Since Publication

A DEFERRAL IS NOT A REPRIEVE: three obligation sets went live while one was postponed.

Since Publication // The Living Log

What Has Changed Since the Book Went to Press

Twenty eight dated developments across the three crisis strands plus the evidence base, each classified by whether it confirms the book, sharpens it, corrects it, or did not exist when the manuscript closed. Current as at 15 September 2026.

28Dated developments
4Corrections to the book
13New since the manuscript closed
9Where the book was right early
Why this page exists and why it is separate. A playbook is only useful if the calendar behind it stays current. Three dates in this book moved within seven months of publication, and one of them was settled six days before it would otherwise have taken effect. This log is the part of the site that has a reason to change every month.

Corrections are published here, not buried. Four figures or characterisations printed in the book are now wrong or too loose, and they are set out in their own table near the bottom with the corrected position. An author who hides corrections is not worth reading on a subject where the dates move.

Nothing on this page is legal, technical or financial advice. Verify every date against the primary source before relying on it.
ConfirmsThe book anticipated it and it happened. Chapter 7 predicted the Digital Omnibus outcome including entry into force three days after publication, which is exactly what occurred.
SharpensThe book was directionally right and the detail is now firmer, usually because a provisional agreement became enacted text with article numbers attached.
CorrectsA figure or a characterisation printed in the book is now wrong. Four entries. Listed again on their own below with the corrected position.
NewDid not exist when the manuscript closed. A rewritten enforcement article, a new class of inventory artefact, and the first national governance framework for autonomous agents.

Filter

REG

Regulatory and Sovereignty

Extends Chapters 3, 7, 8 and 14. The strand where the most moved and where the most was misreported.

8 July 2026 // European UnionConfirmsEnacted law

The Digital Omnibus on AI is enacted law, not a proposal

The package was adopted as Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and entering into force on 27 July 2026, six days before the date on which the high risk obligations would otherwise have applied. It amends the AI Act and also Regulation (EU) 2018/1139 on aviation and Regulation (EU) 2023/1230 on machinery. The Council gave its final approval on 29 June 2026, following the provisional political agreement of 7 May.

What it means for the book. Chapter 7 called this outcome while it was still a proposal, and called the mechanics correctly: it stated the amendments would enter into force three days after publication in the Official Journal, which is precisely what happened. The question the chapter left open, whether the deferral would arrive in time, is now closed. It did, with six days to spare.

Affects Chapter 7. Register rows EU-7, EU-8, EU-9. Verify against the consolidated text on the official EU law portal.

27 July 2026 // European UnionCorrectsEnacted law

Four dates moved, not two, and Article 50 was not one of them

The Omnibus moved exactly four application dates. Annex III stand alone high risk obligations to 2 December 2027. Annex I embedded high risk obligations to 2 August 2028. The Member State duty to have a national regulatory sandbox operational under Article 57 to 2 August 2027. And the machine readable content marking duty, for generative systems already on the market before 2 August 2026, to 2 December 2026. Nothing else changed date. The Omnibus created no new obligations, removed none, and introduced no derogations or exemptions.

Correction to the book. Chapter 7 describes the Article 50 transparency and marking obligations as “deferred by four months only, from August 2026 to December 2, 2026”. The enacted position is narrower and the difference matters. Article 50 applied in full on 2 August 2026 and is enforceable now. What runs to 2 December 2026 is only the machine readable marking duty under Article 50(2), and only for generative systems that were already on the market before 2 August 2026. A system placed on the market after that date had no grace period at all. Read the chapter’s sentence as describing the transitional, not the article.

The sandbox deferral is the one most often missed entirely. It is regularly listed among the provisions the Omnibus left alone. It is not one of them.

Corrects Chapter 7. Register rows EU-4, EU-5, EU-6, EU-7, EU-8. Testable per system with the EU AI Act Deadline Checker.

27 July 2026 // European UnionNewEnacted law

Article 75 is rewritten and the AI Office gains exclusive enforcement competence

The Omnibus rewrites Article 75, retitling it market surveillance and control of AI systems and mutual assistance, and inserts new Articles 75a to 75d. The new Article 75(1) confers on the AI Office exclusive competence for the supervision and enforcement of obligations in relation to two categories: AI systems based on general purpose AI models where the model and the system are developed by the same provider or by providers within the same undertaking, and systems that constitute, or are integrated into, a very large online platform or very large online search engine designated under the Digital Services Act. Because these provisions sit in Chapter IX, which applies from 2 August 2026, the amendments entered the text on 27 July but the powers became exercisable a week later.

What it means for the book. This did not exist when the manuscript closed and it changes who you answer to. For a large enough vertically integrated provider, or for anyone whose system sits inside a designated platform, the counterparty is no longer a national market surveillance authority but the AI Office directly. That is a different escalation path, a different evidentiary expectation and a different political dynamic from the national regulator relationship Chapters 8 and 14 assume. If you are in either category, your regulatory engagement plan needs rewriting rather than adjusting.

New material affecting Chapters 7, 8 and 14. Verify Articles 75, 75a to 75d against the consolidated text.

2 August 2026 // European UnionSharpensIn force

Transparency is live and enforceable, and so is Commission fining power over models

The Act’s main transparency duties, including Article 50, took effect on their original date and are now subject to enforcement. On the same date the Commission’s power to investigate and fine general purpose AI model providers under Article 101 began, and national enforcement of the prohibitions, the AI literacy duty and the general purpose AI rules commenced. The general application date of the Regulation was itself untouched.

What it means for the book. This is the distinction Chapter 7 emphasised and it has now been tested by events. Organisations that read the headline as a general delay and stood their programmes down missed three live obligation sets while gaining time on one deferred set. The chapter’s rule, treat August 2026 as the planning date and December 2027 as a margin to preserve rather than spend, held up exactly.

Confirms Chapters 7 and 8. Register rows EU-4, EU-10, EU-11, EU-12.

19 May 2026 // European UnionNewCommission guidance

Commission guidance on how to classify a high risk system

The Commission published guidelines to help providers, deployers and market authorities assess whether an AI system should be classified as high risk under Article 6, the provision the Act itself required the Commission to clarify. Subsequent draft guidance addresses specifically when a workplace AI tool falls into the high risk category, which is the single most commonly disputed classification question in the Annex III employment area.

What it means for the book. Chapter 7 describes the Article 6 classification test and the Article 6(3) filter. What it could not include is guidance on how a regulator will read them. If you have an Article 6(3) filter claim documented before May 2026, it was written without this material and should be reviewed against it, particularly any claim resting on a system being a preparatory or narrow procedural task in an employment context.

Extends Chapter 7. Relevant to any Article 6(4) documented assessment.

2 December 2026 // European UnionNewForthcoming

The next hard date adds prohibitions rather than removing them

Two new practices join the Article 5 prohibited list on 2 December 2026, covering AI generated non consensual intimate imagery and child sexual abuse material. The same date is the end of the transitional window for machine readable marking of generative systems that were already on the market before 2 August 2026.

What it means for the book. The prohibited list in Chapter 7 is a snapshot of February 2025 and August 2025. It grows. Any organisation running generative capability in a consumer facing product should be checking both of these, because a prohibited practice carries the highest penalty tier in the Regulation and cannot be cured by documentation.

Extends Chapter 7. Register row EU-5. The nearest forthcoming obligation on this page.

27 July 2026 // European UnionNewEnacted law

Bias testing on special category data is now expressly permitted

Among the simplification measures, the Omnibus permits providers and deployers to process special categories of personal data, such as biometric or health data, specifically in order to detect and correct bias in their AI systems.

What it means for the book. This removes a genuine catch that the book does not address: the tension between an Article 10 data governance duty to test for bias and a data protection regime that restricted processing the very attributes you needed in order to test. If your fairness testing programme was scoped around that constraint, it can be widened.

New material affecting Chapters 7 and 8.

2026 // European UnionSharpensAnalysis

Why the deferral happened, which is the part that predicts the next one

The stated reasons were structural rather than political. The harmonised technical standards needed for conformity assessment under Article 40 were not finalised by the original date. Notified bodies still required designation and accreditation. National competent authorities needed resourcing and guidelines, and the AI Office needed operational capacity. On the published analysis, an August 2026 high risk deadline would have been unenforceable in practice.

What it means for the book. This supports the chapter’s framing and gives a test for whether the December 2027 date will hold. The binding constraint was never enterprise readiness, it was the enforcement infrastructure. Watch the progress of harmonised standards and notified body designations rather than the political commentary. If those are not in place by mid 2027, plan for the possibility of a further restaging, while remembering that the conformity work itself does not shrink either way.

Extends Chapter 7. A leading indicator worth tracking quarterly.

2026 // United StatesConfirmsState law

The state patchwork keeps thickening, and keeps mirroring Europe

Connecticut has enacted the CART Act, establishing AI related compliance requirements, joining the set of state regimes that concentrate on consequential decision making in areas such as healthcare, lending and employment.

What it means for the book. Chapter 7 predicted that state rules would increasingly mirror EU AI Act categories while complementing the federal sectoral approach. That is what continues to happen, and it has a practical consequence the chapter draws out: an Annex III style classification exercise done once for Europe is reusable for several United States jurisdictions, which changes the economics of doing it properly.

Confirms Chapter 7 and Chapter 14. Add to the jurisdiction map in the Regulatory Obligation Register.

PQC

Quantum Readiness

Extends Chapters 2, 6, 11 and 13. The strand where the operative dates moved forward, not back.

22 June 2026 // United StatesNewExecutive order

Two executive orders turn post quantum migration from strategy into deadlines

Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, mandates an accelerated government wide migration to post quantum cryptography, establishes binding deadlines for high value assets, and directs the Federal Acquisition Regulatory Council to require contractor compliance with NIST post quantum standards. A second order signed the same day addresses quantum leadership, commercialisation and workforce, and establishes the Quantum Computer for Application Development and Discovery Science effort. The State Department is directed to encourage foreign governments and industry to transition to NIST standardised algorithms.

What it means for the book. Chapter 13 argues that federal timelines reach commercial contracts that carry no direct federal obligation. That argument now has an instrument behind it. A direction to the Federal Acquisition Regulatory Council is the mechanism by which a federal deadline becomes a clause in your contract, and it converts the chapter’s prediction into a procurement exposure you can put a date against.

Extends Chapters 6 and 13. Register rows PQ-3, PQ-4. Verify against the published order text.

22 June 2026 // United StatesCorrectsExecutive order

The operative federal date is no longer 2035. For high value assets it is 2030 and 2031

Federal agencies are to migrate high value assets with key establishment on a post quantum standard by 31 December 2030 and digital signatures by 31 December 2031. Contractors selling to the federal government face a 2030 compliance deadline for NIST standardised algorithms. Support for TLS 1.3 or a successor is required across all federal systems by 2 January 2030. NIST is to run a pilot migration on a subset of its own systems, to be completed no later than 31 December 2027.

Correction to the book. Chapters 2, 6 and 13 use 2035 as the federal anchor and describe it as the de facto expectation flowing into supply chains. 2035 remains the outer horizon and the NSM-10 full compliance date, but it is no longer the operative planning date. For high value assets and for anyone selling to the federal government, the dates that will appear in a contract are 2030 and 2031. If you built a migration plan against 2035 and you are in a federal supply chain, you have five fewer years than the plan assumes, and the shelf life arithmetic in Chapter 2 should be re run with the earlier date.

Corrects Chapters 2, 6 and 13. Re run the Quantum Shelf Life Calculator with 2030 as the planning date.

22 June 2026 // United StatesNewExecutive order

The Cryptographic Bill of Materials becomes a named artefact

CISA and NIST are directed to publish public guidance, within 270 days of the order, on the minimum elements of a Cryptographic Bill of Materials: a machine readable inventory designed to enable the automated assessment of the cryptographic assets used by a hardware or software element. Guidance is therefore due around March 2027.

What it means for the book. This is a new class of artefact and it lands directly between two things the book already treats separately. Chapter 8 covers the AI bill of materials; Chapter 6 and the Cryptographic Census cover cryptographic inventory. A CBOM is the second of those in the machine readable, procurement enforceable form the first is taking. The practical move is to build your cryptographic census now in a structure that can be exported rather than rewritten, because the minimum elements will be published and a supplier questionnaire will follow within a year of that.

New material affecting Chapters 6, 8 and 13. Affects the AIBOM Readiness Checklist and the Cryptographic Census workbook.

21 September 2026 // United StatesNewStandards

FIPS 140-2 sunsets in days, with an immediate procurement consequence

On 21 September 2026 all remaining FIPS 140-2 certificates move to Historical status. From that date only FIPS 140-3 validated modules may be used for new procurement. For anyone selling cryptographic products into the United States government, validation status determines market access from that day forward.

What it means for the book. Not in the manuscript, and the nearest deadline on this page. It is also the cheapest possible test of whether your cryptographic inventory is real: if you cannot answer within the day which of your modules are validated to 140-3 and which are still on 140-2, you do not have an inventory, you have a list. That is the same test the Friday Afternoon Test applies to governance, applied to cryptography.

New material affecting Chapters 6 and 13. Add as a row to the Cryptographic Census.

April 2026 // IndustryConfirmsVendor commitment

The private sector horizon moved in, exactly as the book records

Cloudflare moved its own target for full post quantum security to 2029, citing research breakthroughs from Google and Oratomic, and has described the Q Day timeline as having accelerated. The standing NIST position is that classical public key cryptography should be deprecated by 2030 and disallowed by 2035. The Commercial National Security Algorithm Suite calendar is unchanged: new national security system acquisitions compliant by 1 January 2027, exclusive use in operating systems, applications and cloud services by 2033, full quantum resistance by 2035.

What it means for the book. Chapter 1 records Google’s internal 2029 deadline and Cloudflare targeting the same horizon. Both stand, and Cloudflare has since restated its 2029 target explicitly on the back of new research. The January 2027 acquisition date in Chapter 13 also stands and is now the nearest quantum deadline for anyone in a defence supply chain.

Confirms Chapters 1, 6 and 13. Register rows PQ-5 through PQ-9.

2026 // United StatesNewSecurities disclosure

Quantum readiness is becoming a disclosure question, not only a security one

Proposed regulatory frameworks for digital asset custody now reference NIST post quantum algorithms by name and cite compatibility with the Commercial National Security Algorithm Suite as a security consideration. Several recent registration statements from companies pursuing public listings explicitly disclose the use of hybrid schemes combining post quantum with classical cryptography.

What it means for the book. Chapter 11 argues quantum economics in the language of a CFO. This is the strongest available extension of that argument, and it changes who owns the question. Once quantum posture appears in a registration statement it is a disclosure matter with a general counsel and an audit committee attached, not a technical roadmap item. The relevant question becomes what you would be willing to state in writing, which is a materially higher bar than what you would put on a slide.

New material affecting Chapters 11 and 13. Relevant to the board reporting templates.

2026 // European UnionSharpensCoordinated roadmap

Europe’s roadmap puts the start line at the end of this year

The coordinated European post quantum roadmap, developed by the cooperation group established under the network and information security regime, targets the start of transition by the end of 2026 and protection of critical infrastructure by the end of 2030.

What it means for the book. Chapter 7 treats the European regulatory calendar and Chapter 13 treats the migration. This joins them: for a European critical infrastructure operator the two strands now share a date, and the end of 2030 European target sits alongside the 31 December 2030 United States high value asset date. An organisation operating in both now has one planning horizon rather than two competing ones, which is a rare simplification in this subject.

Extends Chapters 7 and 13.

AGT

Agent Governance

Extends Chapters 1, 4, 5, 10 and 12. The strand where the book’s central argument was independently arrived at by others.

26 May 2026 // GartnerConfirmsAnalyst researchAlso a correction

The autonomy ladder argument is now the mainstream analyst position

Gartner published research warning that enterprises applying uniform governance across all AI agents, regardless of autonomy level or scope, are heading toward widespread deployment failures. Its prediction: by 2027, forty percent of enterprises will demote or decommission autonomous AI agents due to governance gaps identified only after production incidents occur. The recommended remedy is a proportional approach that classifies agents across distinct autonomy levels, each level representing a different trust boundary with its own governance requirements, beginning at a read only observe tier and rising to agents that execute independently.

What it means for the book. This is the strongest external validation the L0 to L5 ladder has received, and it arrived independently. The book’s argument is that autonomy level determines governance intensity, that a common language across technical and non technical stakeholders is the precondition for governing at all, and that the step where the human stops seeing the work is the step that matters. Gartner has reached the same structure, and named the failure mode: “Enterprises are treating AI agent governance as binary, either locked down or fully trusted, and that is the root cause of failure.” Note also that this is a different prediction from the June 2025 one the book cites. Both now stand, and they describe different failures: projects cancelled before production, and agents pulled back after it.

Confirms Chapters 4, 5 and 12. Add alongside the existing Gartner citation in Chapter 1.

26 May 2026 // GartnerConfirmsAnalyst research

Both failure modes match the book’s governance matrix

The research names two symmetrical failures. Over restriction of simple agents slows delivery and drives shadow development. Under restriction of more autonomous agents means they operate with access and authority the organisation never properly evaluated, producing incidents “often from AI taking actions no one realised it had permission to take”.

What it means for the book. Both halves are in the manuscript. Over restriction driving shadow development is the mechanism behind the eighth commitment, that you will find the AI you did not authorize: excessive friction manufactures the very invisibility the commitment exists to address. Under restriction producing actions nobody knew were permitted is the Chapter 5 identity argument, that an agent inherits the security posture of its credentials rather than its autonomy tier. The two failure modes are not opposites to be balanced, they are the same missing capability, which is the ability to tell agents apart.

Confirms Chapters 5, 12 and Commitment Eight.

26 May 2026 // GartnerConfirmsAnalyst research

Approval fatigue is named as a control failure, not a process irritation

On the higher autonomy tiers the research is blunt: “human review is effective only if it remains a meaningful control.” Without strong security testing, clear approval workflows with audit trails and agent specific incident response procedures, “approvals can degrade under time pressure or approval fatigue, creating a false sense of safety while expanding the attack surface”.

What it means for the book. The Governance Charter template in the toolkit contains human oversight measures designed to detect approval by reflex, and the Human Oversight Design Template is built around anti rubber stamp measures. That design choice now has analyst language behind it. The phrase worth carrying into a governance committee is the last one: an oversight control that has degraded does not fail safe, it expands the attack surface while reporting green.

Confirms Chapter 12 and the Agent Governance Charter Template.

February 2026 // NISTConfirmsStandards body

NIST opens an agent standards initiative and states the identity problem in the book’s terms

The Center for AI Standards and Innovation launched an AI Agent Standards Initiative, calling for identity, security and monitoring standards. The associated concept paper from the National Cybersecurity Center of Excellence frames the gap directly: agents are commonly treated as generic service accounts without dedicated identity, authorization or accountability controls. Separately, NIST published AI Agent Hijacking: Strengthening Evaluations for Autonomous AI Systems in its AI 100 series.

What it means for the book. Chapter 5 argues that the dangerous cell in the matrix is low autonomy paired with high identity privilege, and states that an L2 agent holding broad service account credentials inherits the security posture of the credentials rather than the autonomy tier. NIST has now written the same sentence in its own words. This is the single most useful citation available for a CIO who needs to justify agent identity work to a security function that already trusts NIST.

Confirms Chapter 5. Strengthens the identity tier columns in the Agent Inventory workbook.

January 2026 // SingaporeNewNational framework

The first national governance framework for autonomous agents

Singapore’s Infocomm Media Development Authority published a Model AI Governance Framework for Agentic AI, described as the first comprehensive governance framework for autonomous agents. It requires each agent to carry a verifiable digital identity and an audit trail of which agent acted under whose authorisation.

What it means for the book. This is a concrete, citable implementation of the argument Chapter 5 makes in principle, and it is the direction of travel for everyone else. The two requirements are worth reading as a specification rather than as guidance: a verifiable identity per agent, and a trail that answers whose authority the agent was acting under. Most enterprises can produce neither today. If you want a target state for the identity columns of your agent inventory, this is currently the most specific published one.

New material affecting Chapters 5 and 14. A target state for the Agent Inventory workbook.

December 2025 // OWASPNewIndustry standard

A dedicated agentic top ten exists and the classifier maps to it

OWASP published the Top 10 for Agentic Applications, version 1.0, a separate list from the large language model application top ten. It covers goal hijacking, tool misuse and rogue agents among its named risks.

What it means for the book. The manuscript treats agent specific risk categories in Chapters 4 and 5 without a canonical external list to anchor them, because there was not one at the time of writing. There is now. The practical value is in procurement and assurance conversations: a named, versioned industry list is something a supplier can be asked to evidence against, and a board paper can cite without explanation.

New material affecting Chapters 4, 5 and 8. Referenced by the L0 to L5 Classifier crosswalk.

2026 // Survey evidenceNewIndustry survey

About half of production agents are running unmonitored

Published 2026 survey work reports that eighty eight percent of organisations experienced a confirmed or suspected AI agent security incident in the prior year. Separate survey data puts mean agent monitoring coverage at fifty two percent, meaning roughly half of agents in production are running unsecured, with only 9.5 percent of organisations securing more than eighty one percent of their deployed agents. Active deployers among senior technology leaders reported running seventy six to one hundred agents and roughly doubling each quarter.

What it means for the book. The manuscript argues that discovery precedes governance and that most of what is operating was never authorized. These figures put a number on it from the other direction: the problem is no longer only that organisations cannot find their agents, it is that they can name them and still are not watching them. A doubling rate per quarter also means an inventory is stale within a quarter, which is the argument for automated maintenance rather than periodic sweeps.

Extends Chapters 1, 5 and 12. Survey figures, so treat as directional rather than precise.

2026 // ResearchNewRed team study

A red team study documents the failure modes end to end

A published red teaming corpus placed autonomous agents in a live environment with persistent memory, email, chat, filesystem and shell access, and had twenty researchers interact with them over two weeks. The documented case studies include unauthorised compliance with instructions from non owners, sensitive data disclosure, destructive system actions, identity spoofing, and cross agent propagation of unsafe behaviour. Separately, backdoored builds of a widely used model gateway library were downloaded approximately forty seven thousand times during the three hours they were available on a public package index.

What it means for the book. Two additions to the threat picture. Cross agent propagation is the one the manuscript treats least: containment procedures assume you are stopping an agent, not stopping a behaviour that has already spread to its neighbours. The supply chain figure is the more immediately actionable, because a three hour exposure window producing tens of thousands of downloads means the agent dependency chain is now an attack surface in its own right, and the Containment Procedure’s twelve prerequisites should include knowing what your agents import.

Extends Chapters 5 and 12. Affects the Agent Containment and Kill Switch Procedure.

EVD

Evidence and Economics

Extends Chapters 10 and 11. The strand that puts a currency figure against the governance argument.

29 July 2026 // IBM and PonemonCorrectsAnnual study

The breach cost figure in the book is three editions out of date

The 2026 Cost of a Data Breach Report puts the global average at USD 4.99 million, a twelve percent increase year on year and the highest figure recorded across twenty one editions. The United States average reached USD 11.5 million, roughly 2.3 times the global figure. The study drew on 3,558 interviews across 602 organisations in sixteen countries and seventeen industries, covering incidents between March 2025 and February 2026. Healthcare remained the costliest industry for a thirteenth consecutive year.

Correction to the book. The Executive Brief cites an average breach cost of USD 4.45 million, which is the 2023 figure. The sequence since is 4.88 million in 2024, 4.44 million in 2025 and 4.99 million in 2026, with a United States figure of 11.5 million. Any business case built on 4.45 million understates the avoided loss side by roughly twelve percent globally and by a factor of more than two and a half for a United States exposure. If you have taken a paper to a committee using the book’s figure, it is worth reissuing the number rather than the paper.

Corrects the Executive Brief and Chapter 10. Update the assumptions sheet in the Business Case and CpCD Model.

29 July 2026 // IBM and PonemonConfirmsAnnual study

Governance moved from absent to written down, and not into a control

Sixty eight percent of breached organisations lacked AI governance to manage AI or detect its unsanctioned use, against sixty three percent the year before. The composition is the interesting part. Thirty five percent had no policies at all, down from forty one. Thirty three percent had policies still in development, up from twenty two. The share with policies actually in place fell to thirty two percent from thirty seven.

What it means for the book. This is the governance theatre thesis measured. The population did not get worse at writing policy, it got better at it, and worse at operating it: the distribution shifted into a middle state where a policy exists on a slide deck and not in a control. That is exactly the distinction the Friday Afternoon Test exists to expose, and it is the first year the annual study has produced a composition that shows it. Note the methodology caveat, that each year matches a different sample on characteristics rather than tracking the same companies, so this describes the population studied rather than a single journey.

Confirms Chapters 10 and 12, and the Friday Afternoon Test.

29 July 2026 // IBM and PonemonConfirmsAnnual study

Unapproved AI tools now figure in more than four in ten incidents

Workers using unapproved AI tools figured in forty three percent of security incidents, more than double the prior year’s share. Those incidents ended in data loss or compromise about half the time, disrupted operations in four cases out of ten, and about one in five drew a regulatory fine. Only thirty eight percent of organisations required IT approval before AI was deployed, down from forty five percent, and only nineteen percent reported coordinating their governance and security teams.

What it means for the book. Commitment Eight, that you will find the AI you did not authorize, now has a price tag and a fine rate attached. The approval figure moving the wrong way is the more troubling half: as deployment accelerated, the proportion of organisations gating it fell. The nineteen percent coordination figure is the one to take to an executive committee, because it is cheap to fix and it is the precondition for the other two.

Confirms Commitment Eight and Chapter 12. Supports the Shadow AI discovery log.

29 July 2026 // IBM and PonemonNewAnnual study

Attacks on the AI itself cost more than the average breach

Model inversion and prompt injection attacks cost organisations an average of roughly USD 6 million, above the overall average. More than one in four malicious attacks were AI driven, a fifty six percent increase year on year, with deepfake impersonation accounting for close to half of those and AI generated malware about a fifth. Regulatory non compliance was associated with costs of USD 201,112 above the global average, a figure drawn entirely from obligations already in effect. Ninety two percent of breached organisations lacked adequate access controls across human and non human identities, a category that includes API keys, service accounts and agent credentials.

What it means for the book. Three things the manuscript could not include. First, attacks aimed at the model rather than the perimeter now carry a premium, which changes the expected loss side of the Chapter 10 business case. Second, the non compliance figure is drawn from obligations already in force, which makes it usable in a paper without arguing about future regulation. Third, the ninety two percent access control figure covers non human identities explicitly, which is the closest thing yet to a market wide measurement of the Chapter 5 problem.

New material affecting Chapters 5, 10 and 11. Update the expected loss inputs in the Business Case model.

What Has Not Changed

The most expensive error available in this subject is reading a deferral as a reprieve. Everything below kept its original date or its original force.

  • The Article 5 prohibitions. In force since 2 February 2025, untouched by the Omnibus, and the list grows on 2 December 2026. A prohibited practice cannot be brought into compliance by documentation or by a later date, and it carries the highest penalty tier in the Regulation.
  • The Article 4 AI literacy duty. In force since 2 February 2025, with supervision and enforcement from 2 August 2026. It binds deployers, not only providers. Chapter 7 said the literacy timeline was unaffected and it was right.
  • Chapter V general purpose AI obligations. Applying since 2 August 2025 on the original schedule, with Commission investigation and fining powers live from 2 August 2026.
  • Article 50 transparency. Applied on 2 August 2026 as originally scheduled and enforceable now. Only the machine readable marking duty for generative systems already on the market before that date runs to 2 December 2026.
  • Article 49 registration. Including, on the prevailing reading, registration in the EU database even where a provider has concluded under the Article 6(3) filter that a system is not high risk. Treat the post amendment status of that specific requirement as an open point to confirm with counsel.
  • The general application date of the Regulation. 2 August 2026. The Omnibus did not move it.
  • The Commercial National Security Algorithm Suite calendar. New national security system acquisitions compliant by 1 January 2027, exclusive use by 2033, full quantum resistance by 2035. Unchanged and now the nearest quantum deadline for a defence supply chain.
  • The arithmetic of the shelf life test. Years available minus years needed. No development since publication changes the method, only the dates you put into it. If your confidentiality requirement exceeds the window, the exposure exists today and no future effort closes it retroactively.
  • The framework hierarchy. The Sovereignty Clock remains the headline diagnostic, the autonomy ladder remains the classification instrument, and the developments above have if anything strengthened the case for both.

Corrections to the Book

Four figures or characterisations printed in the manuscript are now wrong or too loose. They are collected here so a reader can find them in one place rather than discovering them one at a time, and so a second edition has a work list.

Swipe the table sideways to see every column.

WhereWhat the book saysThe position as at September 2026What to do
Executive Brief and Chapter 10 Average data breach cost of USD 4.45 million. That is the 2023 figure. The sequence since is 4.88 million, 4.44 million, and 4.99 million globally for 2026, with the United States at 11.5 million. Replace the figure in any live business case. Understates avoided loss by about twelve percent globally and by more than a factor of two for a United States exposure.
Chapter 7 Article 50 transparency and marking obligations “deferred by four months only, from August 2026 to December 2, 2026”. Article 50 was not deferred. It applied in full on 2 August 2026. Only the Article 50(2) machine readable marking duty, and only for generative systems already on the market before that date, runs to 2 December 2026. Read the sentence as describing the transitional rather than the article. A system placed on the market after 2 August 2026 had no grace period at all.
Chapters 2, 6 and 13 2035 as the federal post quantum migration deadline and the de facto supply chain expectation. 2035 remains the outer horizon, but Executive Order 14412 sets 31 December 2030 for key establishment and 31 December 2031 for signatures on federal high value assets, with a 2030 contractor deadline directed through the Federal Acquisition Regulatory Council. Re run the shelf life arithmetic with 2030 as the planning date if you sell to the federal government. A plan built to 2035 has five fewer years than it assumes.
Chapter 1 and Chapter 12 Gartner’s June 2025 prediction that over forty percent of agentic AI projects will be cancelled by the end of 2027. Still stands, but is now joined by a separate May 2026 prediction: by 2027, forty percent of enterprises will demote or decommission autonomous agents due to governance gaps found only after production incidents. Cite both. They describe different failures: projects abandoned before production, and agents withdrawn after it. The second is the one that validates the ladder.

One further item is an editorial matter rather than a factual correction. The opening of the Executive Overview reads “In March 2027, a Fortune 500 CIO was terminated”, a future date in the past tense. The scene is a composite and is meant as a near future illustration. A second edition should either set it in the present tense or move the date behind the publication date, because a reader who notices the year reads the rest of the page differently.

How This Page Is Maintained

Every entry is dated and sourced An undated entry is a rumour. Each one names the date, the kind of source, and the chapters it affects, so you can judge the weight to give it without taking the summary on trust.
Corrections are published, not buried Where the book is now wrong, it is listed above with the corrected position and what to do about it. Four such entries as at September 2026. On a subject where dates move, an author who hides corrections is not worth reading.
Survey figures are marked as survey figures Analyst predictions, vendor surveys and annual studies are labelled by source type. Survey data is directional. Enacted law is not. The page does not blur the two, and the annual studies match a fresh sample each year rather than tracking the same organisations.
Verify before you rely Nothing here is legal, technical or financial advice. Every date must be confirmed against the primary source, and the free Regulatory Obligation Register carries a confidence rating and a verification field against each obligation for exactly that purpose.

Test this against one of your own systems

Reading a log is not the same as knowing your position. The free tools apply the dates above to a system you name, and return the ones that have already passed.

About this page. A log of developments relevant to When Agents Rule by Steven Oppenheim, maintained after publication. It is a pointer to primary sources and not a substitute for them, and it is not legal, technical or financial advice. Dates and figures are reported as at 15 September 2026 and several have already moved once: the European high risk deadlines moved in July 2026, and the federal post quantum planning dates moved in June 2026. Analyst predictions and survey figures are the opinions and findings of the organisations named and are labelled by source type so that enacted law is not confused with forecast. Where the book is now wrong, the Corrections table above says so. Verify every date against the consolidated primary text and your own counsel before acting on it.