All posts by Avery Cross

AI Vulnerabilities in Government Systems

AI vulnerabilities in U.S. government systems became a sharper public concern after a June 23, 2026 report that Anthropic’s Mythos model identified weaknesses in highly sensitive government computer systems during a testing exercise. The reported facts are narrow but significant: the model found vulnerabilities within hours, the exercise involved Project Glasswing and U.S. intelligence agencies, and the model did not exploit the systems during that timeframe, according to The Washington Read the rest

AI Data Security Guidance for Developers

AI Data Security moved from general risk language into concrete developer work on May 22, 2025, when the NSA’s Artificial Intelligence Security Center jointly released a Cybersecurity Information Sheet on securing data used to train and operate AI systems. The release was co-authored with CISA, the FBI, Australia’s ACSC, New Zealand’s NCSC-NZ, and the UK’s NCSC-UK, according to the NSA announcement.

For AI developers, the practical value is that … Read the rest

AI Distillation Risks Workshops for Security Teams

AI distillation risks are now appearing in workshop agendas beside agentic AI, model integrity, AI infrastructure security, and standards work. As of September 17, 2026, only some of the events identified in the research remain ahead on the calendar, so teams should separate genuine late-2026 opportunities from sessions that have already concluded.

The topic also needs careful wording. The available event descriptions do not show that the listed workshops are … Read the rest

Network Tomography Telecom: What Orange Trial Proved

Network tomography telecom moved from laboratory promise to live service-provider testing in France this month. Nokia and Orange France say a September 10 trial on Orange’s optical transport network produced near-real-time, link-by-link visibility using data already generated by coherent optical transmissions, pointing toward a different way to find physical-layer problems before customers feel them.

The significance is operational. Telecom networks are already moving toward automated assurance, predictive maintenance, and AI-assisted … Read the rest

FERC Physical Security Standard: CIP-014-4

The FERC Physical Security Standard changed on September 10, 2026, when the Federal Energy Regulatory Commission approved Reliability Standard CIP-014-4, replacing CIP-014-3 for physical security of certain Bulk Electric System facilities. FERC’s September 2026 meeting summary identified the approval under Order RD26-9-000 FERC meeting summary. The practical effect is not immediate operational enforcement, because CIP-014-4 has an effective date of October 1, 2028, but the lead time matters for … Read the rest

EPA Data Center Rules: Technical Changes

EPA Data Center Rules changed in several procedural areas during 2026, with the most visible shift affecting how air permits for smaller pollution sources may be noticed, reviewed, and challenged. The changes did not rewrite federal emission limits in the research record provided here. They did, however, alter the process around permitting, construction sequencing, and certain power configurations that can matter for communities hosting large compute campuses.

The technical issue … Read the rest

Data Center Regulation Stakeholder Planning

Data Center Regulation is becoming a practical planning issue for event teams that support public agencies, operators, utilities, workers, and community groups. The regulatory discussion is no longer limited to technical energy efficiency targets. It now includes reporting duties, permitting conditions, community input, public health concerns, grid cost allocation, and documented consultation.

For an industry event specialist, that shift changes the purpose of a workshop. A useful session cannot be … Read the rest

AI Transparency Act: Compliance After Aug. 2026

The AI Transparency Act is now an operative compliance issue for covered generative AI providers in California, not a distant policy proposal. As of August 2, 2026, SB 942, as amended by AB 853, applies to businesses that create, code, or produce covered public generative AI systems and meet the law’s user threshold. For engineering, legal, trust and safety, product, and standards teams, the practical question is no longer whether … Read the rest

Cyberattack Reports: Prepare Your Organization

Cyberattack Reports from 2025 and 2026 point to a practical management problem: organizations are not only facing more incidents, they are also facing broader recovery demands, higher notification volumes, and a skills burden that reaches beyond security teams. For telecom operators, vendors, managed service providers, and enterprise IT groups, the lesson is not panic. It is disciplined preparation based on what the reports actually show.

The strongest evidence in the … Read the rest

Data Center Energy Actions for Local Stakeholders

Data center energy has become a local governance issue, not only a utility planning topic. Communities asked to host large computing facilities are now weighing grid capacity, ratepayer exposure, tax incentives, land use, water and cooling concerns, backup generation, emergency services, and public trust. For local organizers, the most useful first step is not a protest plan or a press statement. It is a shared evidence base that residents, utilities, … Read the rest