Encrypted at Rest, Naked in Processing
EU-held keys, AES-256 at rest, EU region — and a US processor that holds your plaintext every time the model runs. A threat-model teardown of the standard 'sovereign AI' architecture.
Jun 12 · 13 min read
EU-held keys, AES-256 at rest, EU region — and a US processor that holds your plaintext every time the model runs. A threat-model teardown of the standard 'sovereign AI' architecture.
Jun 12 · 13 min read
China gives away frontier-grade models that the West charges for. Understanding why — and what's baked into the gift — matters for every organization choosing an AI stack.
Jun 11 · 8 min read
4 articles · ~34 min total
Start reading →2 articles · ~18 min total
Start reading →3 articles · ~30 min total
Start reading →5 articles · ~37 min total
Start reading →10 articles · ~82 min total
Start reading →Two contradictory laws, eight years, zero courtroom showdowns. The conflict everyone expects to be settled by judges is being settled somewhere else entirely.
Jun 11 · 8 min read
The PC, the OS, the inbox — scaffolding from when humans had to be the data movers. Your business is a flow now, not a desktop. The substrate moves the data; you do the deciding.
May 5 · 8 min readThe Post-Spreadsheet Business · 2
For 47 years, business has been organized around the cell. AI ends that — not because spreadsheets got faster, but because computers can now make the judgment calls that were the only reason humans had to be in the loop at all.
May 5 · 8 min readThe Post-Spreadsheet Business · 1
Three capability buckets — deterministic, judgment-with-context, human-only. Map every role to a bucket and your headcount plan changes shape.
May 5 · 8 min readThe Post-Spreadsheet Business · 3
Your SOP doc has been in Confluence for three years; two people have read it. The new SOP is a flow that runs itself and pages a human only at the judgment moments.
May 5 · 10 min readThe Post-Spreadsheet Business · 4
The encrypted data you send today gets decrypted the moment a quantum computer is large enough — not the moment you decide to migrate. Here's what's actually standardized, what to ask your vendors, and why hybrid mode is the migration step to take this year.
Apr 30 · 9 min read
Why LVDR ships XChaCha20-Poly1305 instead of AES-256-GCM, runs envelope encryption with a device-keypair root, and has no password-derived key anywhere — eight design decisions reasoned from the constraints, not the textbook.
Apr 30 · 12 min read
A CEO's guide to the infrastructure, compliance, and risk decisions behind deploying AI safely on private company data.
Apr 13 · 8 min readEnterprise AI Infrastructure · 2
AI research assistants reset every session and treat blog posts like peer-reviewed papers. Here's what a knowledge system that actually learns would look like.
Apr 13 · 9 min readBuilding Smarter AI Research · 2
A CTO's guide to the nine infrastructure layers between 'spin up a model' and 'run it safely on private data' — with specific tools, architectures, and failure modes.
Apr 13 · 10 min readEnterprise AI Infrastructure · 1
A technical deep-dive into LumaVista's unified knowledge system — from merge-on-write dedup to four-layer trust assessment to token-budgeted context injection.
Apr 13 · 12 min readBuilding Smarter AI Research · 3
Subsidize, accumulate, integrate, reprice. You've seen this playbook before — with Oracle, AWS, and Salesforce. Now frontier AI labs are running it on your reasoning processes.
Apr 12 · 9 min read
AI has been doing useful work since 1965. The race to build one model that does everything is valuable research — but it's the wrong strategy for companies that need results today.
Apr 12 · 9 min read
The BIGMAS paper applies neuroscience's Global Workspace Theory to multi-agent AI. Here's what that means for building research systems that don't waste a third of their compute.
Apr 5 · 9 min readBuilding Smarter AI Research · 1
Third-party inference proxies are a privacy and operational liability. Here's why we replaced LiteLLM with Meridian — a Go-native gateway with priority queuing, capability routing, and EU-sovereign GPU fleet management.
Apr 5 · 10 min read
Five overlapping EU laws govern how you run AI privately. Here's what GDPR, the AI Act, Data Act, NIS2, and CADA actually require — and what's coming next.
Mar 23 · 10 min read
Renting a GPU from a US company in an EU data center doesn't make your AI workloads sovereign. Here's what the CLOUD Act means for your 'self-hosted' LLM.
Mar 23 · 8 min read
Research agents aren't one model doing everything — they're a team of specialists. Here's how to pick the right open model for each role.
Mar 23 · 10 min read
ChatGPT answers your question. An agent plans how to find the answer, executes that plan across multiple tools, checks its own work, and delivers a verified result. The difference is categorical.
Mar 22 · 9 min read
Not every query needs sovereign infrastructure. A four-level framework for deciding which AI tools are appropriate — from public data to legally privileged information.
Mar 22 · 7 min read
Your health queries reveal diagnoses. Your financial queries reveal wealth. Your legal queries reveal disputes. Personal research deserves personal sovereignty.
Mar 22 · 9 min readWorking Smarter with AI · 4
Pure AI is brilliant but unreliable. Pure code is reliable but rigid. The winning architecture combines both — AI for understanding, deterministic code for enforcement.
Mar 22 · 9 min read
AI is a probability engine, not a calculator. Learn the four levels of prompting — and why multi-agent systems make them all obsolete.
Mar 22 · 7 min readWorking Smarter with AI · 2
Every AI research query you send to a US provider is legally accessible to US authorities. Here's what the CLOUD Act and FISA 702 actually mean for European organizations.
Mar 22 · 9 min read
The real bottleneck in AI quality isn't the prompt — it's the context. Documents, memory, tools, constraints. Getting context right matters 10x more than getting the prompt right.
Mar 22 · 9 min read
Your data is in an EU data center. That doesn't make it sovereign. Here's why the distinction matters — and how to tell the difference.
Mar 22 · 7 min read
The Digital Operational Resilience Act makes every US-hosted AI tool a potential compliance finding. Here's what your CCO needs to know about Article 28.
Mar 22 · 9 min read
Most people either avoid AI or use it for everything. Both are wrong. The DRAG framework shows you which tasks to delegate and which to obsess over.
Mar 22 · 7 min readWorking Smarter with AI · 1
The EU AI Act's transparency duties apply from August 2, 2026 — but the May 2026 Digital Omnibus pushed the high-risk obligations to late 2027 and 2028. If you use AI for legal research, financial compliance, or medical analysis, here's what the new timeline means for you.
Mar 22 · 9 min read
AWS, Azure, and Google all say 'sovereign.' We tear down what each actually promises — and what the CLOUD Act still reaches.
Mar 22 · 10 min read
Two laws, directly contradictory, both in force. A US company served with a CLOUD Act warrant for EU data must choose: violate GDPR or face contempt. Nobody has resolved this.
Mar 22 · 7 min read
Most AI tools think linearly: one prompt, one response. Graph-based AI decomposes questions into parallel subtasks, cross-references findings, and produces research you can actually audit. Here's how DAGs change everything.
Mar 22 · 9 min read
AI-assisted legal research creates privilege and confidentiality risks that Westlaw and LexisNexis never did. Your query reveals more than the answer.
Mar 22 · 9 min read
University researchers routinely paste patient-adjacent data into ChatGPT. Most don't realize this creates GDPR Article 9 exposure, CLOUD Act access for US authorities, and potential clinical trial integrity violations.
Mar 22 · 9 min read
Five independent model families now compete at the frontier. The 'but closed models are better' objection to sovereign AI is gone.
Mar 22 · 7 min read
Everyone says prompt engineering is dead. They're wrong — the skill just evolved from hacking token sequences to briefing a reasoning system.
Mar 22 · 9 min read
Stop asking AI one question at a time. Build research workflows with triggers, schedules, and compound knowledge that turn AI from a tool into infrastructure.
Mar 22 · 7 min readWorking Smarter with AI · 5
GPU servers, VRAM requirements, inference engines, and costs. A practical decision framework for CTOs evaluating self-hosted vs API-based AI.
Mar 22 · 9 min read
Most enterprise AI usage is unsanctioned. Banning it pushes usage underground. Here's how to move from prohibition to governed adoption.
Mar 22 · 7 min read
Most AI tools cite sources but don't evaluate them. What does trust, recency, and corroboration scoring actually mean — and how does it catch hallucinated citations?
Mar 22 · 7 min read
Safe Harbor. Privacy Shield. Data Privacy Framework. Three attempts to bridge FISA 702 with GDPR — three failures. Here's why the pattern repeats, and what to do about it.
Mar 22 · 9 min read
AI can make you dangerously smart or dangerously dependent. The difference is whether you outsource your thinking or use AI as a sparring partner to sharpen it.
Mar 22 · 7 min readWorking Smarter with AI · 3
Most AI tools use one model for everything. That wastes money on simple tasks and underperforms on hard ones. Here's why multi-model architectures are faster, cheaper, and better.
Mar 22 · 7 min read
How the LumaVista Companion App puts encryption keys on your phone — not our servers — so your research stays yours.
Mar 14 · 5 min read
We're opening LumaVista to a small group of early users. Here's what to expect.
Mar 14
AI moves fast. Here's how to keep your knowledge current and help others do the same.
Mar 13 · 8 min readAI Safety Education · 10
Building AI governance that actually works — practical frameworks for compliance, risk management, and organizational accountability.
Mar 6 · 10 min readAI Safety Education · 9
How Model Context Protocol and AI integrations create new security risks — and what to do about them.
Feb 27 · 9 min readAI Safety Education · 8
The security and IP risks developers face when using AI coding tools — and how to use them responsibly.
Feb 13 · 8 min readAI Safety Education · 7
Practical guidelines for using AI at work — what to share, what to protect, and what your organization needs to get right.
Jan 30 · 10 min readAI Safety Education · 6
What parents need to know about AI and children — from homework helpers to social media algorithms.
Jan 16 · 8 min readAI Safety Education · 5
Your AI assistant knows a lot about you. Here's how to use it productively without oversharing.
Dec 30 · 7 min readAI Safety Education · 4
Practical prompting techniques that improve AI output quality and keep your data safe.
Dec 12 · 8 min readAI Safety Education · 3
AI makes mistakes more often than you think. Here's how to spot errors, check facts, and avoid trusting the wrong output.
Nov 28 · 8 min readAI Safety Education · 2
How AI systems collect, store, and use your personal data — and simple steps to protect yourself.
Nov 14 · 6 min readAI Safety Education · 1