>From the week</h2>
<p>Cale&#8217;s post on a bank hiring its first Chief AI Officer reached more than thirteen thousand people. Two later versions of the same argument reached about two hundred each. The difference was posting the day the news broke and opening with the specifics.</p>
<h2>On the road</h2>
<p>Modular is at Ai4 in Las Vegas, August 4 to 6, at The Venetian.</p>
<h2>The question we asked</h2>
<p>At your firm, right now, if somebody asked who approved the AI that touches your client files, is there a name? Or is there a document? Tell us. <a href="https://modtechgroup.com/newsletter/?utm_source=podcast&#038;utm_medium=shownotes&#038;utm_campaign=briefing-2026-07-31">Get the Modular Briefing by email</a> and reply to it, and it lands with a person who reads it.</p>
<h2>A note on the voices</h2>
<p>Laura and Arthur are AI-generated voices, produced locally on Modular&#8217;s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.</p>
<h2>Transcript</h2>
<details>
<summary>Read the full transcript</summary>
<p><strong>Laura:</strong> Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I&#8217;m Laura.</p>
<p><strong>Arthur:</strong> And I&#8217;m Arthur. Three stories today, and one question sitting underneath all of them. When the AI does something, whose name is on it? What your people are quietly using it for, what real oversight looks like, and what the law does when nobody is accountable.</p>
<p><strong>Laura:</strong> Story one. This week a research team published an analysis of more than eight hundred thousand messages from people using a popular AI chatbot for work in the United States. Here is the number. Across every occupation they studied, forty-four percent of work messages were about tasks outside the sender&#8217;s own job. For people in human resources, it was sixty-nine percent. Third highest of any group.</p>
<p><strong>Arthur:</strong> Sit with what that means. Roughly two out of three times an HR professional opens that tool at work, they are doing marketing, or engineering, or finance. Not HR. That is not people slacking. That is people solving a problem that landed on their desk with nobody to hand it to. The report found the crossover runs highest at small companies. Now the uncomfortable version. If your HR team is drafting finance work in a general public tool, what employee information went in with the prompt? A ban does not fix that, because the need is real and the need wins. A sanctioned workspace your company actually owns does, with one person accountable for what goes into it. Your data, your rules.</p>
<p><strong>Laura:</strong> Story two. A pensions industry body published an AI governance framework this week for trustees and administrators. Five principles. Two of them are worth stealing no matter what business you are in.</p>
<p><strong>Arthur:</strong> The first is proportionality. Instead of one blanket AI rule for the whole company, you sort uses into low, medium and high risk, and the high risk ones get real validation. Drafting a meeting summary is not the same as calculating somebody&#8217;s retirement benefit, and a policy that treats them identically gets ignored at both ends. The second is the one people skip. They call it meaningful human oversight, and the word doing the work is meaningful. The reviewer has to hold real authority to change the outcome. If the person reviewing cannot overturn the machine, you do not have oversight. You have a rubber stamp with a job title. That is the whole difference between a framework you can show an auditor and a framework you can actually run.</p>
<p><strong>Laura:</strong> Story three, and it ties the week together. After an AI agent broke out of a test environment and went after another company&#8217;s systems, reporters put a simple question to the lawyers. Who is legally responsible when an AI agent attacks? The answer, so far, is that nobody knows.</p>
<p><strong>Arthur:</strong> The reason is worth understanding. Our laws were built around human decision makers. They know how to ask about intent and oversight. An AI system is not a legal person, so it cannot carry any of that. One security strategist quoted in the piece laid out where the questions land instead. Who designed the system. Who decided what it was chasing. What safeguards were in place. How much independence somebody judged acceptable. Look at that list. Every one of those is answered by a person, or it does not get answered. The AI did it is not a defense. It is an unanswered question with your company&#8217;s name on it.</p>
<p><strong>Laura:</strong> One more, and this one is from our own week.</p>
<p><strong>Arthur:</strong> Cale wrote about a bank hiring its first Chief AI Officer, and the argument was the one we just made. Somebody has to own the decision. That post reached more than thirteen thousand people. He wrote the same argument two more times and posted it the next two mornings. Those reached about two hundred each.</p>
<p><strong>Laura:</strong> Same person, same idea, same audience. So what changed?</p>
<p><strong>Arthur:</strong> The day, and the first sentence. The one that traveled went out while the news was still news, and it opened with the bank, the name and the job title. Which is the same reason vague policies fail. Nobody can act on use AI responsibly.</p>
<p><strong>Laura:</strong> That is the thread today. Your team is already using AI in ways nobody approved, real oversight means somebody can say no, and the law is going to come looking for a name. Have one ready.</p>
<p><strong>Arthur:</strong> Quick note. Modular is at Ai4 in Las Vegas this week, August fourth through sixth. Cale is going for what is actually running in production, not what is announced from a stage. Whatever holds up, you will hear it here.</p>
<p><strong>Arthur:</strong> And here is our question this week, and we want a real answer. At your shop, if somebody asked who approved the AI that touches your client files, is there a name? Or is there a document? Tell us. Reply to the Modular Briefing email and it lands with a person who reads it.</p>
<p><strong>Laura:</strong> Thanks for spending a few minutes with us.</p>
<p><strong>Laura &#038; Arthur:</strong> This has been The Modular Briefing. Your data, your rules. We will see you next time.</p>
</details>
<p><em>Your data, your rules.</em></p>
<p>The post <a href="https://modtechgroup.com/is-there-a-name-on-it/">The Modular Briefing, July 31, 2026: Is There a Name on It?</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-07-31.mp3" length="6878189" type="audio/mpeg" />

			</item>
		<item>
		<title>What &#8216;private AI&#8217; actually means</title>
		<link>https://modtechgroup.com/what-private-ai-actually-means/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-private-ai-actually-means</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 12:16:09 +0000</pubDate>
				<category><![CDATA[Modular]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/what-private-ai-actually-means/</guid>

					<description><![CDATA[<p>What "private AI" actually meansModular house · Explainer, Private AI · ~4 min readPrivate AI is your models and your agents running on infrastructure you control, with your data staying inside boundaries you set. The name is about who holds the keys. It says nothing about how capable the tools are. Your data, your rules,  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/what-private-ai-actually-means/">What &#8216;private AI&#8217; actually means</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>What &#8220;private AI&#8221; actually means</h1>
<p>Modular house · Explainer, Private AI · ~4 min read</p>
<p>Private AI is your models and your agents running on infrastructure you control, with your data staying inside boundaries you set. The name is about who holds the keys. It says nothing about how capable the tools are. Your data, your rules, from dirt to desktop, one partner from the hardware to the interface. Here is what that looks like in practice, and what it does not require you to give up.</p>
<h2>The common misconception</h2>
<p>Say &#8220;private AI&#8221; in a planning meeting and watch what people picture. Usually something small. A stripped-down model wheezing away on a spare laptop, good for a demo and not much else, the discount version of the tools everyone already uses at work. That picture is years out of date. A private workspace runs current open-weight models, several of them, on real hardware in a real facility, and you pick the one that fits the job. Privacy and capability are two separate questions. Answering one does not cost you the other.</p>
<p>The confusion is easy to forgive, because the line got blurry on purpose. The public tools sell a business tier with a setting that promises your data will not be used for training, and that promise is worth something. Read where it lives, though. It lives in a contract, and a contract is a thing both parties can revisit. Meanwhile your prompts still leave your building, cross the open internet, and land on servers you have never seen, in a jurisdiction you did not pick. The setting governs what the vendor says it will do with your data. Where your data goes stays the same.</p>
<p>Private AI closes that gap by removing the trust exercise entirely. Data cannot leak out of a boundary when the computing happens inside the boundary. There is nothing to opt out of. A setting is a promise. A boundary is a fact.</p>
<h2>The three things that make AI private</h2>
<p>Start with where the model runs, because everything else follows from it. When you ask a public tool a question, the question travels. It leaves your network, crosses the internet, and gets processed in a data center you cannot name, alongside everyone else&#8217;s traffic. Private AI turns that around: instead of sending your data to the model, you bring the model to your data. For our clients that means an isolated environment in a US-based, FedRAMP-certified data center, and for organizations that want it, dedicated hardware on their own premises. The question gets answered a few racks away from the data it draws on. Sometimes a few feet.</p>
<p>Then the data itself, which covers a lot more than chat history. The real value of a workspace shows up when you connect it to your documents. Contracts, research, case files, the institutional memory of the whole company. That happens through retrieval: the model reads the relevant pieces of your knowledge base at query time and grounds its answer in them. In a private environment, the documents, the index built from them, and the retrieval itself all stay inside the same boundary. Nothing is used to train anyone&#8217;s model. Nothing is retained by a third party, because there is no third party in the room.</p>
<p>And the part that gets discussed least while mattering most: who draws the boundary. Who can see which documents. Whether the system can reach the internet at all. What gets encrypted, what gets backed up, and what happens to all of it if you decide to leave. On public platforms those rules are set by the vendor and adjusted at the vendor&#8217;s discretion. In a private environment they are yours to set: access controls that separate the legal team&#8217;s vault from marketing&#8217;s, an air gap where the work demands one, and an exit that is just your data, in usable formats, walking out the door with you. That last one tells you who really owned the environment. If leaving is easy, you did.</p>
<h2>What you keep</h2>
<p>Everything your team actually liked about the public tools. The chat interface, the drafting and summarizing, the document questions, the code help. Those run just as well on infrastructure you control, through a clean web interface with access to multiple models, so people pick the model that fits the task instead of the one a vendor is promoting this quarter. Good UX is a software problem, and the software exists. Nobody has to learn to love a command line.</p>
<p>You also keep room to grow, because private is a spectrum, and you do not have to buy the far end of it on day one. Our Wildcat tier is the entry point: an isolated environment on shared infrastructure, in the same FedRAMP facility, under the same US jurisdiction as everything above it. Panther steps up to dedicated infrastructure, with file vaults, role-based access controls, and enhanced encryption for teams handling sensitive documents. Grizzly is the top: fully dedicated hardware, zero-trust architecture, an optional air gap, and the option to run it on your own premises instead of ours. The boundary tightens as you climb. What never changes is the jurisdiction. Your data stays in the United States whether it sits in our facility or in your building.</p>
<p>And you keep one accountable partner across the whole stack. The facility, with its redundant power and its guarded doors. The hardware in the racks. The models, kept patched and current, swapped for better ones as better ones ship. The interface your people log into every morning. When something needs attention, there is no seam between a cloud vendor, a hosting vendor, and an AI vendor for the problem to fall through. You hold the deed, and there is one number to call.</p>
<p>Your data, your rules.</p>
<p>The post <a href="https://modtechgroup.com/what-private-ai-actually-means/">What &#8216;private AI&#8217; actually means</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The hidden cost of renting your AI</title>
		<link>https://modtechgroup.com/hidden-cost-of-renting-your-ai/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=hidden-cost-of-renting-your-ai</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 23:16:05 +0000</pubDate>
				<category><![CDATA[Modular]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/hidden-cost-of-renting-your-ai/</guid>

					<description><![CDATA[<p>The hidden cost of renting your AIFrom the Desk of Cale · Cost, Fixed-cost AI · ~5 min readPer-token pricing is a great way to start and a hard way to budget. The variable cost of someone else's AI infrastructure isn't actually variable to you. You just absorb the outputs: pricing changes, capacity limits, decisions  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/hidden-cost-of-renting-your-ai/">The hidden cost of renting your AI</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>The hidden cost of renting your AI</h1>
<p>From the Desk of Cale · Cost, Fixed-cost AI · ~5 min read</p>
<p>Per-token pricing is a great way to start and a hard way to budget. The variable cost of someone else&#8217;s AI infrastructure isn&#8217;t actually variable to you. You just absorb the outputs: pricing changes, capacity limits, decisions made at a scale you&#8217;ll never see. Fixed, right-sized private infrastructure flips that. You know what you&#8217;re paying, and you know why.</p>
<h2>The day-one price is not the real price</h2>
<p>I&#8217;ve been thinking about taxi meters. A taxi is the right call for a trip to the airport, and nobody argues with the meter for one ride. But if you found yourself taking that same taxi to work every morning, you&#8217;d start doing math on a car payment before the end of the month. Per-token AI is a taxi meter, and a lot of companies are now commuting in it. Nobody chose the commute, either. The meter was already running when the habit formed.</p>
<p>The day-one price looks great because day-one usage is tiny. A handful of questions, a summarized document or two. Fractions of a cent each. Then the tool turns out to be useful, which is the whole point, and useful tools get used. People stop asking one question and start pasting in whole contracts. Someone wires it into a workflow that runs on every support ticket. Then come the agents, and an agent doesn&#8217;t make one call per task. It reads the document, checks its own work, calls a tool, reads the result, tries again. Every one of those steps is a metered ride. The per-token price never moved. Your consumption did, while everyone was busy being productive.</p>
<p>I sat with a client this spring and put a year of their AI invoices side by side on one screen. That was the entire exercise. No spreadsheet wizardry, no consultants. The line went one direction, and nobody in the room could name a month where anyone decided to spend more. That&#8217;s the tell. Metered costs don&#8217;t get decided. They accumulate.</p>
<h2>Variable to them, fixed to you (and vice versa)</h2>
<p>Here&#8217;s the part that took me embarrassingly long to see clearly. The provider&#8217;s costs are mostly fixed. The data centers are already built and the payroll is already set. What&#8217;s variable, to them, is you. Metered pricing is how they convert their fixed cost into your variable one. That&#8217;s a rational move on their side of the table. It&#8217;s just worth noticing which side of the table you&#8217;re on. When a business absorbs volatility, it charges for the service. When it passes volatility through, you&#8217;re the one providing that service, and nobody&#8217;s paying you for it.</p>
<p>So when their world shifts, the shift gets passed through. A new model generation lands and the price per token changes. Demand spikes and rate limits show up at exactly your busy hour. An older model gets retired, and the workflow your team spent a quarter tuning now runs on something that behaves differently. There&#8217;s no villain in any of that. A business planning for millions of customers makes ordinary capacity decisions, and you&#8217;re one line in the plan. You don&#8217;t get a vote. You get an email.</p>
<p>Now put yourself in the budget meeting. Finance asks what AI will cost next year. The honest answer under metered pricing is &#8220;it depends on how much people use it,&#8221; which is another way of saying the better it works, the less we can predict. That&#8217;s a strange incentive to hand a mid-sized team. Success becomes a cost overrun. I&#8217;ve watched a manager quietly discourage adoption of a tool his own company was paying for, because every new enthusiastic user made his forecast worse. Every budget is a guess, but this one is a guess about other people&#8217;s guesses.</p>
<h2>What predictable looks like</h2>
<p>Predictable starts with a boring question: what do you actually run? Not someday, today. Count the real workloads. The document review, the drafting, the internal search, the two or three automations that matter. Most teams find the list is shorter than they feared and steadier than the invoices implied. That steadiness is the asset. You size for your own team and the work it actually does. The whole internet is somebody else&#8217;s capacity problem. Once you know the workload, you can size the hardware to it, and once the hardware is sized, the cost is flat. You know the number in January and it&#8217;s still the number in October.</p>
<p>That&#8217;s the shape of what we build at Modular Technology Group. Our Private AI Workspaces start with Wildcat on shared infrastructure, step up to Panther on dedicated infrastructure, and top out at Grizzly on fully dedicated hardware, which you can host with us or stand up in your own building. The hosted tiers all live in a US-based, FedRAMP-certified data center. Every one of them bills as a flat monthly number. No per-token billing anywhere. We run our own work on the same stack, so when the meter argument comes up, we&#8217;re not speculating. We live on the fixed side of it. Right-sizing is a conversation. Some teams land on shared infrastructure and stay there happily. Some need the hardware where they can see it. Either way the number gets chosen, and you&#8217;re in the room when it happens.</p>
<p>The total-cost math is worth saying plainly. Owning can look more expensive on day one, the way a car payment looks worse than one cab fare. But a fixed cost changes the direction of every incentive after that. Under a meter, each new user is a liability. On infrastructure you own, each new user makes every task cheaper, because the same monthly number is now doing more work. You quit rationing the tool and start pushing it. Adoption stops being a cost problem and turns back into what it should have been, which is a productivity story. And because the models sit behind an interface you control, no single provider&#8217;s pricing decision can reach into your budget. When a better open model ships, it slots in. The bill doesn&#8217;t notice.</p>
<p>Here&#8217;s something you can do this week, and it costs nothing. Pull your last twelve months of AI invoices and put them in one place. Ask two questions. What happens to this line if usage doubles, and who decided the current number? If the answers are &#8220;it doubles&#8221; and &#8220;nobody,&#8221; you&#8217;re renting, and now you know what the rent really is. Then you get to decide what the number should be instead. Your data, your rules, from dirt to desktop.</p>
<p>If your AI line item has quit behaving, or you just want a second set of eyes on the own-versus-meter math, I&#8217;m always glad to compare notes. No pitch. Bring the invoices.</p>
<p>Own it, don&#8217;t rent it. Your data, your rules.</p>
<p>The post <a href="https://modtechgroup.com/hidden-cost-of-renting-your-ai/">The hidden cost of renting your AI</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Modular Briefing, Episode 8: Who Gave It the Keys?</title>
		<link>https://modtechgroup.com/who-gave-it-the-keys/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=who-gave-it-the-keys</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Sun, 26 Jul 2026 13:31:30 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[Podcast]]></category>
		<category><![CDATA[agentic]]></category>
		<category><![CDATA[agents]]></category>
		<category><![CDATA[AI guardrails]]></category>
		<category><![CDATA[oversight]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/who-gave-it-the-keys/</guid>

					<description><![CDATA[<p>One link can create an agent with your connectors attached. Who hands out that authority, who watches it, and who decides where it runs.</p>
<p>The post <a href="https://modtechgroup.com/who-gave-it-the-keys/">The Modular Briefing, Episode 8: Who Gave It the Keys?</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div style="margin:0 0 24px;">
<audio controls preload="metadata" style="width:100%;" src="https://assets.modtechgroup.com/podcast/audio/modular-briefing-ep08.mp3"></audio>
<p style="font-size:16px;color:#ffffff;margin:6px 0 0;">Episode 8 &middot; 4:40 &middot; <a href="https://assets.modtechgroup.com/podcast/audio/modular-briefing-ep08.mp3">Download MP3</a> &middot; <a href="https://assets.modtechgroup.com/podcast/feed.xml">RSS</a> &middot; <a href="#transcript">Transcript</a></p>
</div>



<p class="wp-block-paragraph">An AI agent is not a feature you switch on. It is an actor with authority. This week: a single link that could build a working agent inside somebody&#8217;s workspace with every connector attached and approvals switched off, an attacker who ran an agent unattended inside a national finance ministry, and a government that stopped a billion-euro cloud procurement to ask where its data lives. Three sizes of the same question.</p>



<h2 class="has-text-color wp-block-heading" style="color:#ffffff">In this episode</h2>



<ul class="wp-block-list">
<li><strong>A link that built an agent.</strong> Researchers showed one crafted URL could create a working agent inside a logged-in account, attach every connected mailbox and file store, set approvals to never ask, and put it on an hourly schedule. Patched on June 8, with no reported exploitation in the wild. The open question is not the bug. It is how casually agent authority gets handed out.</li>
<li><strong>An agent nobody was supervising.</strong> A security firm reports an attacker running an off-the-shelf agent with its approval mode disabled for post-exploitation work inside a national finance ministry. One firm is the only public source and the ministry has not confirmed it. The transferable lesson is that the useful setting was the one that removed the human.</li>
<li><strong>A government asking where its data lives.</strong> Ireland&#8217;s Office of Government Procurement cancelled a cloud framework competition over digital sovereignty. Jurisdiction moved from a slide in a security review to a reason to stop a contract.</li>
</ul>



<h2 class="has-text-color wp-block-heading" style="color:#ffffff">Sources</h2>



<ul class="wp-block-list">
<li><a href="https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html" rel="nofollow">The Hacker News, July 24, 2026 &mdash; agent-builder flaw</a></li>
<li><a href="https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html" rel="nofollow">The Hacker News, July 24, 2026 &mdash; unattended agent at a national finance ministry</a></li>
<li><a href="https://www.theregister.com/public-sector/2026/07/22/ireland-stalls-1b-microsoft-tender-amid-digital-sovereignty-questions/5276149" rel="nofollow">The Register, July 22, 2026 &mdash; Ireland stalls cloud tender over digital sovereignty</a></li>
</ul>



<h2 class="has-text-color wp-block-heading" style="color:#ffffff">AI voice disclosure</h2>



<p class="wp-block-paragraph">Laura and Arthur are AI-generated voices, produced locally on Modular&#8217;s own hardware. Story selection, reporting, and fact-checking are done by the Modular Technology Group team. Your data, your rules applies to our own production too.</p>



<details id="transcript" style="margin:20px 0;border:1px solid #E1E8ED;border-radius:10px;padding:14px 18px;">
<summary style="cursor:pointer;font-weight:700;">Full transcript</summary>
<div style="margin-top:12px;font-size:15px;line-height:1.6;">
<p><strong>Laura:</strong> Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I&#8217;m Laura.</p>
<p><strong>Arthur:</strong> And I&#8217;m Arthur. Three stories today, and one idea underneath all of them. An AI agent is an actor with authority. So today, who hands out that authority. Who is watching it. And who gets to decide where any of it runs.</p>
<p><strong>Laura:</strong> Story one. Security researchers showed that on a widely used AI platform, one crafted link was enough to build a working agent inside somebody&#8217;s account. The victim only had to be logged in and click. The agent came up from a template, attached every mailbox and file store that account had already connected, set its approval prompts to never ask, and put itself on an hourly schedule. To be fair to the vendor, they fixed it on the eighth of June, and nobody has reported it being used in the wild.</p>
<p><strong>Arthur:</strong> Picture that at the desk. Somebody in accounting clicks a link in an email, and forty minutes later there is a thing in their workspace reading the mailbox on a timer, with permission to act, and no human ever approved it. The patch closes that one door. It does not answer the question the story asks, which is how casually agent authority gets handed out in the first place. In most companies right now, anybody with a login can create an agent, wire it to real data, and nobody can name who owns it. That is the part you can fix this week. Give every agent a boundary and a person accountable for it, in a workspace your company actually owns rather than one you rent by the seat. Your data, your rules.</p>
<p><strong>Laura:</strong> Story two is what that looks like when nobody is watching. A security firm reports that an attacker ran an off-the-shelf AI agent inside a national finance ministry, using it for the messy work after a break-in, with the agent&#8217;s approval mode switched off so it would not stop to ask. Researchers found the operator&#8217;s own toolkit sitting in an exposed directory, around five hundred and eighty-five files. Worth saying plainly: one firm is the only public source, the ministry has not confirmed any of it, and their national cyber team was notified in mid July.</p>
<p><strong>Arthur:</strong> Take the caveat seriously and the lesson still stands, because the interesting detail is not the break-in. It is that the useful setting was the one that turns the human out of the loop. That setting exists on the tools your own team uses. If somebody on your staff can disable an approval gate to move faster, then the gate was decoration. Real oversight means the boundary sits outside the agent, in infrastructure you control, and it means you have an off switch that works even when the agent is mid-task. Your data, your rules, and that includes the AI working on it. Your AI, your rules.</p>
<p><strong>Laura:</strong> Story three moves the question up a level. Ireland&#8217;s government procurement office just cancelled a major cloud framework competition after concerns were raised about digital sovereignty. For scale, the framework it would have replaced is capped at three hundred and fifty million euro and runs to September of twenty twenty-seven, and an opposition deputy put the replacement somewhere between seven hundred and fifty million and one billion euro.</p>
<p><strong>Arthur:</strong> Here is why that matters to a twelve-person firm in Kentucky. A government just treated the question of where its data lives, and whose law reaches it, as a reason to stop a procurement in its tracks. That question used to be a slide in a security review. Now it moves contracts. If a national government is willing to pause and ask it, it is a fair question for you to ask about the systems running your client files. And you get better answers when the stack is yours: infrastructure you own, in a US-based FedRAMP facility, at a fixed monthly cost instead of a meter you cannot see, one stack from dirt to desktop. Your data, your rules.</p>
<p><strong>Laura:</strong> That is the thread today. A link that built an agent. An agent nobody was supervising. A government that stopped a contract to ask where its data lives. Same question at three different sizes.</p>
<p><strong>Arthur:</strong> If your team is starting to point AI agents at real systems and you are not sure who owns them or what they are allowed to touch, we would genuinely like to compare notes. No hard pitch. Head to modtechgroup dot com slash consultation and book a conversation with the Modular team. We will help you figure out where your data lives, what it really costs, and what your options are.</p>
<p><strong>Laura:</strong> Thanks for spending a few minutes with us.</p>
<p><strong>Laura:</strong> This has been The Modular Briefing.</p>
<p><strong>Arthur:</strong> Your data, your rules.</p>
<p><strong>Laura:</strong> We will see you next time.</p>
</div>
</details>
<script>
(function(){
  function openTranscript(){
    var d=document.getElementById('transcript');
    if(d&&location.hash==='#transcript'){d.open=true;d.scrollIntoView();}
  }
  window.addEventListener('hashchange',openTranscript);
  document.addEventListener('DOMContentLoaded',openTranscript);
  document.addEventListener('click',function(e){
    var a=e.target.closest&&e.target.closest('a[href="#transcript"]');
    if(a){var d=document.getElementById('transcript');if(d){d.open=true;}}
  });
})();
</script>



<p class="wp-block-paragraph">If your team is pointing AI agents at real systems and nobody can say who owns them or what they may touch, <a href="https://modtechgroup.com/consultation/?utm_source=podcast&amp;utm_medium=episode&amp;utm_campaign=ep08">book a conversation</a>.</p>



<p class="wp-block-paragraph"><strong>Your data, your rules.</strong></p>
<p>The post <a href="https://modtechgroup.com/who-gave-it-the-keys/">The Modular Briefing, Episode 8: Who Gave It the Keys?</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://assets.modtechgroup.com/podcast/audio/modular-briefing-ep08.mp3" length="4482238" type="audio/mpeg" />

			</item>
		<item>
		<title>The compliance gate paused. Your duty to your data did not.</title>
		<link>https://modtechgroup.com/compliance-gate-paused-duty-to-data/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=compliance-gate-paused-duty-to-data</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 13:05:30 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/compliance-gate-paused-duty-to-data/</guid>

					<description><![CDATA[<p>Compliance · CMMC, Private AI, Governance · ~6 min readOn July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, the third-party certification requirement that had been scheduled to start appearing in defense contracts on November 10, 2026, roughly four months out (DefenseScoop). Read the announcement closely: the suspension covers  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/compliance-gate-paused-duty-to-data/">The compliance gate paused. Your duty to your data did not.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Compliance · CMMC, Private AI, Governance · ~6 min read</em></p>
<p>On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, the third-party certification requirement that had been scheduled to start appearing in defense contracts on November 10, 2026, roughly four months out (<a href="https://defensescoop.com/2026/07/13/dod-halts-cmmc-cybersecurity-requirements-phase-2/">DefenseScoop</a>). Read the announcement closely: the suspension covers only the certification gate. DFARS 7012 still applies. The NIST 800-171 self-assessment still applies. For anyone bringing AI into the defense supply chain, that means less paperwork sitting on top of the same responsibility. Piping that data into someone else&#8217;s cloud model is still a risk you own.</p>
<p>What the suspension actually covers</p>
<p>Phase II is the part of CMMC where an outside assessor certifies you, meaning Level 2 assessments conducted by a C3PAO and the Level 3 assessments above them. That requirement is now suspended while a new CMMC Reform Task Force runs a 60-day review, and Phases 3 and 4 are frozen along with the program&#8217;s future implementation milestones. The stated reason is cost. The department wants to cut compliance expense and bureaucratic burden as part of a wider effort to streamline defense acquisition, and for a small contractor that is genuinely good news.</p>
<p>The review leaves the standing rules in place. DFARS clause 252.204-7012, which requires you to safeguard covered defense information and report cyber incidents, remains in force. So does the CMMC Phase I self-assessment: you still complete a NIST SP 800-171 self-assessment and upload your score to the DoD&#8217;s SPRS system. An inaccurate score can still create liability under the False Claims Act. The only thing removed from the calendar is the assessor&#8217;s visit. Every rule that assessor would have checked remains on the books.</p>
<p>What the pause means for how you handle CUI</p>
<p>The obligation follows the data, and it always has. Controlled unclassified information, CUI, carried the same obligations on July 14 that it carried on July 12, whether or not anyone is scheduled to check your work. Now consider where CUI actually goes when someone on your team pastes a spec or a contract excerpt into a public AI chat tool. It leaves your network and lands on infrastructure you cannot inspect, under retention terms you never negotiated. DFARS 7012 still expects you to report incidents involving that information, and you cannot report what you cannot see.</p>
<p>There is also the score you already attested. Your SPRS submission describes an environment where CUI stays inside defined controls. If CUI is quietly flowing into public tools, that submission stops being true, and the False Claims Act does not pause for a task force. The right response is simply to know where your data goes, and that is a thing you get to decide.</p>
<p>The private-AI answer for defense work</p>
<p>The same move that satisfies the standing rules also unlocks the AI you wanted in the first place: run the model inside a boundary you control. That can be your own environment, or a private one a partner builds and operates for you. When the model lives where the data lives, CUI never crosses into a system you cannot account for. This maps directly onto what survived the review. 7012 asks you to safeguard covered defense information; a boundary you control is the safeguard. The 800-171 self-assessment asks you to score your environment honestly; a contained environment is one you can score honestly and keep scoring honestly, review or no review.</p>
<p>You can move before the task force reports, and you can bring in help to do it. Modular Technology Group builds and runs private AI for contractors in exactly this position, and we own the whole stack. Your data, your rules, from dirt to desktop. Use the pause to get your AI inside your boundary, so that whatever comes back from the review, you are already standing where the rules point.</p>
<p>Your data, your rules.</p>
<p>The post <a href="https://modtechgroup.com/compliance-gate-paused-duty-to-data/">The compliance gate paused. Your duty to your data did not.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI needs a home, not a hotel</title>
		<link>https://modtechgroup.com/ai-needs-a-home-not-a-hotel/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ai-needs-a-home-not-a-hotel</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Thu, 23 Jul 2026 14:46:15 +0000</pubDate>
				<category><![CDATA[Modular]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/ai-needs-a-home-not-a-hotel/</guid>

					<description><![CDATA[<p>From the Desk of Cale · Private AI · ~4 min readMost companies did not decide to rent their AI. It happened one login at a time. A hotel is fine for a night, but you do not own the room, you cannot change the locks, and the nightly rate is whatever they say it  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/ai-needs-a-home-not-a-hotel/">AI needs a home, not a hotel</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>From the Desk of Cale · Private AI · ~4 min read</em></p>
<p>Most companies did not decide to rent their AI. It happened one login at a time. A hotel is fine for a night, but you do not own the room, you cannot change the locks, and the nightly rate is whatever they say it is. Your business AI deserves a home you own, where your data stays yours and the bill does not surprise you.</p>
<p>How renting happens by accident</p>
<p>Nobody signs a lease with the whole company in mind. Someone in marketing starts a free trial to draft campaign copy. An engineer signs up with a work email because the tool saves an hour a day. Neither asks permission, because why would they? It is a free trial. Six months later there are a dozen seats spread across four departments, nobody owns any of them, and nobody can say what has been pasted into which chat window. There is no boundary because nobody ever drew one.</p>
<p>The moment you notice is usually mundane. A renewal notice arrives at a new rate, or a client&#8217;s security questionnaire asks where their information lives and the honest answer takes a week to assemble. So you decide to consolidate, and you discover that the prompts, the saved conversations, the custom workflows, the habits your team built are all inside someone else&#8217;s building. You can walk out, but you leave the furniture. That is the tell that you have been renting all along: leaving costs more than staying, and the landlord knows it.</p>
<p>What &#8220;owning the room&#8221; actually buys you</p>
<p>Start with the question your clients are already asking you: where does our data live? When you own the room, the answer is one sentence. It lives here, inside a boundary we control, and it does not feed anyone else&#8217;s model. That answer shortens security reviews and calms auditors, and it has the advantage of being simply true. No contract exhibit required.</p>
<p>The economics change too. Renting means metered billing, per seat and per token, at a rate set by someone who knows you cannot easily leave. Owning means the cost is mostly fixed. You know what the hardware costs and what running it costs, and the bill in month eighteen looks like the bill in month three. Budgeting becomes boring, which is exactly what budgeting should be. There is a quieter benefit underneath both of those: because the models sit behind an interface you control, you can change them without changing anything else. When a better open model ships, and they ship constantly now, you swap it in over a weekend. No migration project, no new vendor negotiation. The room stays the same. Only the furniture improves.</p>
<p>What it does not require you to give up</p>
<p>The usual objection is that owning means going without. It does not. The tools your team already likes (the chat interface, the document work, the code assistance, the meeting summaries) run just as well on infrastructure you control. Good UX is a software problem, and the software exists. Your people should not notice a difference, except that the question of where the data goes finally has an answer.</p>
<p>Owning also does not mean building from scratch. You would not pour your own foundation to own a house; you would hire a builder and hold the deed. The same trade exists here. A partner can stand up the hardware, run the models, keep everything patched and current, and hand you the keys. That is the work we do at Modular: your data, your rules, from dirt to desktop. You hold the deed. We keep the lights on.</p>
<p>Your data, your rules.</p>
<p>The post <a href="https://modtechgroup.com/ai-needs-a-home-not-a-hotel/">AI needs a home, not a hotel</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
