❌

Reading view

GAO report shows gap between scale of illegal vapes and enforcement 

With thousands of illegal e-cigarettes for sale in the U.S., both the Trump and Biden administrations have vowed to crack down on the illicit fruit- and candy-flavored vapes that hold particular appeal to minors. But a new government report suggests law enforcement efforts by the Department of Justice lag far behind the scope of the problem. 

Most DOJ enforcement actions between fiscal year 2022 and fiscal year 2025 — 50 out of a total of 88 — were to add the names of remote e-cigarette sellers to a list of unauthorized businesses, according to the report from the Government Accountability Office. The second-most common type of enforcement actions (20 out of 88) noted in the report were injunctions to stop legal violations. 

Read the rest…

© Stephanie Keith/Getty Images

  •  

STAT+: Replimune skin cancer drug that became FDA flashpoint is rejected again

The Food and Drug Administration on Friday rejected — again — an experimental treatment for advanced skin cancer developed by Replimune Group. 

Replimune’s treatment, an engineered virus designed to rev up the immune system against melanoma, has been a flashpoint in a simmering debate over shifting standards at the agency.

The drug was initially rejected in July, just two months after Vinay Prasad was appointed the FDA’s head of biologics. As an academic oncologist, Prasad criticized regulators for approving drugs with limited data, and the Replimune decision was viewed as a possible sign of the stricter stance he might take at the agency.

Continue to STAT+ to read the full story…

© Markus Schober and Elaine Fuchs, The Rockefeller University/NIH

  •  

IBM: How robust AI governance protects enterprise margins

To protect enterprise margins, business leaders must invest in robust AI governance to securely manage AI infrastructure.

When evaluating enterprise software adoption, a recurring pattern dictates how technology matures across industries. As Rob Thomas, SVP and CCO at IBM, recently outlined, software typically graduates from a standalone product to a platform, and then from a platform to foundational infrastructure, altering the governing rules entirely.

At the initial product stage, exerting tight corporate control often feels highly advantageous. Closed development environments iterate quickly and tightly manage the end-user experience. They capture and concentrate financial value within a single corporate entity, an approach that functions adequately during early product development cycles.

However, IBM’s analysis highlights that expectations change entirely when a technology solidifies into a foundational layer. Once other institutional frameworks, external markets, and broad operational systems rely on the software, the prevailing standards adapt to a new reality. At infrastructure scale, embracing openness ceases to be an ideological stance and becomes a highly practical necessity.

AI is currently crossing this threshold within the enterprise architecture stack. Models are increasingly embedded directly into the ways organisations secure their networks, author source code, execute automated decisions, and generate commercial value. AI functions less as an experimental utility and more as core operational infrastructure.

The recent limited preview of Anthropic’s Claude Mythos model brings this reality into sharper focus for enterprise executives managing risk. Anthropic reports that this specific model can discover and exploit software vulnerabilities at a level matching few human experts.

In response to this power, Anthropic launched Project Glasswing, a gated initiative designed to place these advanced capabilities directly into the hands of network defenders first. From IBM’s perspective, this development forces technology officers to confront immediate structural vulnerabilities. If autonomous models possess the capability to write exploits and shape the overall security environment, Thomas notes that concentrating the understanding of these systems within a small number of technology vendors invites severe operational exposure.

With models achieving infrastructure status, IBM argues the primary issue is no longer exclusively what these machine learning applications can execute. The priority becomes how these systems are constructed, governed, inspected, and actively improved over extended periods.

As underlying frameworks grow in complexity and corporate importance, maintaining closed development pipelines becomes exceedingly difficult to defend. No single vendor can successfully anticipate every operational requirement, adversarial attack vector, or system failure mode.

Implementing opaque AI structures introduces heavy friction across existing network architecture. Connecting closed proprietary models with established enterprise vector databases or highly sensitive internal data lakes frequently creates massive troubleshooting bottlenecks. When anomalous outputs occur or hallucination rates spike, teams lack the internal visibility required to diagnose whether the error originated in the retrieval-augmented generation pipeline or the base model weights.

Integrating legacy on-premises architecture with highly gated cloud models also introduces severe latency into daily operations. When enterprise data governance protocols strictly prohibit sending sensitive customer information to external servers, technology teams are left attempting to strip and anonymise datasets before processing. This constant data sanitisation creates enormous operational drag. 

Furthermore, the spiralling compute costs associated with continuous API calls to locked models erode the exact profit margins these autonomous systems are supposed to enhance. The opacity prevents network engineers from accurately sizing hardware deployments, forcing companies into expensive over-provisioning agreements to maintain baseline functionality.

Why open-source AI is essential for operational resilience

Restricting access to powerful applications is an understandable human instinct that closely resembles caution. Yet, as Thomas points out, at massive infrastructure scale, security typically improves through rigorous external scrutiny rather than through strict concealment.

This represents the enduring lesson of open-source software development. Open-source code does not eliminate enterprise risk. Instead, IBM maintains it actively changes how organisations manage that risk. An open foundation allows a wider base of researchers, corporate developers, and security defenders to examine the architecture, surface underlying weaknesses, test foundational assumptions, and harden the software under real-world conditions.

Within cybersecurity operations, broad visibility is rarely the enemy of operational resilience. In fact, visibility frequently serves as a strict prerequisite for achieving that resilience. Technologies deemed highly important tend to remain safer when larger populations can challenge them, inspect their logic, and contribute to their continuous improvement.

Thomas addresses one of the oldest misconceptions regarding open-source technology: the belief that it inevitably commoditises corporate innovation. In practical application, open infrastructure typically pushes market competition higher up the technology stack. Open systems transfer financial value rather than destroying it.

As common digital foundations mature, the commercial value relocates toward complex implementation, system orchestration, continuous reliability, trust mechanics, and specific domain expertise. IBM’s position asserts that the long-term commercial winners are not those who own the base technological layer, but rather the organisations that understand how to apply it most effectively.

We have witnessed this identical pattern play out across previous generations of enterprise tooling, cloud infrastructure, and operating systems. Open foundations historically expanded developer participation, accelerated iterative improvement, and birthed entirely new, larger markets built on top of those base layers. Enterprise leaders increasingly view open-source as highly important for infrastructure modernisation and emerging AI capabilities. IBM predicts that AI is highly likely to follow this exact historical trajectory.

Looking across the broader vendor ecosystem, leading hyperscalers are adjusting their business postures to accommodate this reality. Rather than engaging in a pure arms race to build the largest proprietary black boxes, highly profitable integrators are focusing heavily on orchestration tooling that allows enterprises to swap out underlying open-source models based on specific workload demands. Highlighting its ongoing leadership in this space, IBM is a key sponsor of this year’s AI & Big Data Expo North America, where these evolving strategies for open enterprise infrastructure will be a primary focus.

This approach completely sidesteps restrictive vendor lock-in and allows companies to route less demanding internal queries to smaller and highly efficient open models, preserving expensive compute resources for complex customer-facing autonomous logic. By decoupling the application layer from the specific foundation model, technology officers can maintain operational agility and protect their bottom line.

The future of enterprise AI demands transparent governance

Another pragmatic reason for embracing open models revolves around product development influence. IBM emphasises that narrow access to underlying code naturally leads to narrow operational perspectives. In contrast, who gets to participate directly shapes what applications are eventually built. 

Providing broad access enables governments, diverse institutions, startups, and varied researchers to actively influence how the technology evolves and where it is commercially applied. This inclusive approach drives functional innovation while simultaneously building structural adaptability and necessary public legitimacy.

As Thomas argues, once autonomous AI assumes the role of core enterprise infrastructure, relying on opacity can no longer serve as the organising principle for system safety. The most reliable blueprint for secure software has paired open foundations with broad external scrutiny, active code maintenance, and serious internal governance.

As AI permanently enters its infrastructure phase, IBM contends that identical logic increasingly applies directly to the foundation models themselves. The stronger the corporate reliance on a technology, the stronger the corresponding case for demanding openness.

If these autonomous workflows are truly becoming foundational to global commerce, then transparency ceases to be a subject of casual debate. According to IBM, it is an absolute, non-negotiable design requirement for any modern enterprise architecture.

See also: Why companies like Apple are building AI agents with limits

Banner for AI & Big Data Expo by TechEx events.

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post IBM: How robust AI governance protects enterprise margins appeared first on AI News.

  •  

Trump administration admits a glaring error in its accusations about New York health care fraud

NEW YORK — President Donald Trump’s administration this week acknowledged it made a significant error in figures it used to help justify a fraud probe into New York’s Medicaid program, a glaring mistake that undercuts a federal campaign to tackle waste, mostly in Democratic-led states.

The error, one of at least a few misrepresentations in its description of the program, prompted health analysts to question how many of the Republican administration’s sweeping anti-fraud efforts around the country were based on faulty findings. It also reflected a common criticism that’s been made of Trump’s second administration — that it tends to attack first and confirm the facts later.

Read the rest…

© Tom Brenner/AP

  •  

STAT+: A new trick for old science, and biotech VCs’ scrambled playbook

Want to stay on top of the science and politics driving biotech today? Sign up to get our biotech newsletter in your inbox.

CAR-T therapies are continuing to gain traction in autoimmune disease, with a notable new case.

Also, the FDA has withdrawn approval of GSK’s leucovorin for a rare brain disorder tied to autism, closing out an unusual episode shaped in part by political pressure.

Continue to STAT+ to read the full story…

© Adobe

  •  

STAT+: Pharmalittle: We’re reading about cheap generic obesity drugs in India, high demand for estrogen patches and more

And so, another working week will soon draw to a close. Not a moment too soon, yes? This is, you may recall, our treasured signal to daydream about weekend plans. Our agenda includes promenading with the official mascots, escorting Mrs. Pharmalot to a musical happening and visiting a new eatery. We also hope to have yet another listening party, where the rotation will include this, this, this, this and this. And what about you? This may be an opportunity to enjoy the great outdoors, perhaps a stroll by the seashore or a walk in the woods. A long drive in the country may be nice, although it will cost you. Or perhaps simple pleasures such as noshing on a pastry with a hot cup of stimulation will do. You could also catch up on your reading or reach out to someone special. Well, whatever you do, have a grand time. But be safe. Enjoy, and see you soon…

A flood of cheap copies of Novo Nordisk’s blockbuster weight-loss drug in India is already reshaping the country’s fast-growing obesity medicine market, showing how quickly the patent cliff will affect GLP-1 makers like Eli Lilly, Bloomberg News explains. Within days of dozens of generics hitting the Indian market after Novo’s patent expired locally, the drug’s share in the country’s GLP-1 segment jumped to 33% in March from 25% a month earlier, according to researcher Pharmarack. That gain came at the expense of Lilly’s Mounjaro, which is still under patent protection in India and whose share fell to 64% from 71%. The data marks the first meaningful snapshot of how market dynamics will change for GLP-1 makers as their patents near expiry.

The U.S. Food and Drug Administration withdrew approval of a GSK drug that the Trump administration had promoted as a treatment for autism, adding another twist to the unusual story of a decades-old drug, Bloomberg News informs us. The agency is pulling its approval of Wellcovorin, a branded version of leucovorin from GSK, according to a post in the Federal Register. GSK had requested that the approval be withdrawn. The FDA first approved leucovorin decades ago and it has been used to blunt the side effects of chemotherapy for some cancer patients. In September, Trump administration officials endorsed leucovorin as an autism treatment. Last month, the FDA approved its use for cerebral folate deficiency, which is seen in some people with autism.

Continue to STAT+ to read the full story…

© Alex Hogan/STAT

  •  

STAT+: GSK says goodbye to leucovorin (again)

Get your daily dose of health and medicine every weekday with STAT’s free newsletter Morning Rounds. Sign up here.

Buyer beware: If you are an avid consumer of WAP Sensual Enhancement, the Food and Drug Administration says the pill “may be harmful.”

Want to learn about other dubious products under federal scrutiny? Scroll down.

Continue to STAT+ to read the full story…

© JUSTIN TALLIS/AFP via Getty Images

  •  

Why companies like Apple are building AI agents with limits

Next-generation AI assistants being developed in the Apple ecosystem and by chipmakers like Qualcomm, but early reports suggest they are being designed with limits in place.

Tom’s Guide has described early versions of these assistants as capable of navigating apps, carrying out bookings, and managing tasks in services. For instance a private beta agentic system completed tasks like booking services or posting content in apps. In one test, it moved through an app workflow and reached a payment screen before asking the user for confirmation.

AI agents are being built with approval checkpoints. Sensitive actions, especially those tied to payments or account changes, require user confirmation before they are completed. The “human-in-the-loop” model lets the system prepare an action, but leaves approval to the user. Research linked to Apple’s AI work has explored ways to ensure systems pause before taking actions users did not explicitly request.

Banking apps already require confirmation for transfers. The same idea is now being applied to AI-driven actions in multiple services.

Limits and control

A control layer comes from restricting what the AI can access. Rather than providing the system full access to apps and data, businesses are establishing limits, such as which apps the AI can interact with and when actions can be triggered.

In practice, this means the AI may be able to draft a purchase or prepare a booking, but not finalise it without approval. It also means the system cannot move freely in all services unless it has been granted permission.

According to Tom’s Guide, the facility is for privacy. If data remains on the device, it eliminates the need to send sensitive information to external servers.

In areas like payments, AI systems are expected to work with partners that already have strict rules in place. In one reported example, payment providers’ services are being integrated to provide secure authentication before transactions are completed, though such safeguards are still under development. The existing systems act as an additional layer of oversight. They can set transaction limits or require extra verification.

Much of the discussion around AI governance has focused on enterprise use. That includes areas like cybersecurity and large-scale automation. The consumer side introduces a different challenge and companies must design controls that work for everyday users. That means clear approval steps and built-in privacy protections.

Autonomy with boundaries

As AI gains the ability to carry out actions, the risks become greater as errors can lead to financial loss or data exposure.

By placing controls at multiple points, including approval and infrastructure, companies are trying to manage those risks.

The approach may shape how agentic AI develops in the near term. Rather than aiming for full independence, companies appear focused on controlled environments where the risks can be managed.

(Photo by Junseong Lee)

See also: Agentic AI’s governance challenges under the EU AI Act in 2026

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post Why companies like Apple are building AI agents with limits appeared first on AI News.

  •  

How sports betting apps hook users

For most of the last 80 years, sports betting was limited to Las Vegas. But after a 2018 Supreme Court decision loosened regulations on professional sports wagers, it became possible to place bets on games 24/7 — with nothing more than a smartphone and a bank account. 

In 2013, just five years prior to the landmark SCOTUS case, gambling was classified in the Diagnostic and Statistical Manual of Mental Disorders (DSM-5) in a new category called “Substance-Related and Addictive Disorders.” This grouped gambling with alcohol use disorder and other addictions. Gambling is also known to have the highest suicide rate of any addiction.

Read the rest…

  •  

Opinion: What public health can learn from the MAHA movement

I didn’t expect to find myself face to face with leaders and activists from the “Make America Healthy Again” movement in respectful dialogue, or to consider inviting one into a public health classroom. But that’s exactly where I found myself this spring.

At a national public health meeting in March, I attended a session that brought together public health professionals, physicians, and MAHA leaders for a rare, good-faith conversation. I went out of curiosity. I left with a level of clarity I hadn’t expected — and a few unexpected connections.

Read the rest…

© John Moore/Getty Images

  •  

Opinion: I’m a MAHA activist. I went into the public health lion’s den — and it changed how I think

The past few weeks have been nothing but discouraging for those of us who helped create the Make America Healthy Again movement, including a silly executive order on glyphosate that feels anathema to what we have fought for. I’d be lying if I said that my heart hasn’t been bent toward repentance for my part in the whole thing. I helped champion Bobby Kennedy as a campaign volunteer, and when he joined up with then-candidate Donald Trump, I reluctantly decided that the trade-offs were worth what I believed Kennedy could advocate for within the walls of a Trump White House: the best fixes for a very sick and broken nation. 

Yet I found myself recently, and reluctantly, headed to the citadel of arrogance: Washington (well, Arlington, Va., to be more specific). At the invitation of Brinda Adhikari — one of the hosts of the podcast “Why Should I Trust You?” — I attended the Association of Schools and Programs of Public Health’s annual meeting, where I spoke on a panel about engaging in civil conversation in a session called “A Dialogue Between Academic Public Health and MAHA.”

Read the rest…

© Adobe

  •  

Meta has a competitive AI model but loses its open-source identity

The open-source AI movement has never lacked for options. Mistral, Falcon, and a growing field of open-weight models have been available to developers for years. But when Meta threw its weight behind Llama, something shifted. A company with three billion users, vast compute resources, and the credibility of a tech giant was now building openly, and the developer community responded.

By early 2026, the Llama ecosystem had reached 1.2 billion downloads, averaging about 1 million per day. That is the context for what happened on April 8, 2026. Meta launched Muse Spark, its first major new Meta AI model in a year, and the first product from its newly formed Meta Superintelligence Labs.

It is capable in ways Llama 4 never was, benchmarks well against the current frontier, and is completely proprietary. No free download. No open weights. No building on it unless Meta decides you can.

The companyspentUS$14.3 billion, brought in Alexandr Wang from Scale AI to lead its AI rebuild, then spent nine months tearing down its entire AI stack and starting over. Muse Spark is what came out the other side. The developer community that made Llama what it was is now being asked to wait for a future open-source version that may or may not arrive on any predictable timeline.

What is Muse Spark?

Muse Spark is a natively multimodal reasoning model with tool-use, visual chain of thought, and multi-agent orchestration built in. It now powers Meta AI, which reaches over three billion users in Meta’s apps. Meta rebuilt its technology infrastructure from scratch, letting the company create a model that is as capable as its older midsize Llama 4 variant for an order of magnitude less compute.

That efficiency number is worth noting. At the scale Meta operates, compute costs compound fast, and running a frontier-class Meta AI model at a fraction of the cost of its predecessors changes the economics of deploying it in billions of interactions daily.

On benchmarks, the picture is genuinely mixed. Muse Spark scores 52 on the Artificial Intelligence Index v4.0, placing it fourth overall behind Gemini 3.1 Pro, GPT-5.4, and Claude Opus 4.6. Meta has not claimed to have built the best model in the world, which is itself a departure from the over-claiming that damaged Llama 4’s credibility.

Where Muse Spark leads is health. On HealthBench Hard – open-ended health queries – it scores 42.8, substantially ahead of Gemini 3.1 Pro at 20.6, GPT-5.4 at 40.1, and Grok 4.2 at 20.3. Health is a stated priority for Meta; the company says it worked with over 1,000 physicians to curate training data for the model.

Muse Spark also offers three modes of interaction: Instant mode for quick answers, Thinking mode for multi-step reasoning tasks, and Contemplating mode, which orchestrates multiple agents’ reasoning in parallel to compete with the most demanding reasoning modes from Gemini Deep Think and GPT Pro.

The open-source retreat

This is the part of the Muse Spark story that the benchmark tables do not capture. Unlike Meta’s previous models, which were released as open-weight models – meaning anyone could download and run them on their own equipment – Muse Spark is entirely proprietary. The company said it will offer the model in a private preview to select partners through an API, making Muse Spark even more proprietary than the paid models offered by Meta’s rivals.

Wang addressed the change directly, stating: “Nine months ago, we rebuilt our AI stack from scratch. New infrastructure, new architecture, new data pipelines. This is step one. Bigger models are already in development with plans to open-source future versions.”

The developer community’s response has been sceptical. Some see this as a necessary pivot after Llama 4 failed to gain expected traction. Others view it as Meta closing the gates once it has something worth protecting. That is the community now being asked to wait while competitors without that open-source legacy continue shipping freely available weights.

Distribution over benchmarks

Meanwhile, Meta is not waiting for the developer community to come around. Muse Spark will debut in the coming weeks inside Facebook, Instagram, WhatsApp, and Messenger, as well as in Meta’s Ray-Ban AI glasses. That rollout path is arguably more consequential than any benchmark result. OpenAI and Anthropic sell to developers and enterprises. Meta deploys directly to over three billion people already inside its apps daily.

Meta’s push into health does raise privacy questions worth watching. Muse Spark users will need to log in with an existing Meta account to use it, and while Meta does not explicitly say personal account information will be used by the AI, the company has generally trained on public user data and has positioned Muse Spark as a personal superintelligence product.

Meta stock rose more than 9% on the day of the launch, a signal that investors read the Muse Spark release as proof that the US$14.3 billion bet on Wang and the nine-month rebuild produced something real. Whether the promised open-source versions actually materialise is a question the developer community will press every quarter. The answer will define how this chapter of Meta’s AI story is remembered.

See Also: The Meta-Manus review: What enterprise AI buyers need to know about cross-border compliance risk

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post Meta has a competitive AI model but loses its open-source identity appeared first on AI News.

  •  

STAT+: Top health officials highlight efforts to make medical records more portable

Zac Jiwa, a federal Medicare official, delivered a eulogy of sorts at a Thursday Medicare event highlighting the successes of the Health Tech Ecosystem initiative. 

The eulogy’s subject? The clipboard. 

For the past eight months, hundreds of health tech companies have been working to meet goals set out by the federal government to make patient records more portable, create systems that import patients’ data into providers’ electronic health records systems, and stand up various patient apps. The idea is to make filling out a stack of paperwork at every doctor’s visit, on that ubiquitous clipboard, a thing of the past.

Continue to STAT+ to read the full story…

© Mark Schiefelbein/AP

  •  

New rules for CDC vaccine panel aim to address lawsuit, empower Kennedy’s allies

After a courtroom defeat, Trump administration health officials have revised the governing documents for a key federal vaccine panel to broaden its membership, increase its focus on potential harms of vaccines, and empower allies of health secretary Robert F. Kennedy Jr.

The new charter for the committee that advises the Centers for Disease Control and Prevention on vaccine use appears aimed at trying to evade the type of legal challenge that has left the currently appointed body in limbo. In addition, the document puts greater emphasis on the role of the Advisory Committee on Immunization Practices in studying injuries possibly linked to vaccination  — though the committee has always paid close attention to any emerging evidence that called into question the safety of individual vaccines.

Read the rest…

© Elijah Nouvelage/Getty Images

  •  

STAT+: A new health care blueprint from a key Democratic think tank

You’re reading the web edition of D.C. Diagnosis, STAT’s twice-weekly newsletter about the politics and policy of health and medicine. Sign up here to receive it in your inbox on Tuesdays and Thursdays.

In which RFK Jr. says the “government lies to us” while sitting in front of an HHS seal. Send news tips and podcast recommendations to John.Wilkerson@statnews.com or John_Wilkerson.07 on Signal.

First, control health care costs

Last month, a group of 12 Senate Democrats proposed a framework for rebuilding the health care system. The idea was to spur input from others ahead of when Democrats might get a chance to act on those plans.

Continue to STAT+ to read the full story…

© Adobe

  •  

Agentic AI’s governance challenges under the EU AI Act in 2026

AI agents hold the promise of automatically moving data between systems and triggering decisions, but in some cases, they can act without a clear record of what, when, and why they undertook their tasks.

That has the potential to create a governance problem, for which IT leaders are ultimately responsible. If an organisation can’t trace an agent’s actions and don’t have proper control over its authority, leaders can’t prove that a system is operating safely or even lawfully to regulators.

That’s an issue set to become more important from August this year, as enforcement of the EU AI Act kicks in. According to the text of the Act, there will be substantial penalties for failures of governance relating to AI, especially when used in high-risk areas such as when personally-identifiable information is processed, or financial operations take place.

What IT leaders need to consider in the EU

Several steps can be taken to alleviate high levels of risk, and of these, the ones that stand out for consideration include agent identity, comprehensive logs, policy checks, human oversight, rapid revocation, the availability of documentation from vendors, and the formulation of evidence for presentation to regulators.

There are several options decision makers can consider that will help create the record of activities undertaken by agentic systems. For example, a Python SDK (software development kit), Asqav, can sign each agent’s action cryptographically and link all records to an immutable hash chain – the type of technique that’s more associated with blockchain technology. If someone or something changes or removes a record, verification of the chain fails.

For governance teams, using a verbose, centralised, possibly-encrypted system of record for all agentic AIs is a measure that provides data well beyond the scattered text logs produced by individual software platforms. Regardless of the technical details of how records are made and kept, IT leaders need to see exactly where, when, and how agentic instances are acting throughout the enterprise.

Many organisations fail at this first step in any recording of automated, AI-driven activity. It’s necessary to keep a registry of every agent in operation, with each uniquely identified, plus records of its capabilities and granted permissions. This ‘agentic asset list’ ties neatly into the requirements of the EU AI Act’s article 9, which states:

  • Article 9: For high-risk areas, AI risk management has to be an ongoing, evidence-based process built into every stage of deployment (development, preparation, production), and be under constant review.

Furthermore, decision-makers need to be aware of the Act’s Article 13:

  • High-risk AI systems have to be designed in such a way that those deploying them can understand a system’s output. Thus, an AI system from a third-party must be interpretable by its users (not an opaque code blob), and should be supplied with enough documentation to ensure its safe and lawful use.

This requirement means the choice of model and its methods of deployment are both technical and regulatory considerations.

Putting the brakes on

It’s important for any agentic deployment to offer a facility for the revocation of an AI’s operating role, preferably within a matter of seconds. The ability to revoke quickly should be part of emergency response processes. Revocation options should include the immediate removal of privileges, immediate ceasing of API access, and the flushing of queued tasks.

The presence of human oversight, combined with the presentation of enough context for humans to make informed decisions, means that human operators must be able to reject any proposed action. It’s not considered adequate for the person reviewing a decision to see only a prompt or a confidence score. Effective oversight needs information around context, every agent’s authority, and time enough to intervene to prevent mis-steps.

Multi-agent considerations

While every agent’s action should be recorded automatically and retained, multi-agent processes are particularly complex to track, as failures can take place among chains of agents. It’s therefore important for security policies to be tested during the development of any system that intends to utilise multiple agents.

Finally, governing authorities may require logs and technical documentation at any time, and will certainly need them after any incident they have been made aware of.

Conclusion

The question to be considered by IT leaders considering using AI on sensitive data or in high-risk environments is whether every aspect of the technology can be identified, constrained by policy, audited, interrupted, and explained. If the answer is unclear, governance is not yet in place.

(Image source: “Last Judgement” by Lawrence OP is licensed under CC BY-NC-ND 2.0. To view a copy of this license, visit https://creativecommons.org/licenses/by-nc-nd/2.0)

 

Want to learn more about AI and big data from industry leaders? Check out AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and co-located with other leading technology events. Click here for more information.

AI News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

The post Agentic AI’s governance challenges under the EU AI Act in 2026 appeared first on AI News.

  •  

STAT+: 5 years after lupus breakthrough, CAR-T is still surprising autoimmunity researchers

Georg Schett had two things: a young patient deathly ill with lupus, and a couple of mouse studies raising the possibility that special T cells could tame the condition.

The German physician-scientist could produce the cells — chimeric antigen receptors, or CARs — at his institution, which was half the battle. Another hurdle: The patient’s parents. “They were like, ‘Don’t do that. You’re crazy,’” recalled Fabian Müller, Schett’s collaborator at the University of Erlangen-Nuremberg. A widespread fear at the time was that T cells would trigger or worsen autoimmune disease. 

The rest of the story is the rare scientific fairy tale: The patient got better. Five years on, she is still in remission, and working in the very clinic where she was treated. Her case upended the world of autoimmune disease, driving a flood of experimentation and investment and offering new hope to millions of patients. 

Continue to STAT+ to read the full story…

© Adobe

  •  
❌