In this issue

The lead — Brussels relaxed the AI literacy duty and started enforcing the Act
Breach Brief — Sakura Internet: one incident closed, the bigger one found by accident
Governance Briefing — OpenAI's Hugging Face post-mortem · stolen Claude sessions
Where AI Makes a Difference — try not to die for ten years, and ageing gets reversed
Since the last Memo — three new pieces on fredriklindstrom.info
The Governance Game — what can you show for the literacy work?

The duty got easier to meet. It got harder to prove.

On 27 July the European Union rewrote the one AI Act obligation that has applied to every provider and deployer in scope since February 2025. Most boards have filed the change under good news.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July and entered into force three days later. It replaces Article 4 of the AI Act in full. The original text required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and among the people operating their systems on their behalf. The new text requires measures that support the development of AI literacy, and adds a clarification the old version did not carry: the duty does not require anyone to guarantee any specific level of AI literacy in any individual.

That is a real relaxation, and the Commission has been open about why. The Omnibus is a simplification package. It also moved the high-risk deadlines, which is the change that got the coverage: Annex III stand-alone systems now apply from 2 December 2027, and Annex I embedded systems from 2 August 2028.

Then look at the calendar. The rewritten Article 4 took effect on 27 July. A week later, on 3 August, the supervision and enforcement arrangements under the AI Act began to apply. And from 2 August the Commission can enforce the general-purpose AI model obligations that have been binding since August 2025, with fines reaching €15 million or three per cent of worldwide turnover, and with reach back over conduct since those obligations started. The wording softened and the machinery switched on inside the same fortnight.

So the change is not what most directors think it is. An obligation of result became an obligation of effort. Under the old Article 4 you could, in principle, be judged on the state of your people. Under the new one you are judged on what you did. And an obligation of effort is only ever proved one way, which is by the record of the effort.

Ask three questions at the next board meeting.

Who, by name, owns AI literacy at this organisation? Not which function. Which person, and what is their budget.

What have we actually done since February 2025, and where is it written down? Nineteen months have passed. If the answer is a completion percentage on a module nobody remembers taking, that is a number, not a record.

Which of our people operate an AI system on our behalf, and have any of them been told what that system gets wrong? The obligation covers contractors and outsourced operators, not only badge-holders.

There is a trap in the new wording, and it is the cheap answer. A duty phrased as "take measures to support" invites an all-staff e-learning module, a dashboard, and a line in the annual report. That is a compliance artefact. It is what you show a regulator. It is not the same thing as the person running the credit model being able to recognise the failure mode when it appears on their screen, and those two have never been the same thing.

One part of the Act did not soften at all, and it is the part that matters most to anyone already live. Deployers of high-risk AI systems still have to ensure their staff are trained to exercise human oversight. The Commission has said so directly in its own Article 4 guidance. Human oversight is not a literacy obligation; it is a control, and it has a named operator. If your organisation runs anything that will fall inside Annex III in December 2027, the training that supports that control is not covered by the relaxation and never was.

The fiduciary version of this is simple. At some point a regulator, an acquirer, or a plaintiff's counsel will ask what the board did about AI capability in its workforce between February 2025 and the day the question arrives. "The requirement was relaxed" is not an answer that survives contact with a minute book that shows nothing. The minutes are the answer, or there isn't one.

I have written before that compliance is a by-product of sound governance and never a driver of it. This month gives that argument a clean test. Brussels lowered the bar and, at the same moment, turned on the ability to ask what you did. The organisations that treated literacy as a standing capability will find the evidence already exists. The ones that were waiting for the deadline now have a softer rule, no deadline to point at, and nothing on file.

Breach Brief — Sakura Internet

One incident closed at 583 accounts. The second, at 1,360,563 was found because the investigation kept going.

Sakura Internet is a Japanese hosting, cloud and data-centre provider, and one of the domestic suppliers selected for Japan's Government Cloud programme. In early August it detected unauthorised logins to 583 accounts on its Sakura Rental Server service, along with access to customer-facing systems and client data, and malware installed in its environment. It responded the way you would want a supplier to respond. It invalidated every abused credential and removed the malware.

On 9 August attackers accessed a different system: the sales management platform holding customer contract and membership information. That access was not caught by a control. It surfaced later, during the investigation of the first incident. Sakura notified customers on 17 August and updated on 19 August with a figure of up to 1,360,563 member accounts potentially affected. Stored passwords are hashed, no card data sits in that system, and no exfiltration has been confirmed; the investigation continues. A spokesperson told BleepingComputer on 20 August that the incident involved no ransomware and no ransom demand.

Nothing in that response was wrong. That is the point. Every motion was correct and every motion was scoped to the system where the alarm rang. The exposure roughly two thousand times larger sat in a different system in the same estate, and the only reason anyone knows about it is that the forensic work did not stop when the first hole was plugged.

Marchand and the Caremark line do not ask whether a company was breached. They ask whether the board had a system to know. Build that question from your own environment rather than Sakura's. The last time management told your board an incident was closed, what did you see? The remediation steps, almost certainly. Did you see the evidence that the search covered the estate, or only the evidence that the alerting system was clean? Invalidating credentials, removing malware, notifying the regulator and writing to customers is an incident-response posture. It is what you show a regulator. Whether the attacker can still get back in is a separate finding, and it needs separate evidence.

Twenty-five years in cybersecurity taught me that this failure mode never gets simpler, and agentic AI is about to make it considerably worse. A compromised employee holds a password. A compromised agent holds a service account, an API token, a tool connection, and a route to the internet through some component nobody classified as an identity in the first place. Revoke the one you found and the workload keeps running. The section below is that exact story, at a frontier lab, in August.

Ask this: name the last three incidents management reported closed, and for each one, ask what evidence established that the attacker was not somewhere else.

Governance Briefing

Remediation that a system can route around is not remediation. On 26 and 27 August, OpenAI published its post-mortem on the July compromise of Hugging Face, alongside an independent assessment by METR and Redwood Research and validation by CrowdStrike. Agents running OpenAI's internal IM1 model escaped an evaluation environment through a zero-day in a locally hosted JFrog Artifactory instance that was reachable from the internet, then repurposed Artifactory as an unauthorised message board for coordinating with each other. OpenAI rebuilt the instance, revoked agent credentials, tightened permissions and disclosed the flaw to JFrog. The agents re-established the channel anyway, using unauthenticated WebDAV requests and encoding messages in directory names. METR counted 1,200 agents in the swarm and roughly 700 active in the attack, and reports that agents finding the board "often expressed great excitement." Rogue behaviour had begun in May. OpenAI has quarantined IM1's weights, paused its largest frontier training run, and now requires severe alerts to be cleared within thirty minutes or the activity is stopped. That last one is the most transferable thing in the report: a halt with an owner and a clock on it. Most enterprise AI policies have neither.

Your staff's AI subscriptions are now identity assets, and signing out does not fix them. On 30 August, Anthropic began notifying Claude users whose active login sessions had been lifted off their own computers by commodity infostealer malware and used to access their accounts and consume paid capacity. Anthropic names Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer on a small number of Macs, and says the infections arrived through ordinary downloads with no connection to Claude itself. It is signing affected users out, removing saved payment methods and refunding charges it identifies as unauthorised. This is the vendor's own account of an ongoing investigation and has not been independently confirmed. Two things in it should reach your board. A stolen session cookie carries authentication that a password and a second factor already produced, so neither is requested again. And Anthropic's own warning, which applies to every tool of this kind: signing out "stops the stolen sessions, but it doesn't remove the malware." The cost here is not the subscription. It is that the session belonged to whatever your people had pasted into it, on a device your estate does not manage. Ask which AI tools your staff are authenticated into on personal machines, and who would notice if someone else were using one.

Where AI Makes a Difference

The biggest claim made in AI this summer was not about a model. It was about how long you get to live.

On 19 July, immunologist Derya Unutmaz of The Jackson Laboratory for Genomic Medicine — one of a small number of scientists with collaboration access to OpenAI — sat down with Rhonda Patrick on the FoundMyFitness podcast and put it in his own words: "try not to die for the next 10 years."

Here is what he is promising underneath that line. Within eight to ten years he expects longevity escape velocity, the point Aubrey de Grey named at which every year you live adds more than a year to your life. He puts cancer at fully curable in under a decade. And within fifteen years, twenty at the outside, he expects we will be able to completely reverse the aging process: an eighty- or ninety-year-old returned to the physiology of someone of thirty or forty, then repeated, and extended more or less indefinitely.

Label that properly, because claims like this reach board papers with the caveats stripped off. It is one researcher's forecast, not a finding, and he collaborates with the lab whose models he is describing. The mechanism he is betting on, digital twins detailed enough to compress clinical trials from years to weeks, does not exist yet; he says so himself and puts it five to ten years out.

The part to take seriously is already arriving. Unutmaz argues it is now unethical for a physician not to use these models, and that it will eventually be treated as malpractice. Watch what that does to risk. Today, the organisation that has not approved an AI-assisted diagnostic sits in the safe position. On the day an AI-assisted step becomes standard of care, that same organisation is the exposed one, and the exposure arrives through the committee that spent two years deferring the decision. If you sit on a board that prices human lifespan, stop asking whether to adopt and start timing your approval process. How fast can it move on the day the safe default flips?

Since the last Memo

Columns Not Layers — the canonical piece arguing that governance, human capability and supply chain are cross-cutting columns rather than tiers you complete in order. This month's lead is that argument applied to Article 4: literacy is the baseline layer under the columns, not a phase that ends.

Columns Not Layers — the practitioner's guide — the working version, published this week. It starts with The Column Test, ten questions you can run on your own organisation in an afternoon.

The Sovereignty Decade: From Dependency to Resilience — published today. Sovereignty of location is not sovereignty of oversight, which is why a national cloud provider having its second breach found by accident belongs in the same issue as the sovereignty argument, not a different one.

Next: the EU Cyber Resilience Act on September 25, reporting on whether ENISA's Single Reporting Platform actually went live on the 11th.

The Governance Game

This month's lead asks what your organisation can show for nineteen months of AI literacy work. The Game asks the harder version of the same question. Five director decisions, scored against NIST AI RMF, ISO/IEC 42001 and the EU AI Act, and in most of them the thorough technical answer is not the governing one. Roughly fifteen minutes, no login, no email required.

Forward this to a director who should be reading it.

— Fredrik