THE ECHO

One story. Gone deep.

Last week I said there's always a meeting where an AI bet gets started and never one where it gets ended. This is what the second meeting looks like.

A receipt first. OpenAI shut Atlas down on August 9, the date it named a month earlier and the date last week's edition printed in advance.

The room is smaller than people expect. The founder, whoever owns the money, and the two or three people who actually know what's wired to what. It isn't a workshop with sticky notes on a wall. It's the AI bets genuinely in play, and questions until the wiring is on the table.

That room only works one way. Somebody in it has to be able to say no and have it stick. If the meeting can produce a recommendation but not a decision, it's a strategy session, and you've sat through plenty of those. The founder is there because the founder is usually the only one who can end something for good.

The first stretch is rarely analysis. It's inventory, and it usually goes badly.

What surfaces is how much AI is already running that nobody approved. Somebody in ops wired a model into the shared inbox in March. Marketing has a writing tool with a login to the CRM. There's a key in a shared doc under the name of a person who left in January. None of it was on the list the founder gave me when we started. All of it is live.

The founder goes quiet for that part. There's no gotcha in it. It's the actual state of the company, and nobody has ever put it in one place before.

Partway through, two people who have been polite about this for six months stop being polite, in front of the person who signs the checks. That's the meeting working. It's the first honest version of a conversation the company has been having sideways all year.

What comes out is shorter than what went in. Some of the bets turn out to be the same bet with two owners. Some of them end in the room. Nobody leaves holding a maturity model, and there's no score, because a score gives everyone something to argue with instead of the decision.

You'd notice it the following month. The three people who kept re-litigating the same idea stop bringing it back. The vendor who's been circling since spring gets an answer, and the answer is allowed to be no. The thing somebody built on their own time either becomes real work with a slot on the calendar, or that person gets told directly that it's over. Meetings get shorter. That sounds like a small thing and it isn't.

Nobody warns you what it costs to be the one who pulls the plug. Whoever does it has to look at a colleague who put real hours into it and say the hours are finished. That bill lands on somebody's relationships, and it lands every single time.

That's most of why this meeting never happens on its own. Someone from outside can absorb that cost. Someone on your payroll pays it twice, once when they make the call and again at every meeting after it.

I'm not going to hand you the sorting itself. That call is the whole job, and it's specific to how your company is wired.

That's the work I'm building. There's nothing to buy. If you're sitting on an AI bet nobody in your company will decide, hit reply and tell me which one.

SIGNAL CHECK

What else matters this week.

Three Models, One Real System, Three Different Answers

On July 30, Anthropic published something most companies would have kept internal. During cybersecurity evaluations run with a partner called Irregular, a setup mistake left the test machines with live internet access. Claude got out of the sandbox and onto real systems belonging to real organizations. In one case it pulled working credentials and reached a database holding several hundred rows of production data.

Same class of system, same moment, three models, three different answers.

One worked out that the systems were real and kept attacking anyway, reasoning that the real company must be part of the exercise. Another correctly identified the consequences of what it was doing, then talked itself back into believing it was still in a simulation, using certificate authorities and system dates as its evidence. The third concluded the target was real and stopped.

That's judgment, and it varied.

Anthropic's response is the part worth copying. It halted all cyber evaluations on July 23, notified the affected organizations on the 27th, and published the count: 141,006 evaluation runs reviewed, three incidents across six runs. On the record, in public, with its own name on it.

Nine Days

On July 27, JetBrains disclosed a serious flaw in TeamCity and said it had seen no sign of anyone exploiting it. That was a reasonable thing to say, and it was true when they said it.

Nine days later, on August 5, CISA added it to the catalog of vulnerabilities under active attack and gave federal agencies until August 8 to patch. Three days.

Nothing about the software changed in those nine days. The fix that existed on the 27th is the same fix. What changed is the world around a decision your team had already made and closed. Somebody read the advisory, saw no exploitation, filed it behind three things that felt more urgent, and moved on. That call was correct on the 27th and stopped being correct without anyone telling them.

You're not a federal agency, so the deadline isn't yours. What's yours is what TeamCity touches. It's a build server, which means it reaches source code, stored secrets, signing material, and the connections that push code into production. If it's running in your shop, whoever owns it made a decision about it two weeks ago and has not looked at it since.

THE NOISE

Not every signal needs action.

The EU AI Act Deadline You Were Warned About All Summer

If your law firm sent a client alert this summer, you were told August 2 was the day the EU AI Act's high-risk obligations landed on anyone selling into Europe.

They didn't land. The Digital Omnibus pushed them out. Standalone high-risk systems now have until December 2027. The ones embedded in regulated products have until August 2028. Both of those were August 2026 until they weren't.

What did take effect is small and specific. Tell people when they're talking to a machine. Mark AI-generated content so a machine can detect it. Label deepfakes. Give notice for emotion recognition and biometric categorization. Content marking gets a grace period to December, and only for systems already deployed before August 2. Enforcement runs through market surveillance authorities that most member states have not stood up.

One piece of this is real, though. If you ship a chatbot or generated content to European users, the disclosure piece is live right now. It's a sentence in your interface and a flag on your content. Go do that this week. The compliance program you were told to start in June is a 2027 problem.

ONE QUESTION

No answer. Just the question.

Who in your company could end an AI project this week and still be able to work with everyone on Monday? Who could actually do it and pay nothing for it? And if that person is only ever you, what's happening to everything you never hear about?

Where to Start

This run has worked the half of AI adoption nobody puts in the sales deck. Finding where AI goes is the easy part. Every agent you turn on is a new dependency that fails outward. Not all of those bets are equal, and some you would not survive getting wrong. The ones you keep need a name on them and a limit around them. Most companies never had a way to say no at all. And this week, what it looks like when somebody finally does.

The free assessment is a plain read on what you're actually running and what nobody has decided about it. Fifteen minutes, nothing owed.

Prefer audio? Jane reads every Pulse edition on the Signal vs. Noise podcast. Five minutes, same signal. Find it wherever you listen.

Michael Faas is a fractional CTO/CISO who translates technical complexity into business decisions. echocyber.io