<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Modular Technology Group</title>
	<atom:link href="https://modtechgroup.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://modtechgroup.com/</link>
	<description></description>
	<lastBuildDate>Fri, 04 Sep 2026 17:37:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>
	<item>
		<title>Google put a leash on Antigravity, and that&#8217;s the whole story</title>
		<link>https://modtechgroup.com/google-put-a-leash-on-antigravity-and-thats-the-whole-story/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-put-a-leash-on-antigravity-and-thats-the-whole-story</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 17:15:48 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/google-put-a-leash-on-antigravity-and-thats-the-whole-story/</guid>

					<description><![CDATA[<p>Google put a leash on Antigravity, and that's the whole storyGoogle spent the better part of a year telling everyone that Antigravity, its agentic coding environment, was the future of software work. Agents that plan, write, test, and ship with a human somewhere in the loop, loosely defined. Last week The Register reported that Google  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/google-put-a-leash-on-antigravity-and-thats-the-whole-story/">Google put a leash on Antigravity, and that&#8217;s the whole story</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>Google put a leash on Antigravity, and that&#8217;s the whole story</h1>
<p>Google spent the better part of a year telling everyone that Antigravity, its agentic coding environment, was the future of software work. Agents that plan, write, test, and ship with a human somewhere in the loop, loosely defined. Last week <a href="https://www.theregister.com/ai-and-ml/2026/08/21/google-tethers-antigravity-to-enterprise-controls-amid-ai-shakeup/5290730">The Register reported</a> that Google is now tethering Antigravity to its enterprise admin controls. Policy enforcement, permission scoping, audit visibility, the works.</p>
<p>Read that again. The company with more AI research muscle than almost anyone on the planet looked at its own autonomous agents running inside customer environments and decided they needed a leash.</p>
<p>That&#8217;s not a product announcement. That&#8217;s an admission.</p>
<h2>What the tether actually tells you</h2>
<p>For roughly two years the agentic AI pitch has been velocity. Let the agent touch the repo, the ticket queue, the database, the deployment pipeline. Trust the model. Move fast.</p>
<p>Enterprises, it turns out, were not buying it at scale. Security teams kept asking the same unglamorous questions. What can this agent read? What can it write? Who approved that? Where&#8217;s the log? And the honest answer, for most agentic tools shipped since 2024, was some version of &#8220;we&#8217;re working on it.&#8221;</p>
<p>So Google did what a vendor under pressure does: it built the controls its buyers were demanding and wired them into the Google admin plane. Good for Google. Genuinely good for Antigravity customers, too, in the narrow sense. An agent with scoped permissions and an audit trail beats an agent without them every single day.</p>
<p>But notice where those controls live. Inside Google&#8217;s console, expressed in Google&#8217;s policy language, enforced by Google&#8217;s infrastructure, covering Google&#8217;s agents. If you run Antigravity plus a Copilot deployment plus a homegrown agent on an open-weights model, and most mid-size shops we talk to are already in exactly that mixed state, you now have one well-governed island and a lot of open water.</p>
<h2>Governance rented from a vendor is still lock-in</h2>
<p>Here&#8217;s the part that should bother you more than the ungoverned agents did.</p>
<p>When your AI governance is a feature of one vendor&#8217;s platform, your policy layer becomes a switching cost. Every rule you write in their console, every approval workflow you build around their audit log, every compliance attestation that cites their controls, all of it deepens the moat around that one product. Leave the product and you leave your governance behind. You&#8217;d have to rebuild it from scratch inside the next vendor&#8217;s console, in their language, with their gaps.</p>
<p>That&#8217;s a strange place to park something as load-bearing as &#8220;who is allowed to let software act on our behalf, and under what conditions.&#8221;</p>
<p>Governance isn&#8217;t a feature. It&#8217;s a function. It belongs to the organization, above the tools, the way your security policy isn&#8217;t a setting inside your firewall vendor&#8217;s dashboard. The firewall enforces the policy. It doesn&#8217;t own it.</p>
<h2>What owning it looks like</h2>
<p>This is exactly the problem a fractional Chief AI Officer, or a small AI Program Office if you want the standing version, exists to solve. Not a committee that meets quarterly and produces a PDF. A working function that does specific things:</p>
<ul>
<li>Keeps an inventory of every agent and model in use, sanctioned or not. Most orgs that build this list for the first time find two or three tools nobody in leadership knew about.</li>
<li>Writes permission and data-access policy once, in plain language the business owns, then maps it onto each platform&#8217;s controls. Google&#8217;s tether becomes one enforcement point among several, instead of the whole strategy.</li>
<li>Defines what gets logged, reviewed, and escalated when an agent acts, regardless of whose agent it is.</li>
<li>Maintains an exit plan per vendor. If the policy layer is yours, swapping the tool underneath is an engineering project, not an identity crisis.</li>
</ul>
<p>None of this requires a full-time executive salary, and at most firms it shouldn&#8217;t get one. It requires a few disciplined days a month from someone who has done it before and answers to you, not to a platform&#8217;s roadmap.</p>
<p>The alternative is what we&#8217;re watching play out now: each hyperscaler ships its own governance surface, each one slightly different, and enterprises stitch together a compliance story out of four vendors&#8217; screenshots and hope the auditor doesn&#8217;t ask how the pieces relate.</p>
<h2>The principle underneath</h2>
<p>Modular&#8217;s position on data has been the same since day one. Your data, your rules. And that includes the AI working on it. Your AI, your rules. An agent that can read your files, write your code, and act in your name is not a productivity toy. It&#8217;s an actor inside your business, and the rules governing an actor inside your business should be written by you, enforceable everywhere, and portable to whatever stack you run next year.</p>
<p>Google tethering Antigravity is a milestone worth marking, because it settles the argument. Ungoverned agentic AI is untenable, and now even the people selling the agents say so out loud. The open question is only who holds the tether. The vendor, or you.</p>
<p>We think the answer is obvious, and we think it&#8217;s a solvable, medium-sized project rather than a moonshot. Most of the firms we work with get a real inventory, a written policy, and enforcement mapping in place within a quarter.</p>
<p>So here&#8217;s what I&#8217;m curious about. If an auditor walked in tomorrow and asked you to list every AI agent with write access to something that matters in your business, how long would that list take to produce, and who in your org would have to produce it? Tell me honestly. The answers I&#8217;ve heard so far range from &#8220;ten minutes&#8221; to &#8220;we&#8217;d have to send an all-staff email,&#8221; and the gap between those two companies is the entire story.</p>
<p>The post <a href="https://modtechgroup.com/google-put-a-leash-on-antigravity-and-thats-the-whole-story/">Google put a leash on Antigravity, and that&#8217;s the whole story</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Modular Briefing, September 3, 2026: What Governance Actually Asks For</title>
		<link>https://modtechgroup.com/what-governance-actually-asks-for/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-governance-actually-asks-for</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 13:00:00 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Podcast]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/?p=6055</guid>

					<description><![CDATA[<p>No news this week. One argument instead. AI governance, for a business your size, is four things: an owner, a boundary, a log, and evidence. Arthur and Laura make the case from the ground up, explain why all four scale down to a thirty-person firm, and why the fourth one is the one that binds. Your data, your rules.</p>
<p>The post <a href="https://modtechgroup.com/what-governance-actually-asks-for/">The Modular Briefing, September 3, 2026: What Governance Actually Asks For</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure class="wp-block-audio"><audio controls src="https://assets.modtechgroup.com/podcast/audio/modular-briefing-vault.mp3"></audio><figcaption>The Modular Briefing, September 3, 2026 &middot; 5:19</figcaption></figure>
<p>No news this week. One argument instead, built from the ground up, because it is the place our reporting keeps landing and it has earned a hearing on its own. AI governance, for a business your size, is four things. An owner. A boundary. A log. And evidence. That is the entire list.</p>
<h2>In this episode</h2>
<ul>
<li><strong>Who owns this?</strong> Not who bought it, and not who is good with computers: who is accountable when it goes wrong. Software with no owner does not sit still, it spreads. The fix costs nothing. One name next to one tool, and it can be a name already on your organization chart.</li>
<li><strong>Where does it end?</strong> A boundary is not a fence around the tool. It is a sentence about your material: what this is allowed to touch, and what it is not. Two lines is a real boundary. Then the harder half: where does your material go while the tool is looking at it? If it has to stay inside your walls, the tool has to run inside your walls.</li>
<li><strong>What happened?</strong> The log, and the one design choice that decides whether it is worth keeping: give the software its own identity. If your AI runs on an employee&#8217;s credentials, then in your own logs the software and the employee are one actor, and you cannot answer the only question anybody asks afterward.</li>
<li><strong>Can you show it?</strong> Not describe it. Show it. The name of the owner, the sentence about the boundary, a month of the log. Evidence is cheap to keep and impossible to build backwards. Nobody has ever manufactured last quarter.</li>
</ul>
<h2>The question we asked</h2>
<p>Pick any AI tool in your business and answer question one out loud. Who owns this? If a name comes easily, you are further along than you think. If it does not, you have just found this month&#8217;s work. <a href="https://modtechgroup.com/newsletter/?utm_source=podcast&amp;utm_medium=shownotes&amp;utm_campaign=briefing-2026-09-03">Get the Modular Briefing by email</a> and reply to it, or write to Arthur at arthur@modtechgroup.com. A person reads every reply.</p>
<h2>A note on this edition</h2>
<p>This edition cites no news and no outside sources, on purpose. It is the argument the news editions keep arriving at from different directions, made directly. Nothing in it goes stale.</p>
<h2>A note on the voices</h2>
<p>Laura and Arthur are AI-generated voices, produced locally on Modular&#8217;s own infrastructure. The editorial judgement and script are the work of the Modular team.</p>
<h2>Transcript</h2>
<details>
<summary>Read the full transcript</summary>
<p><strong>Arthur:</strong> Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I&#8217;m Arthur.</p>
<p><strong>Laura:</strong> And I&#8217;m Laura. No news today. One argument instead, built from the ground up, because it is the place our reporting keeps landing and we think it has earned a hearing on its own. Here it is, and then we will spend five minutes making the case. AI governance, for a business your size, is four things. An owner. A boundary. A log. And evidence. That is the entire list.</p>
<p><strong>Laura:</strong> Start with the word, because the word is doing real damage. Say governance in a room of thirty people and everybody pictures the same furniture. A committee. A binder. A consultant with a slide deck. Something a bank has and you do not. So the sentence that comes next is almost always the same one. We are too small for that. And it is true about the binder. It is false about the thing the binder was supposed to hold, which is four answers to four questions. Question one is who owns this.</p>
<p><strong>Arthur:</strong> Not who bought it. Not who is good with computers. Who is accountable when it goes wrong. And that one matters more than the other three put together, because software with no owner does not sit still. It spreads. Somebody finds it useful, tells two colleagues, and within a quarter it is touching material nobody ever decided it should touch. No one chose that. It happened, the way things happen when it is nobody&#8217;s job to notice. Now look at what the fix costs. Nothing. You are writing one name next to one tool, and it can be a name already on your organization chart. Their workload does not change. What changes is that the question has somewhere to go. When somebody wonders out loud whether client material belongs in this thing, there is a person whose job it is to have an answer, instead of a shrug that goes around the room and comes back.</p>
<p><strong>Laura:</strong> Question two. Where does it end. That is the boundary, and it is the one small organizations skip, because a boundary sounds like a restriction and a restriction sounds like the opposite of why you bought the thing. But a boundary is not a fence around the tool. It is a sentence about your material. What is this allowed to touch, and what is it not.</p>
<p><strong>Arthur:</strong> And you already have one, which is the part worth sitting with. Every business we work with already knows which of its files would be a very bad day. The client file. The medical file. The payroll file. The deal that is not signed yet. Nobody had to be taught that, and nobody wrote it down either, which is exactly the problem, because an unwritten boundary cannot be handed to a new hire, and it cannot be handed to software at all. So write the sentence. Two lines is a real boundary. This tool may see our public material and our internal drafts. It may not see client files, personnel files, or anything covered by an agreement we signed. Then the harder half. Where does your material go while the tool is looking at it. Because a boundary you enforce by asking people to be careful is not a boundary. It is a hope. If the material has to stay inside your walls, the tool has to run inside your walls. Your data, your rules. And that includes the AI working on it. Your AI, your rules.</p>
<p><strong>Laura:</strong> Question three. What happened. That is the log, and let us be clear about what we mean, because the word makes people picture a compliance product with a dashboard and a monthly fee. We do not mean that. We mean the ordinary answer to an ordinary question. Which tool, doing what, on whose behalf, and when.</p>
<p><strong>Arthur:</strong> There is one design choice underneath that, and it decides whether the log is worth keeping. Give the software its own name. Its own login, its own identity, in a class of its own, not borrowed from a person. Because if your AI runs on an employee&#8217;s credentials, then in your own logs the software and the employee are one actor, and later, when it matters, you cannot answer the only question anybody asks. Which of you did that. Give the tool its own name and the answer writes itself, and that is an afternoon of work. Which brings us to question four, the one that turns three good habits into something you can stand behind. Evidence. Can you show it. Not describe it. Show it. The name of the owner. The sentence about the boundary. A month of the log. And here is the asymmetry nobody warns you about in advance. Evidence is cheap to keep and impossible to build backwards. Nobody has ever manufactured last quarter.</p>
<p><strong>Laura:</strong> So that is the argument. An owner, a boundary, a log, and evidence. Notice what is not on the list. Which model you picked. What you spend. Whether you hired anybody. And notice that all four scale down, which is the part that keeps getting missed. A thirty person firm can answer all four inside a week. What a large enterprise has is not better governance. It is the same four answers with more people maintaining them.</p>
<p><strong>Arthur:</strong> Which is why we do not think most businesses need an AI department. They need somebody whose job it is. One person, some of the time, who owns the four answers and keeps them current. That is the whole idea behind a fractional chief AI officer, and it is not a clever product. It is an honest reading of what four questions cost. So here is our question for you. Pick any AI tool in your business and answer question one out loud. Who owns this. If a name comes easily, you are further along than you think. If it does not, you have just found this month&#8217;s work. Write to me at arthur at modtechgroup dot com and tell me which of the four is hardest where you are. A person reads every reply.</p>
<p><strong>Laura:</strong> Thanks for spending a few minutes with us.</p>
<p><strong>Arthur &amp; Laura:</strong> This has been The Modular Briefing. Your data, your rules. We will see you next time.</p>
</details>
<p><em>Your data, your rules.</em></p>
<p>The post <a href="https://modtechgroup.com/what-governance-actually-asks-for/">The Modular Briefing, September 3, 2026: What Governance Actually Asks For</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://assets.modtechgroup.com/podcast/audio/modular-briefing-vault.mp3" length="7677536" type="audio/mpeg" />

			</item>
		<item>
		<title>When the financing comes with a data clause</title>
		<link>https://modtechgroup.com/when-the-financing-comes-with-a-data-clause/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=when-the-financing-comes-with-a-data-clause</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 13:30:51 +0000</pubDate>
				<category><![CDATA[Data Sovereignty & Privacy]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/when-the-financing-comes-with-a-data-clause/</guid>

					<description><![CDATA[<p>When the financing comes with a data clauseSpirit Airlines needed money. Google, according to the flight attendants' union, wanted something more interesting than interest payments.Fortune reported last week that the Association of Flight Attendants is accusing Google of structuring a deal around Spirit's restructuring that would hand the tech giant access to confidential airline data  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/when-the-financing-comes-with-a-data-clause/">When the financing comes with a data clause</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>When the financing comes with a data clause</h1>
<p>Spirit Airlines needed money. Google, according to the flight attendants&#8217; union, wanted something more interesting than interest payments.</p>
<p>Fortune <a href="https://fortune.com/2026/08/21/flight-attendant-union-google-confidential-data-spirit-airlines/">reported last week</a> that the Association of Flight Attendants is accusing Google of structuring a deal around Spirit&#8217;s restructuring that would hand the tech giant access to confidential airline data for AI purposes. The union&#8217;s language was blunt. &#8220;Adding insult to injury&#8221; is how they framed it: their employer is in financial distress, their jobs are uncertain, and now the data generated by their work might get folded into someone else&#8217;s model training as a side effect of a transaction they had no seat at.</p>
<p>Set aside for a moment whether the union&#8217;s characterization holds up in every detail. The shape of the deal is the story. And the shape is one we&#8217;re going to see again and again.</p>
<h2>Data as the sweetener</h2>
<p>When a company is healthy, its data sits behind contracts, policies, and a general reluctance to give anything away. When a company is desperate, all of that becomes negotiable. Data turns into an asset on the table, right next to the gates and the aircraft leases. A lender or strategic partner who wants training data doesn&#8217;t have to buy it on the open market. They can attach it to financing that the company can&#8217;t afford to refuse.</p>
<p>Notice who&#8217;s missing from that negotiation. The flight attendants whose schedules, communications, performance records, and operational patterns make up a real chunk of that &#8220;confidential data&#8221; were not in the room. They didn&#8217;t sign up for it when they took the job. There was no consent moment. Their information became a bargaining chip because it happened to be sitting in systems their employer controlled and their employer needed cash.</p>
<p>That&#8217;s the part that should make every executive uncomfortable, and not only on behalf of the workers. Flip the seats. Your company&#8217;s data is sitting in a vendor&#8217;s cloud right now. That vendor has its own investors, its own pressures, its own potential acquirers. If your vendor hits a rough patch, or gets bought, or signs a strategic partnership with an AI lab, what stops your data from becoming their sweetener?</p>
<p>Read your agreements. In most cases the honest answer is: less than you think. Terms of service change. &#8220;Improving our services&#8221; clauses stretch. Acquisitions transfer data along with everything else, and the successor company&#8217;s appetite may not match the original vendor&#8217;s promises.</p>
<h2>Consent doesn&#8217;t survive the deal</h2>
<p>Here&#8217;s the mechanism worth naming plainly. Consent, in most data arrangements, is a snapshot. An employee consents to an HR system. A company consents to a cloud provider&#8217;s terms. Then the world moves. The provider changes hands, the terms get amended, a financing deal introduces a new party with new incentives. The original consent never contemplated any of it, but the data doesn&#8217;t get re-asked. It just flows to wherever the paperwork now permits.</p>
<p>The Spirit situation makes this vivid because a bankruptcy court and a union give it visibility. Most versions of this story never get a headline. The data quietly gains a new downstream use, a new processor, a new training pipeline, and nobody with standing to object ever finds out.</p>
<p>For firms handling client files, patient records, case materials, or workforce data, this should reframe the vendor question entirely. The question is not &#8220;do I trust this vendor today.&#8221; It&#8217;s &#8220;do I trust every future owner, creditor, and strategic partner of this vendor, under financial conditions I can&#8217;t predict.&#8221; Nobody can answer yes to that honestly.</p>
<h2>The only clean answer is architectural</h2>
<p>You can&#8217;t contract your way out of this. You can architect your way out of it.</p>
<p>If the AI workload runs inside infrastructure you control, on hardware in a known jurisdiction, with models you selected and can swap, there&#8217;s nothing for a third party to acquire access to. There&#8217;s no pool of your data sitting in someone else&#8217;s cloud waiting to become deal collateral. A vendor&#8217;s bankruptcy, acquisition, or creative new financing arrangement can&#8217;t repurpose data it never touched.</p>
<p>That&#8217;s the entire premise behind private AI workspaces as we build them at Modular. Client data and workforce data stay inside the client&#8217;s environment. Models run locally. Nothing feeds a third-party training pipeline, not because a policy says so, but because there&#8217;s no pipe. We own the stack from the physical facility to the interface the user touches, which means there&#8217;s no intermediate layer where someone else&#8217;s business model can intervene. Your data, your rules, from dirt to desktop.</p>
<p>And because the pricing is fixed, there&#8217;s no meter running that tempts anyone, us included, to find secondary value in what flows through the system. The economics are aligned with the architecture. You pay for capability, not for the privilege of becoming training data.</p>
<p>The flight attendants understood something instinctively that a lot of boardrooms still haven&#8217;t internalized: once your data is in someone else&#8217;s hands, your interests and theirs will eventually diverge, and when they do, the paperwork will favor whoever holds the servers.</p>
<h2>The closing thought</h2>
<p>I keep coming back to the phrase &#8220;adding insult to injury.&#8221; The injury was the financial distress. The insult was discovering that your working life had a resale value you never agreed to. Spirit&#8217;s flight attendants at least have a union loud enough to get this into Fortune. Most employees, and most companies whose data is riding in third-party clouds, will never get the courtesy of a headline.</p>
<p>The uncomfortable exercise for this week: pull up your top three data-holding vendors and try to answer, from the actual contract language, what happens to your data if they&#8217;re acquired or restructured. If you&#8217;ve done that exercise, or if you think I&#8217;m overreading the Spirit deal, tell me what you found. I&#8217;d genuinely like to compare notes.</p>
<p>The post <a href="https://modtechgroup.com/when-the-financing-comes-with-a-data-clause/">When the financing comes with a data clause</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When the partners aren&#8217;t getting paid, look harder at the product</title>
		<link>https://modtechgroup.com/when-the-partners-arent-getting-paid-look-harder-at-the-prod/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=when-the-partners-arent-getting-paid-look-harder-at-the-prod</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 13:30:51 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/when-the-partners-arent-getting-paid-look-harder-at-the-prod/</guid>

					<description><![CDATA[<p>When the partners aren't getting paid, look harder at the productThe Register ran a piece this week that should get more attention than it will: Salesforce partners are reportedly not seeing meaningful revenue from Agentforce. Not customers grumbling. Partners. The consultancies and integrators who staffed up practices, sat through the certifications, and built their 2026  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/when-the-partners-arent-getting-paid-look-harder-at-the-prod/">When the partners aren&#8217;t getting paid, look harder at the product</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>When the partners aren&#8217;t getting paid, look harder at the product</h1>
<p>The Register ran a piece this week that should get more attention than it will: <a href="https://www.theregister.com/saas/2026/08/21/salesforce-partners-not-seeing-meaningful-revenue-from-agentforce-ai-platform-report-says/5291167">Salesforce partners are reportedly not seeing meaningful revenue from Agentforce</a>. Not customers grumbling. Partners. The consultancies and integrators who staffed up practices, sat through the certifications, and built their 2026 pipeline around Marc Benioff&#8217;s favorite word.</p>
<p>That detail matters more than another &#8220;AI pilot stalls&#8221; headline would. Partners are the canary in any enterprise software ecosystem. They only make money when customers actually deploy, expand, and renew. When a vendor&#8217;s sales numbers look fine but the partner channel is starving, it usually means the product is being sold but not used. Licenses in a drawer. Pilots that never graduate.</p>
<p>I&#8217;ve been saying for a while that agents bolted onto a SaaS platform were going to hit this wall, and I want to walk through why, because the reasoning matters more than the schadenfreude.</p>
<h2>The bolt-on problem, specifically</h2>
<p>An agent is only as useful as what it&#8217;s allowed to touch and what it&#8217;s trusted to do. Agentforce, by design, lives inside Salesforce. That&#8217;s great if your entire operational reality lives inside Salesforce. Almost nobody&#8217;s does. The customer record is in the CRM, sure, but the contract is in a document system, the invoice history is in the ERP, the actual conversation with the client is in email, and the tribal knowledge is in somebody&#8217;s head or a shared drive from 2019.</p>
<p>So the &#8220;agent&#8221; either stays narrow enough to be safe and ends up doing work a workflow rule could have done in 2015, or it reaches outward through connectors and suddenly you&#8217;re paying platform prices for integration work while your governance story gets murkier with every hop. Neither version produces the outcome the demo promised. Partners can&#8217;t bill against outcomes that don&#8217;t materialize.</p>
<p>Then there&#8217;s pricing. Agentforce launched with per-conversation pricing, and consumption models like that put the customer in a strange position: the more successful the agent is, the bigger the bill, and the bill is set by the same vendor that controls the platform, the model access, and the switching costs. CFOs noticed. Variable AI bills tied to usage you can&#8217;t fully predict are exactly the kind of thing that keeps a pilot a pilot forever. Nobody signs off on production when they can&#8217;t forecast the line item.</p>
<h2>What actually gets agents into production</h2>
<p>Here&#8217;s what we&#8217;ve learned building AgentWorks deployments, and it&#8217;s almost boringly unglamorous.</p>
<p>First, the job comes before the agent. You don&#8217;t buy an agent platform and then hunt for use cases. You pick one process with a measurable cost, in hours or dollars or errors, and you build the agent to do that process. Scope is a feature. An agent that does one thing inside hard boundaries ships. An agent that &#8220;can do anything across your org&#8221; gets stuck in security review, and it should.</p>
<p>Second, governance is designed in, not reviewed in. Every AgentWorks agent runs against defined permissions, logged actions, and a human checkpoint wherever the blast radius justifies one. When compliance asks &#8220;what can this thing actually do, and who approved it,&#8221; the answer is a document, not a shrug. Your data, your rules. And that has to include the AI working on that data. Your AI, your rules, which means you decide what the agent reads, what it writes, which model it runs on, and where all of it lives. On a platform vendor&#8217;s agent, most of those decisions were made for you before you ever logged in.</p>
<p>Third, the economics have to be legible. We do fixed pricing on this work because a client cannot govern what they cannot forecast. If the marginal cost of the agent doing its job is a surprise, the agent will be throttled by the finance department long before it&#8217;s throttled by any technical limit.</p>
<p>And fourth, model agnosticism. The right model for a contract-summarization agent and the right model for a triage agent are often different, and both will be different again in eight months. An agent architecture that lets you swap the model without rebuilding the system is worth more than any single model choice you make today. Platform agents lock that decision to the platform&#8217;s roadmap.</p>
<h2>The honest read on the Register story</h2>
<p>None of this means Salesforce built something worthless, and this isn&#8217;t a pile-on. It means the &#8220;add agents to the platform you already pay for&#8221; pitch has a structural flaw: the platform&#8217;s interests and the customer&#8217;s interests diverge exactly at the points that determine whether an agent earns its keep. Scope, data reach, pricing, and model choice. The partners caught in the middle are just the first ones to feel it, because they&#8217;re the only party in the ecosystem paid strictly on real adoption.</p>
<p>The agent era is going to be won by narrow, governed, accountable deployments that a specific team relies on every day. We use ours daily, which is how we know which parts of the pitch survive contact with an actual Tuesday.</p>
<p>If you&#8217;ve run an agent pilot this year, on Agentforce or anything else, I&#8217;m genuinely curious: what killed it or what saved it? Was it governance, cost, scope creep, or something nobody warned you about? Tell me. The failure stories are teaching us more than the keynotes are.</p>
<p>The post <a href="https://modtechgroup.com/when-the-partners-arent-getting-paid-look-harder-at-the-prod/">When the partners aren&#8217;t getting paid, look harder at the product</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Shady AI is what an empty chair looks like from the outside</title>
		<link>https://modtechgroup.com/shady-ai-is-what-an-empty-chair-looks-like-from-the-outside/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=shady-ai-is-what-an-empty-chair-looks-like-from-the-outside</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 13:30:51 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/shady-ai-is-what-an-empty-chair-looks-like-from-the-outside/</guid>

					<description><![CDATA[<p>Shady AI is what an empty chair looks like from the outsideThe Hacker News ran a piece this week on "shady AI", their sharper name for shadow AI, and called it security's next big governance problem. They're right about the diagnosis. I want to push on the cause, because I think most companies are misreading  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/shady-ai-is-what-an-empty-chair-looks-like-from-the-outside/">Shady AI is what an empty chair looks like from the outside</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>Shady AI is what an empty chair looks like from the outside</h1>
<p>The Hacker News ran a piece this week on <a href="https://thehackernews.com/2026/08/why-shady-ai-is-securitys-next-big.html">&#8220;shady AI&#8221;</a>, their sharper name for shadow AI, and called it security&#8217;s next big governance problem. They&#8217;re right about the diagnosis. I want to push on the cause, because I think most companies are misreading it.</p>
<p>The standard story goes like this: employees discovered that free AI tools make their jobs easier, IT hasn&#8217;t sanctioned any of them, so people quietly paste client contracts, patient notes, and source code into whatever chatbot loads fastest. Security finds out months later, usually by accident. Cue the panic memo and the blanket ban.</p>
<p>That story treats shadow AI as a discipline problem. It isn&#8217;t a discipline problem. It&#8217;s a vacancy.</p>
<h2>Nobody owns the question</h2>
<p>Walk into a mid-sized firm and ask a simple question: who decides which AI tools are allowed here? Watch what happens. IT says they handle security review but not AI strategy. Legal says they&#8217;ll weigh in on contracts when asked. The COO says it&#8217;s on the roadmap. Meanwhile a paralegal has a browser extension summarizing privileged email, a sales rep wired a free agent into the CRM with a personal API key, and an analyst is running quarterly numbers through a consumer chatbot that trains on inputs by default.</p>
<p>None of those people are being reckless in their own minds. They&#8217;re being productive. The tool worked, nobody said no, and more to the point, nobody was there to say no. Or yes. The chair where that decision should get made is empty at most organizations, and shadow AI is simply what fills a vacuum.</p>
<p>Bans don&#8217;t fix vacuums. A ban is a &#8220;no&#8221; issued by someone who wasn&#8217;t in the room when the work needed doing, and employees treat it accordingly. The Hacker News piece touches on this: prohibition pushes usage underground, off the corporate network, onto personal devices, where security has zero visibility instead of partial visibility. You traded a manageable problem for an invisible one and called it policy.</p>
<h2>What actually fills the chair</h2>
<p>This is the exact gap the fractional Chief AI Officer exists to close. Not a consultant who writes a 40-page acceptable-use policy and leaves. Someone who sits in the seat, part-time but genuinely accountable, and does four unglamorous things.</p>
<p>First, inventory. You can&#8217;t govern what you can&#8217;t see. Before any policy discussion, find out what&#8217;s actually in use: the browser extensions, the personal subscriptions, the API keys nobody logged. Most firms are shocked by this list. The shock is useful. It converts an abstract worry into a spreadsheet with names on it.</p>
<p>Second, sanctioned alternatives. Here&#8217;s the part the ban-first crowd skips. People adopted these tools because the tools work. If you take away the free chatbot without replacing the capability, they&#8217;ll find another free chatbot. The answer is a private AI workspace they can actually use, running on infrastructure you control, where the drafting and the summarizing and the analysis happen without the data ever leaving your jurisdiction. At Modular that&#8217;s not theoretical. Our own teams run daily on the same private stack we deploy for clients, hosted on US soil, at a fixed monthly price, so the finance conversation is as boring as the compliance conversation. Boring is the goal.</p>
<p>Third, a real AI Program Office. Small, standing, cross-functional. It reviews new tool requests in days instead of quarters, keeps the approved list current, and gives employees a place to ask &#8220;can I use this?&#8221; and get an answer before they&#8217;ve already used it. Speed matters more than people admit. An approval process that takes six weeks is a prohibition wearing a lanyard.</p>
<p>Fourth, policy that says yes with conditions. &#8220;AI is banned&#8221; and &#8220;AI is fine, go nuts&#8221; are equally lazy. The workable version reads more like: this class of data can go into these tools, this class cannot, here&#8217;s the sanctioned path for the gray areas, and here&#8217;s who to ask when you&#8217;re not sure. Employees follow rules they can actually follow.</p>
<h2>The sovereignty thread underneath</h2>
<p>There&#8217;s a reason this maps so cleanly onto how we think about infrastructure. Your data, your rules. That&#8217;s been the thesis all along, and shadow AI is what it looks like when the rules never got written. Every unsanctioned tool is a small, silent transfer of control: your client&#8217;s contract now lives in someone else&#8217;s training pipeline, under someone else&#8217;s terms of service, in someone else&#8217;s jurisdiction. And that includes the AI working on the data, not just the data itself. Your AI, your rules. Governance without agency over the models and the tooling is just paperwork about someone else&#8217;s decisions.</p>
<p>The firms that get ahead of this won&#8217;t be the ones with the strictest bans or the longest policies. They&#8217;ll be the ones where somebody actually owns the question, where the sanctioned path is easier than the shadow path, and where &#8220;which AI touched this data&#8221; has an answer you could give a regulator without sweating.</p>
<p>The empty chair is the whole problem. Filling it doesn&#8217;t require a full-time executive salary. It requires deciding that the question deserves an owner.</p>
<p>Here&#8217;s what I&#8217;d genuinely like to know from the people reading this: when you last found an unsanctioned AI tool inside your organization, how did you find it? An audit, an incident, or dumb luck? The answers to that question tell you more about your governance posture than any policy document will.</p>
<p>The post <a href="https://modtechgroup.com/shady-ai-is-what-an-empty-chair-looks-like-from-the-outside/">Shady AI is what an empty chair looks like from the outside</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>DBS gave 1,500 employees AI agents. The interesting part is what had to exist first</title>
		<link>https://modtechgroup.com/dbs-gave-1-500-employees-ai-agents-the-interesting-part-is-w/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dbs-gave-1-500-employees-ai-agents-the-interesting-part-is-w</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Sun, 23 Aug 2026 14:00:48 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/dbs-gave-1-500-employees-ai-agents-the-interesting-part-is-w/</guid>

					<description><![CDATA[<p>Singapore's DBS is rolling out specialist AI agents to 1,500 employees, per Finextra's report from August 21. Not a chatbot in the corner of the intranet. Agents. Software that takes an objective, works through steps, touches systems, and hands back a result. The headline number is 1,500 people. That's not the story. The story is  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/dbs-gave-1-500-employees-ai-agents-the-interesting-part-is-w/">DBS gave 1,500 employees AI agents. The interesting part is what had to exist first</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="fusion-fullwidth fullwidth-box fusion-builder-row-1 fusion-flex-container nonhundred-percent-fullwidth non-hundred-percent-height-scrolling" style="--awb-border-radius-top-left:0px;--awb-border-radius-top-right:0px;--awb-border-radius-bottom-right:0px;--awb-border-radius-bottom-left:0px;--awb-flex-wrap:wrap;" ><div class="fusion-builder-row fusion-row fusion-flex-align-items-flex-start fusion-flex-content-wrap" style="max-width:1310.4px;margin-left: calc(-4% / 2 );margin-right: calc(-4% / 2 );"><div class="fusion-layout-column fusion_builder_column fusion-builder-column-0 fusion_builder_column_1_1 1_1 fusion-flex-column" style="--awb-bg-size:cover;--awb-width-large:100%;--awb-margin-top-large:0px;--awb-spacing-right-large:1.92%;--awb-margin-bottom-large:0px;--awb-spacing-left-large:1.92%;--awb-width-medium:100%;--awb-spacing-right-medium:1.92%;--awb-spacing-left-medium:1.92%;--awb-width-small:100%;--awb-spacing-right-small:1.92%;--awb-spacing-left-small:1.92%;"><div class="fusion-column-wrapper fusion-flex-justify-content-flex-start fusion-content-layout-column"><div class="fusion-text fusion-text-1"><p>Singapore&#8217;s DBS is rolling out specialist AI agents to 1,500 employees, per <a href="https://www.finextra.com/newsarticle/48281/singapores-dbs-deploys-specialist-ai-agents-for-1500-employees?utm_medium=rssfinextra&amp;utm_source=finextrafeed">Finextra&#8217;s report from August 21</a>. Not a chatbot in the corner of the intranet. Agents. Software that takes an objective, works through steps, touches systems, and hands back a result.</p>
<p>The headline number is 1,500 people. That&#8217;s not the story. The story is that a bank did this. A bank regulated by the Monetary Authority of Singapore, one of the strictest financial supervisors on the planet, decided it was comfortable letting autonomous software act on behalf of its staff at scale.</p>
<p>Banks do not get comfortable by accident. Somewhere behind that announcement is a mountain of unglamorous work: permission scoping, data boundaries, audit trails, escalation paths, and a clear answer to the question &#8220;who is accountable when the agent gets it wrong?&#8221; DBS has been building its internal AI machinery for the better part of a decade. The agents are the visible tip. The governance is the iceberg.</p>
<h2>Specialist beats general, and that&#8217;s a governance choice</h2>
<p>Notice the word Finextra used: specialist. Not one giant do-everything assistant. Narrow agents with defined jobs.</p>
<p>That&#8217;s not a product limitation. It&#8217;s a control decision, and it&#8217;s the right one. A specialist agent has a scope you can write down. You can enumerate the systems it touches, the data it reads, the actions it&#8217;s allowed to take, and the point at which it must stop and ask a human. You can log every step against that scope and review the logs. Try doing any of that with a general agent that has broad access &#8220;to be helpful.&#8221; You can&#8217;t, and neither can your compliance team, and neither can your regulator.</p>
<p>The specialist model is how you make agents auditable. DBS understood that. Most firms rushing into agent pilots right now do not.</p>
<h2>How the pilot usually goes at everyone else</h2>
<p>Here&#8217;s the pattern we keep seeing in mid-market firms, especially regulated ones. Somebody in operations wires up an agent using a SaaS platform&#8217;s shiny new agent builder. It works. It&#8217;s genuinely useful. Word spreads. Three months later there are eleven agents nobody centrally tracks, four of them have credentials to systems holding client data, and one of them has been quietly emailing summaries of internal documents through a third-party API in another jurisdiction.</p>
<p>Then someone asks the questions that should have come first. What data can these agents see? Where do their logs live? Who approved their permissions? Can we prove to an examiner what any of them did on a given Tuesday in March?</p>
<p>Bolting oversight onto that mess after the fact is miserable work. You&#8217;re reverse-engineering scope from behavior, revoking access people now depend on, and rebuilding trust with a compliance team that just found out about the whole thing. Baked in beats bolted on every single time, and the cost difference is not close.</p>
<h2>What baked-in actually looks like</h2>
<p>This is the design philosophy behind AgentWorks, Modular&#8217;s agent framework for regulated firms, and honestly it&#8217;s less about clever AI and more about boring, deliberate plumbing.</p>
<p>Every agent gets a written charter before it runs: job, systems, data classes, action limits. If it&#8217;s not in the charter, the agent can&#8217;t do it. Permissions are scoped and enforced at the infrastructure layer, not politely requested in a prompt, so an agent that shouldn&#8217;t see client PII physically cannot query it. Every action lands in an immutable log tied to the agent, the task, and the human who owns that agent. When an examiner asks what happened, you pull the record instead of pulling an all-nighter.</p>
<p>High-consequence actions route through human approval gates. The agent drafts, a person authorizes. Low-stakes steps run autonomously, and anything with real consequences waits for a human signature. And the whole thing runs on infrastructure the client controls, on US soil, at a fixed price. No metered surprise when an agent gets busy, and no wondering which country your audit trail lives in.</p>
<p>And because Modular is model-agnostic, the agent that fits the job gets the model that fits the job. Swap it later if something better ships. The governance layer doesn&#8217;t care which model is underneath, which is exactly how it should be.</p>
<p>Your data, your rules. And that includes the AI working on it: your AI, your rules. An agent is just software acting with your authority, so the rules that govern your data have to govern the agent too. Same jurisdiction, same access controls, same audit standard. If your agent platform can&#8217;t inherit those rules, you don&#8217;t have a governance problem waiting to happen. You already have one. You just haven&#8217;t logged it yet, because nothing is logging it.</p>
<h2>DBS earned this. You can too, faster</h2>
<p>DBS spent years and a small army of engineers building the machinery that makes 1,500 agents defensible. A 200-person wealth manager or a regional insurer doesn&#8217;t have that army and doesn&#8217;t need it. The pattern is now known. Specialist agents, written charters, enforced scopes, human gates, logs you&#8217;d be happy to show a regulator. That&#8217;s a buildable package, and it&#8217;s a lot cheaper to build it before your first agent ships than after your eleventh.</p>
<p>The firms that get this right in the next eighteen months won&#8217;t be the ones with the most agents. They&#8217;ll be the ones who can answer, in one meeting, exactly what every agent they run is allowed to do and prove it did only that.</p>
<p>Here&#8217;s my honest question for anyone at a regulated firm reading this: if your regulator asked tomorrow for a list of every AI agent operating in your environment and what each one can touch, how long would that list take to produce? An hour, or a very uncomfortable silence? Tell me where you&#8217;d land. I suspect the answers are worse than most leadership teams think, and I&#8217;d genuinely like to be wrong.</p>
</div></div></div></div></div>
<p>The post <a href="https://modtechgroup.com/dbs-gave-1-500-employees-ai-agents-the-interesting-part-is-w/">DBS gave 1,500 employees AI agents. The interesting part is what had to exist first</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Modular Briefing, August 22, 2026: Show Your Work</title>
		<link>https://modtechgroup.com/show-your-work/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=show-your-work</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Sat, 22 Aug 2026 22:34:03 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Podcast]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/show-your-work/</guid>

					<description><![CDATA[<p>A bar association wants consent before the software listens. A securities examiner wants the committee minutes. A cyber agency wants an owner and a log. Three authorities, two continents, ten days, and none of them asked for a demo.</p>
<p>The post <a href="https://modtechgroup.com/show-your-work/">The Modular Briefing, August 22, 2026: Show Your Work</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure class="wp-block-audio"><audio controls src="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-08-22.mp3"></audio><figcaption>The Modular Briefing, August 22, 2026 &middot; 5:31</figcaption></figure>
<p>Three different authorities, in two different countries, inside ten days. A bar association, a securities examiner and a national cyber agency. Not one of them asked whether anybody&#8217;s AI was any good. All three asked the harder question: can you show your work?</p>
<h2>In this episode</h2>
<ul>
<li><strong>The default setting is the policy.</strong> The New York City Bar Association released Formal Opinion 2026-2 on August 17 (the opinion itself is dated August 5), extending two earlier opinions from clients to co-counsel, opposing counsel, witnesses, prospective clients and a firm&#8217;s own investigators. Get consent from every participant before an AI captures a conversation, and absent a good reason, the default should be to leave it switched off. The duty of competence now includes knowing how to turn the thing off. A New York City opinion rather than a national rule, but the reasoning travels. <a href="https://www.nycbar.org/reports/formal-opinion-2026-2-ethical-use-of-ai-for-recording-transcribing-and-summarizing-non-client-conversations/" rel="nofollow noopener" target="_blank">Formal Opinion 2026-2</a></li>
<li><strong>What examiners want is the minutes.</strong> Financial Advisor Magazine, working from an examination request document obtained by Citywire, reports what SEC examiners are asking investment advisers about AI: does the firm have an AI committee, does it keep written minutes, which channels promote the firm&#8217;s AI (the &#8220;AI washing&#8221; probe, with two 2024 cases settled for a combined $400,000), and were employees ever trained on the policy. No rule requires a document titled &#8220;AI policy&#8221;; advertising, compliance, privacy, recordkeeping and fiduciary rules already do the work. The ask is evidence, not a binder. <a href="https://www.fa-mag.com/news/sec-is-asking-rias-to-show-their-ai-work--here-s-what-examiners-want-88149.html" rel="nofollow noopener" target="_blank">Financial Advisor Magazine</a></li>
<li><strong>Agent governance, written down at last, and it is four controls.</strong> The UK&#8217;s National Cyber Security Centre published interim guidance on agentic AI on August 20. Every agent gets its own identity in a class distinct from humans, credentials scoped and short-lived, a named individual accountable for its activity, and its actions logged into monitoring the way a person&#8217;s are. Their maturity ladder ends, for the most sensitive work, at no external access with the model hosted locally. Interim guidance from a British agency, not American law. <a href="https://www.ncsc.gov.uk/blogs/managing-the-cyber-risk-of-agentic-ai" rel="nofollow noopener" target="_blank">NCSC</a></li>
</ul>
<h2>The question we asked</h2>
<p>Pick the newest AI tool inside your business. Can you name the person accountable for it, and show what it did last week? <a href="https://modtechgroup.com/newsletter/?utm_source=podcast&amp;utm_medium=shownotes&amp;utm_campaign=briefing-2026-08-22">Get the Modular Briefing by email</a> and reply to it. A person reads every reply.</p>
<h2>A note on the voices</h2>
<p>Laura and Arthur are AI-generated voices, produced locally on Modular&#8217;s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.</p>
<h2>Transcript</h2>
<details>
<summary>Read the full transcript</summary>
<p><strong>Laura:</strong> Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I&#8217;m Laura.</p>
<p><strong>Arthur:</strong> And I&#8217;m Arthur. Here&#8217;s what tied this week together. Three different authorities, in two different countries, inside ten days. A bar association, a securities examiner, and a national cyber agency. Not one of them asked whether your AI is any good. All three asked the same much harder question. Can you show your work?</p>
<p><strong>Laura:</strong> Story one, and it is about the quietest piece of software in your building. The meeting notetaker. On August seventeenth the New York City Bar Association released a formal ethics opinion from its Professional Ethics Committee on using AI to capture, transcribe and summarize conversations with people who are not your clients. The headline conclusion is one most firms have never actually made on purpose. Unless you have a good reason in that specific instance, the default should be to leave it switched off.</p>
<p><strong>Arthur:</strong> And the reach is wider than it sounds. Two earlier opinions covered conversations with clients. This one extends the same principles to co-counsel, opposing counsel, witnesses, prospective clients, and your own investigators. Get consent from everyone on the call before anything starts capturing. And the line that should land for a small firm: competence now includes knowing how to switch the thing off. Two honest notes. This is a New York City bar opinion, not a national rule, and the opinion itself is dated August fifth even though it was announced on the seventeenth. But the reasoning travels. And then the situation you don&#8217;t control at all: when the other side&#8217;s notetaker is running, you don&#8217;t own its security and you may never see the transcript. So the default setting is the policy. Somebody at your firm has to decide whether the bot joins the call, and if nobody has decided, then your vendor decided for you. Your data, your rules, and that goes for the AI itself. Your AI, your rules.</p>
<p><strong>Laura:</strong> Story two. In finance the same question arrived as a document request. Financial Advisor Magazine reported on August eighteenth, working from an examination request list obtained by Citywire, what Securities and Exchange Commission examiners are now asking investment advisers about artificial intelligence. And the questions are not about the technology. Does the firm have an AI committee. Does that committee keep written minutes.</p>
<p><strong>Arthur:</strong> Worth saying plainly: we have not read that document ourselves, so we are relaying the reporting, not the source. What the reporting describes is a paper trail hunt. Every channel where the firm advertises its AI, which is the agency checking for what the industry calls AI washing. It brought the first two of those cases in twenty twenty-four, and they settled for a combined four hundred thousand dollars. And whether employees were ever actually trained on the policy they were handed. Here is the part that travels well past finance. There is no rule requiring a document titled AI policy. The rules that already exist do the work: advertising, compliance, client privacy, recordkeeping, and your duty to the client. So nobody is asking you to invent a new binder. They are asking for evidence. An inventory of which tools are actually running. A training log with dates on it. Minutes that show a decision and who made it. That is an afternoon of work this month, and it is impossible to manufacture in the middle of an examination.</p>
<p><strong>Laura:</strong> Story three, and it&#8217;s the one I&#8217;d print out. On August twentieth the United Kingdom&#8217;s National Cyber Security Centre published interim guidance on the cyber risk of agentic AI. As far as we can tell it is the first time a government body has written down what governing an agent actually means in practice. It is shorter than anybody selling you a governance platform would like.</p>
<p><strong>Arthur:</strong> Four things. Every agent gets its own identity, in a class of its own, not a human&#8217;s login. Its credentials are narrow and short lived. A named person is accountable for what that agent does. And the agent&#8217;s actions get logged into your monitoring exactly the way a person&#8217;s activity is. That&#8217;s the list. Notice what it fixes. If your agent runs on an employee&#8217;s credentials, then in your own logs the agent and the employee are the same actor, and you can&#8217;t answer the only question that matters afterward: which one of you did that? Give the agent its own name and the answer writes itself. One caveat, said clearly: this is a British agency, and it&#8217;s interim guidance, not American law. Nobody needs to wait for their own regulator to copy four controls that already work. And note where their own maturity ladder ends up for sensitive work. No external access, model hosted locally, on infrastructure you control. From dirt to desktop. Your data, your rules.</p>
<p><strong>Laura:</strong> So the thread. A bar association asked for consent before the software listens. An examiner asked for the minutes. A cyber agency asked for an owner and a log. Two continents, three authorities, ten days, and none of them wanted a demo. Every one of them wanted proof. Capability is the part you buy. Evidence is the part you keep, and nobody can buy it for you afterward.</p>
<p><strong>Arthur:</strong> So here&#8217;s our question this week. Pick the newest AI tool inside your business. Can you name the person accountable for it, and show what it did last week? If both come easily, you&#8217;re in better shape than most. If they don&#8217;t, that&#8217;s not a failure, it&#8217;s just the next thing to write down. Reply to the Modular Briefing email and tell us where you landed, or write to me at arthur at modtechgroup dot com. A person reads every reply.</p>
<p><strong>Laura:</strong> Thanks for spending a few minutes with us.</p>
<p><strong>Laura &amp; Arthur:</strong> This has been The Modular Briefing. Your data, your rules. We will see you next time.</p>
</details>
<p><em>Your data, your rules.</em></p>
<p>The post <a href="https://modtechgroup.com/show-your-work/">The Modular Briefing, August 22, 2026: Show Your Work</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-08-22.mp3" length="7947746" type="audio/mpeg" />

			</item>
		<item>
		<title>A framework is not a control. Somebody has to run it.</title>
		<link>https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=a-framework-is-not-a-control-somebody-has-to-run-it</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 00:15:49 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/</guid>

					<description><![CDATA[<p>A framework is not a control. Somebody has to run it.AI Governance, fractional CAIO, AI program office, ~5 min readThere is a moment that arrives a few weeks after a good governance document lands on your desk. You have read it. You agree with all of it. The five principles are sensible, the risk tiers  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/">A framework is not a control. Somebody has to run it.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><strong>A framework is not a control. Somebody has to run it.</strong></h1>
<p>AI Governance, fractional CAIO, AI program office, ~5 min read</p>
<p>There is a moment that arrives a few weeks after a good governance document lands on your desk. You have read it. You agree with all of it. The five principles are sensible, the risk tiers make sense, and you cannot name a single person whose job it is to do any of it by Friday.</p>
<p>That moment is where most AI governance programs quietly stop.</p>
<p>On 29 July the Society of Pension Professionals published <a href="https://www.actuarialpost.co.uk/downloads/cat_1/SPP-Governance-in-the-Age-of-AI-29.7.26.pdf">Governance in the Age of AI: A Practical Framework for Responsible Leadership</a>, aimed at pension scheme trustees and the advisers and administrators who serve them. <a href="https://www.finextra.com/newsarticle/48160/spp-launches-ai-governance-framework-for-pensions-industry">Finextra covered the launch</a> the same week. If you do not work in pensions, read it anyway. Almost nothing in it is specific to pensions, and the argument it makes is the one every department head is about to have.</p>
<h2>What the pensions industry actually said</h2>
<p>The paper&#8217;s central claim is refreshingly unglamorous: AI does not need a new governance regime. It needs the duties that already exist, applied to facts those duties were not written for.</p>
<p>Trustees already owe a duty of prudence. They already have risk registers, service provider oversight, internal controls, and cyber and data governance frameworks. The SPP&#8217;s position is that AI belongs inside all of those, not in a separate binder next to them. The framework sets out five principles: transparency, accountability, proportionality to risk, security by design, and meaningful human oversight. It recommends classifying every AI use as low, medium, or high risk, and keeping an AI register that records current use cases, who owns each one, how it was approved, how often it is reviewed, and what gets reported to the board.</p>
<p>The urgency is in the adoption curve. The SPP&#8217;s own annual surveys found 87% of pension firms using AI in 2025 and 100% in 2026, <a href="https://www.pensionsage.com/pa/SPP-launches-AI-governance-framework-for-pension-schemes.php">as Pensions Age reported</a>. Jo Fellowes, who chairs the SPP&#8217;s administration committee, framed it this way: &#8220;The challenge is therefore not whether AI should be used, but how it can be used safely, transparently and with appropriate oversight.&#8221;</p>
<p>The Pensions Regulator reached the same place in its AI Plan of 20 May 2026, stating that trustees remain accountable for decisions and outcomes even when they delegate activities to providers or advisers. No new obligation was created. An existing one grew a much larger surface area.</p>
<h2>The gap between a principle and a control</h2>
<p>Here is where the paper gets uncomfortable, and where it earns the attention of anyone outside pensions.</p>
<p>&#8220;Meaningful human oversight&#8221; is the principle everyone signs. It is also the one almost nobody can currently evidence. The SPP invokes the Information Commissioner&#8217;s Office, whose draft guidance on automated decision-making went to consultation on 31 March, and the ICO&#8217;s test for meaningful human involvement is unusually concrete. The reviewer has to be trained to understand the system&#8217;s logic, outputs, limits, and risks. They have to hold the authority and the information to reach a different conclusion, not merely endorse the machine&#8217;s. They have to review while the decision can still be changed. And they have to do it every time, because spot checks leave everything else unchecked.</p>
<p>Asked by <a href="https://cfi.co/europe/2026/07/spp-ai-governance-framework-what-human-oversight-now-has-to-mean/">CFI.co</a> whether current administrator and adviser practice would satisfy those criteria, the SPP declined to claim it would. Fellowes said trustees and the industry are still getting to grips with AI uses and how to govern them, so there has not been enough challenge of administrators and advisers to understand what practices they actually have in place.</p>
<p>That is an unusually honest answer from a trade body, and it names the real problem. The distance between writing &#8220;a human reviews the output&#8221; in a policy and being able to prove it under questioning is enormous. It is filled with people, calendars, tooling, records, and someone senior enough to say no.</p>
<h2>Who owns this on Monday</h2>
<p>Every organization I talk to about AI governance is somewhere on the same three-step path, whether they run a pension scheme or a 60-person manufacturer.</p>
<p>They write the policy. That part is fast, and increasingly there is a good published framework to start from, which is exactly what the SPP has just given the pensions industry for free.</p>
<p>Then they discover the policy describes an operating model nobody is operating. There is no register, because building one means asking eleven departments what they are actually using and getting honest answers. There is no risk tiering, because tiering requires someone with the standing to tell a director their favorite tool is high risk. There is no evidence trail, because nobody specified what evidence looks like before the systems went live.</p>
<p>Then they either staff it or they do not. Staffing it properly means a Chief AI Officer, and for most mid-market organizations that role is real but not full-time. That is the gap Modular Technology Group&#8217;s fractional CAIO practice exists to fill: an executive who owns the AI program, writes and maintains the policy, runs the AI register and the sanctioned tool list, tiers the use cases, sets the review cadence, and shows up to the board meeting with the reporting the framework asks for. An AI Program Office behind that keeps the artifacts current between meetings, because a register that is six months stale is worse than none, since it looks like control.</p>
<p>The framework tells you what good looks like. It does not tell you who does it, and it cannot. That part is an org chart decision, and it is the only part that changes anything.</p>
<h2>Your data, your rules, and that includes the AI working on it</h2>
<p>Your AI, your rules. Not the vendor&#8217;s rules, not the model provider&#8217;s terms of service, and not a control that exists in a document and nowhere else.</p>
<p>Ask the three questions the SPP is really asking. Where is AI being used across your operation right now, including the parts nobody approved? Who is accountable for each of those uses by name? If a regulator, a client, or your own board asked you to reconstruct why an AI-assisted decision came out the way it did, could you?</p>
<p>If the answers are uncomfortable, you are in normal company. The SPP just told an entire industry the same thing in writing. The organizations that come out of this well will be the ones that treated the framework as a starting position rather than a finished deliverable, and put a name next to every line of it.</p>
<p>The post <a href="https://modtechgroup.com/a-framework-is-not-a-control-somebody-has-to-run-it/">A framework is not a control. Somebody has to run it.</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When compliance is built in, the audit stops being a project</title>
		<link>https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=compliance-built-in-audit-stops-being-a-project</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 00:15:49 +0000</pubDate>
				<category><![CDATA[Compliance]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/</guid>

					<description><![CDATA[<p>When compliance is built in, the audit stops being a projectCompliance, compliance-by-architecture, CMMC, ~5 min readAsk a compliance officer what the worst part of the job is and you will rarely hear "the regulations." You will hear about the six weeks before an audit. The scramble to find out which control changed, when, and why.  [Read more...]</p>
<p>The post <a href="https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/">When compliance is built in, the audit stops being a project</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1><strong>When compliance is built in, the audit stops being a project</strong></h1>
<p>Compliance, compliance-by-architecture, CMMC, ~5 min read</p>
<p>Ask a compliance officer what the worst part of the job is and you will rarely hear &#8220;the regulations.&#8221; You will hear about the six weeks before an audit. The scramble to find out which control changed, when, and why. The spreadsheet that was accurate in March. The engineer who has left the company and was the only person who knew how the logging worked.</p>
<p>That scramble is a symptom. It happens because compliance was bolted onto a system after the system existed, and the evidence has to be reassembled by hand every time somebody asks for it.</p>
<p>Pierre Ferran made a version of this argument on Finextra on 29 July, in a piece titled <a href="https://www.finextra.com/blogposting/32405/compliance-is-becoming-infrastructure-not-overhead">Compliance is becoming infrastructure, not overhead</a>. It is written for financial institutions, and the scale he describes is a bank&#8217;s scale. The mechanism he identifies is the same one that breaks a 70-person defense supplier trying to hold CMMC.</p>
<h2>The seam where compliance actually breaks</h2>
<p>Ferran&#8217;s diagnosis is precise, and it is worth quoting the shape of it. The bottleneck in a regulated firm is no longer expertise. Financial institutions employ some of the best regulatory specialists in the world, and they are not confused about what any single rule means.</p>
<p>What breaks is everything sitting between the text and the control. Interpreting the rule for this specific business. Mapping it to the products and processes it touches. Finding the gap in the existing policy. Fixing it. Assigning ownership. And being able to prove all of that later, when an auditor asks in 2027 why a control changed in 2025.</p>
<p>He describes the legacy operating model in a way that will be familiar well outside banking. A guideline is published. Someone in legal reads it and writes a summary. A spreadsheet gets updated. A working group is scheduled for three weeks later. Risk, technology, and product each read the same summary and reach slightly different conclusions about what it means for them, and the reconciliation happens in meetings, months before implementation starts. Then the next consultation closes and the cycle restarts.</p>
<p>By his account, a firm operating across a handful of jurisdictions now faces thousands of regulatory developments a day once you count level-one texts, delegated acts, technical standards, and supervisory guidance. Whether or not that number holds for your sector, the direction is not in dispute. Ferran points to DORA, applicable since January 2025, MiCAR, fully applicable at the end of 2024, and the AI Act phasing in through 2026 and 2027, with an AML package and PSD3 behind them. Regulation stopped being an event and became a flow.</p>
<h2>Security already made this move</h2>
<p>The best part of Ferran&#8217;s argument is the analogy he reaches for. There was a time when a security review happened just before a product went live. Today that would be unthinkable. Security is designed in across the whole build, because managing risk after systems exist is slow and expensive.</p>
<p>The closer precedent, he notes, is internal to compliance itself. GDPR already proved the point inside the discipline. Privacy could not be contained in the legal function. Privacy by design had to reach into product decisions, data protection assessments had to involve engineers, and records of processing depended on data teams keeping them current. That was the first obligation that could not be satisfied by a document.</p>
<p>AI is the next one, and it is less forgiving. An obligation about where personal data may be processed is an architectural question before it is a legal one. If your models run in someone else&#8217;s cloud, in a jurisdiction you did not choose, on infrastructure whose logging you cannot inspect, you are not going to policy your way out of it. The answer to &#8220;where does this data live and who can reach it&#8221; is decided by a purchase order, not a paragraph.</p>
<h2>What building it in looks like</h2>
<p>For a small or mid-sized organization, &#8220;compliance as infrastructure&#8221; is not an abstraction. It is a short list of decisions made in a particular order.</p>
<p>Residency and jurisdiction come first, because they are the hardest to change later. Which physical facility holds the data, under which country&#8217;s law, and who has custody of the keys. Everything downstream inherits from that answer.</p>
<p>Then access, scoped and revocable, with a record. Not a policy that says only authorized personnel may access client data, but a system where unauthorized access is structurally not available and every authorized access leaves a trail nobody can quietly edit.</p>
<p>Then evidence as a byproduct of running, rather than a project that starts eight weeks before the assessor arrives. If your audit trail is generated by the same systems that do the work, the audit stops being an archaeology exercise. You already have the answer to when a control changed, because the change is in the log.</p>
<p>This is what Modular Technology Group means by compliance-by-architecture rather than compliance-by-audit. Private AI infrastructure in a US facility, so residency and jurisdiction are settled facts rather than vendor commitments. Fixed monthly pricing, because a compliance program you cannot budget for is a compliance program that gets deferred. And a program built to satisfy the framework the client is actually held to, whether that is CMMC, NIST 800-171, HIPAA, or FedRAMP alignment, rather than a general posture of being careful.</p>
<p>The economics are the part that usually surprises people. Bolted-on compliance is cheap to start and expensive forever, because every new obligation costs another remediation project. Built-in compliance costs more in month one and then absorbs new requirements as configuration changes. Ferran&#8217;s test for a firm is a good one to steal: how long does it take you, from the day a requirement is published, to know which parts of your operation it touches and who owns the response. If the honest answer is months, the problem is architectural.</p>
<h2>Your data, your rules, from dirt to desktop</h2>
<p>Modular owns the stack from the physical facility through the user interface, which is the only way to answer the residency question without a footnote. One vendor, no handoffs between a cloud provider, a hosting provider, and an AI provider, each of whom can only speak for their own layer.</p>
<p>Compliance has always been the price of operating in a regulated industry. What is changing, and Ferran is right that GDPR started it rather than the AI Act, is that it is turning into the thing that lets you move faster instead of the thing that stops you making mistakes. The firms that get there will not be the ones with the biggest compliance teams. They will be the ones who stopped treating compliance as paperwork and started treating it as plumbing.</p>
<p>The post <a href="https://modtechgroup.com/compliance-built-in-audit-stops-being-a-project/">When compliance is built in, the audit stops being a project</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Modular Briefing, August 10, 2026: The Agent Was You</title>
		<link>https://modtechgroup.com/the-agent-was-you/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-agent-was-you</link>
		
		<dc:creator><![CDATA[Arthur]]></dc:creator>
		<pubDate>Mon, 10 Aug 2026 13:00:00 +0000</pubDate>
				<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Podcast]]></category>
		<guid isPermaLink="false">https://modtechgroup.com/?p=5915</guid>

					<description><![CDATA[<p>A federal court says the human who points an agent is the one who acted. A stress test says a tired reviewer waves through one dangerous request in three. And a show floor full of agent governance turned out to be mostly dashboards.</p>
<p>The post <a href="https://modtechgroup.com/the-agent-was-you/">The Modular Briefing, August 10, 2026: The Agent Was You</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure class="wp-block-audio"><audio controls src="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-08-10.mp3"></audio><figcaption>The Modular Briefing, August 10, 2026 &middot; 6:27</figcaption></figure>
<p>Cale is back from Ai4 in Las Vegas, and the news wrote his trip report for him. Three stories this week, and one question underneath all of them: when an agent acts, who answers for it?</p>
<h2>In this episode</h2>
<ul>
<li><strong>A federal court says the human who points the agent is the one who acted.</strong> On August 4 the Ninth Circuit vacated the injunction Amazon had won against Perplexity&#8217;s Comet shopping agent. Under the federal anti-hacking law, the court read &#8220;access&#8221; as a person entering a system; software is a tool, and tools do not carry liability. One circuit, an early stage, and Amazon&#8217;s other theories are still live. <a href="https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf" rel="nofollow noopener" target="_blank">Opinion, No. 26-1444 (PDF)</a></li>
<li><strong>&#8220;A human reviews it&#8221; has a measured failure rate.</strong> Belgian developer Alex Wauters built a browser game that flashes real agent permission prompts on a sixty-second clock. Across more than forty thousand rounds, players approved roughly one dangerous request in three. Anthropic&#8217;s own telemetry puts real-world approval around ninety-three percent. <a href="https://www.theregister.com/ai-and-ml/2026/08/06/humans-in-the-loop-miss-a-third-of-dangerous-ai-coding-agent-requests/5284236" rel="nofollow noopener" target="_blank">The Register</a></li>
<li><strong>Half a continent could last one business day.</strong> A survey of 1,500 firms across the UK, France and Germany found 73.9% worried Washington could cut off their access to US technology, and 54.5% said they could operate for a single business day without their cloud services. 44% have a continuity plan they have tested. The survey was commissioned by Proton, which sells the sovereign alternative; weigh it accordingly. <a href="https://www.theregister.com/off-prem/2026/08/06/european-firms-afraid-of-us-tech-kill-switch-but-havent-made-an-escape-plan/5284030" rel="nofollow noopener" target="_blank">The Register</a></li>
</ul>
<h2>Report from the floor: Ai4 2026</h2>
<p>Cale worked more than thirty booths at The Venetian, August 4 to 6. Three things he brought home.</p>
<ul>
<li><strong>The argument won.</strong> A main-stage keynote titled &#8220;From Renting AI to Owning Intelligence.&#8221; Appliance vendors printing &#8220;No tokens. No surprises.&#8221; on their booth walls. The CIO of a NATO procurement agency describing keeping local models close for sensitive work. Owning your AI has stopped being a niche position.</li>
<li><strong>Most &#8220;agent governance&#8221; is a dashboard.</strong> It shows you what your agent did. Far fewer products will stop it, and watching an agent misbehave in real time is not a control. The crowd of new names read like the late nineties; Cale&#8217;s own bet, offered as a bet, is that many are gone within a year. If your oversight lives in a startup&#8217;s dashboard, your controls inherit that startup&#8217;s odds.</li>
<li><strong>Ng and Hinton.</strong> They disagree about where this goes, and Hinton&#8217;s doom ran a little thick for Cale. The take-home fits in two sentences: build now, the way Ng says. Govern like Hinton is right.</li>
</ul>
<h2>The question we asked</h2>
<p>If one of your agents did something wrong yesterday, could you reconstruct what it touched, or would you be guessing? <a href="https://modtechgroup.com/newsletter/?utm_source=podcast&amp;utm_medium=shownotes&amp;utm_campaign=briefing-2026-08-10">Get the Modular Briefing by email</a> and reply to it. A person reads every reply.</p>
<h2>A note on the voices</h2>
<p>Laura and Arthur are AI-generated voices, produced locally on Modular&#8217;s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.</p>
<h2>Transcript</h2>
<details>
<summary>Read the full transcript</summary>
<p><strong>Arthur:</strong> Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I&#8217;m Arthur.</p>
<p><strong>Laura:</strong> And I&#8217;m Laura. When we left you, we said Cale was headed to Ai4 in Las Vegas to see what actually holds up. He&#8217;s back. Three days, thirty booths, two legends on stage, and one sticker from the CIA. What he saw is the story the news wrote while he was there. When an agent acts, who answers for it? A federal court just gave an answer. So did a stress test of human oversight. So did a continent pricing its own dependency.</p>
<p><strong>Arthur:</strong> Story one. On August fourth, the Ninth Circuit Court of Appeals answered the question every AI pilot eventually runs into. When an agent acts, who did it? The case was Amazon against Perplexity, whose Comet shopping agent had been operating on Amazon&#8217;s site on customers&#8217; behalf. Amazon had won an order blocking it back in March. The appeals court threw that order out.</p>
<p><strong>Laura:</strong> And the reasoning is the part your business should care about. Under the federal anti-hacking law, the court said access means a person entering a computer system. Software is a tool. Tools don&#8217;t carry liability. So when your employee points an agent at a system, the one who accessed it is your employee. And behind your employee, your firm. The honest caveats, because the legal press is being careful and so are we. One circuit, an early stage, and Amazon&#8217;s other legal theories are still open. This is not a court declaring agents fine. But it&#8217;s the first appellate word, and it points the accountability at whoever deployed the agent. So the vague question just became specific. Who at your firm may point an agent at what, and is that written down? If nobody wrote it down, then today the answer is everybody. Your data, your rules, and that goes for the AI itself. Your AI, your rules.</p>
<p><strong>Arthur:</strong> Story two. Almost every AI policy written this year leans on one sentence. A human reviews it. This week The Register reported a number for how much weight that sentence holds. A Belgian developer, Alex Wauters, built a browser game that flashes real agent permission prompts, some safe, some dangerous, sixty seconds to approve or deny. Across forty thousand rounds, players approved roughly one dangerous request in three.</p>
<p><strong>Laura:</strong> And before anyone says that&#8217;s just a game, Anthropic&#8217;s own telemetry says real users approve about ninety-three percent of what their agents ask for. Approval fatigue. The more prompts you see, the less you read each one. Cale heard the same conclusion from the defense side at Ai4. On the cybersecurity panel that stuck with him most, Ed Cartagena of Menlo Security laid out the new threat picture, and Cale&#8217;s takeaway was two sentences long. An agent with borrowed credentials behaves like a fast, tireless employee nobody supervises. And attacks move at machine speed, so a human clicking yes on every step was never going to be the control that holds. Your people aren&#8217;t careless. The control was never built to carry the whole load. So layer it. Least access, so a bad yes can&#8217;t reach client files. A boundary the agent can&#8217;t talk its way out of. Let the machines watch the machines, and save the humans for the calls a human should make.</p>
<p><strong>Arthur:</strong> Story three, also from The Register. A survey of fifteen hundred businesses across the UK, France and Germany found nearly three in four are worried the US government could cut off their access to American technology. And more than half said that if they lost their cloud services, they could keep operating for one business day. One.</p>
<p><strong>Laura:</strong> Fair disclosure, the way the reporting makes it. The survey was commissioned by Proton, a Swiss company that sells the sovereign alternative, so weigh it accordingly. But the gap is real, and it isn&#8217;t only European. Fewer than half of those firms have a continuity plan they&#8217;ve actually tested. So here&#8217;s the move. An exit plan is not a migration. It&#8217;s a document. Where does your data live? Who can reach it? What still runs if a vendor stops answering? How long would a move take? You can write the first version in an afternoon. And if you want the stronger position, run the work that matters on infrastructure you control, from dirt to desktop, so the kill switch question never has your name in it. Your data, your rules.</p>
<p><strong>Arthur:</strong> Before we close, the report from the floor. Cale talked to every booth he could get to at Ai4, more than thirty. Infrastructure on one end, agent governance as far as he could see. Cisco. PayPal. Mistral. His read comes in three parts.</p>
<p><strong>Laura:</strong> Part one, the argument won. A main stage keynote was literally titled From Renting AI to Owning Intelligence, appliance vendors are printing no tokens, no surprises on their booth walls, and the CIO of a NATO procurement agency described keeping local models close for the sensitive work. Owning your AI has quit being a niche position. Part two, a warning if you&#8217;re shopping that hall. Most of what&#8217;s sold as agent governance is a dashboard. It shows you what your agent did. Far fewer products will stop it, and watching an agent misbehave in real time is not a control. The crowd of new names reminded Cale of the late nineties, and his honest bet, take it as one, is that many won&#8217;t be around in a year. If your oversight lives in a startup&#8217;s dashboard, your controls inherit that startup&#8217;s odds. Part three, the keynotes. Andrew Ng and Geoffrey Hinton famously disagree about where this goes, and Cale will tell you Hinton&#8217;s doom ran a little thick. His take home fits in two sentences. Build now, the way Ng says. Govern like Hinton is right.</p>
<p><strong>Arthur:</strong> So the thread. The court says an agent&#8217;s actions belong to whoever pointed it. The research says a tired human clicking yes isn&#8217;t ownership. Half a continent just learned that renting everything means owning nothing. And on that show floor, capability was everywhere and enforcement was scarce. Capability is easy to buy. Accountability has to be assigned.</p>
<p><strong>Laura:</strong> Our question this week, and be honest. If one of your agents did something wrong yesterday, could you reconstruct what it touched, or would you be guessing? Reply to the Modular Briefing email and tell us which one you are. A person reads every reply.</p>
<p><strong>Arthur:</strong> Thanks for spending a few minutes with us.</p>
<p><strong>Laura &amp; Arthur:</strong> This has been The Modular Briefing. Your data, your rules. We will see you next time.</p>
</details>
<p><em>Your data, your rules.</em></p>
<p>The post <a href="https://modtechgroup.com/the-agent-was-you/">The Modular Briefing, August 10, 2026: The Agent Was You</a> appeared first on <a href="https://modtechgroup.com">Modular Technology Group</a>.</p>
]]></content:encoded>
					
		
		<enclosure url="https://assets.modtechgroup.com/podcast/audio/modular-briefing-2026-08-10.mp3" length="9310084" type="audio/mpeg" />

			</item>
	</channel>
</rss>
