Pre-Mortem: NHS Federated Data Platform

 

On 3 August 2026, NHS England apologised. The apology confirmed what National Data Guardian Nicola Byrne had identified five days earlier: the Data Protection Impact Assessment (DPIA) for the Federated Data Platform had stated that only NHS staff could access identifiable patient data. That statement was wrong. Palantir staff held access to identifiable patient information within the national data integration environment, an arrangement the DPIA had not disclosed.

This is the fifteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

The Bet

NHS England is betting that a £330 million platform built on Palantir’s proprietary Foundry software can serve as the trusted data infrastructure for NHS analytics, and that the governance commitments made publicly about data access are auditable in practice. The bet has been partially called already. The DPIA that underpinned the programme’s public accountability framework described access controls that did not match operational reality. NHS England acknowledged the error and corrected it. The bet that now matters: that the February 2027 break clause decision, whether to extend or exit, can be made on the basis of accurate information.

The Assumption

The single belief the whole framework rests on: that NHS England can demonstrate meaningful oversight and control of a platform whose codebase NHS analysts cannot read or edit. Palantir owns the Foundry software. NHS analysts work within the platform but cannot examine or modify the code that shapes its outputs. The National Data Guardian (NDG) criticism was triggered by the gap between what was publicly asserted about data access and what was operationally true. If the accountability assertion in the DPIA did not survive scrutiny, the assumption that NHS England can verify what Palantir staff do with patient data inside a proprietary system deserves the same examination.

The Sequence

November 2023. Palantir wins the £330 million FDP contract.

April 2026. Parliamentary debate on the FDP. NHS England officials warned staff internally not to criticise the platform’s performance.

12 May 2026. NHS England confirms Palantir staff have administrative access to identifiable patient data in the national data integration environment, contradicting earlier assurances.

June 2026. The government announces a formal review of the Palantir contract, following a Science, Innovation and Technology Committee report that branded the company “an unacceptable point of weakness” in UK public sector infrastructure.

9 July 2026. The Health and Social Care Committee writes to the Health Innovation Minister recommending the exercise of the February 2027 break clause, citing “serious mistrust” among the public towards Palantir.

29 July 2026. National Data Guardian Nicola Byrne formally criticises NHS England for inaccurate DPIA disclosure.

3 August 2026. NHS England apologises and confirms the DPIA error.

The Pager

The National Data Guardian used her statutory function and the result was a public apology from NHS England. The named individual who authorised the submission of a DPIA that did not accurately describe Palantir staff access has not been identified publicly. Jules Hunt, interim Director General for Technology, Digital and Data, holds the relevant executive function. The chief digital and information officer role has not had a permanent holder since at least early 2025; the most recent interim departed in April 2026, before the DPIA error became public. The programme sits with interim leadership in the window immediately before the most consequential procurement decision of its lifespan.

The Proof

February 2027 is the break clause decision point. The Department of Health and Social Care must actively trigger the first extension; if it does not, the contract lapses in spring 2027. The Health and Social Care Committee’s recommendation is on the public record. The government has not yet responded. The outcome measure is binary and specific: the break clause is exercised or it is not. Whether the platform’s actual adoption record across NHS trusts factors into that decision is the proof measure.

Verdict

If the government exercises the February 2027 break clause, it becomes the first time a cross-party parliamentary committee recommendation, a National Data Guardian rebuke, and a public apology from the contracting body have together produced a procurement exit in NHS technology history. That would be a significant accountability signal for every future public sector AI contract. If the contract is extended, the question shifts to what changed in the governance architecture to justify continuation, and whether the interim executives carrying the programme can demonstrate what that change looks like in operational terms. The break clause is not a threat. It is a proof point with a date.

Pre-Mortem: A Billion Workers Scored in Secret. Is It Legal?

On 20 January 2026, two job applicants filed a class action against Eightfold AI Inc. in a California state court. The complaint alleged that the company had scraped personal data on over one billion workers, scored every candidate on a zero-to-five scale, and discarded low-ranked applicants before any human saw their application. The legal basis is the Fair Credit Reporting Act (FCRA). The plaintiffs’ central claim is not that the algorithm was biased. It is that the algorithm existed in secret.

This is the fourteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

Eightfold AI and the companies deploying its platform are betting that an AI system which aggregates third-party data, including social media profiles, location data, and online tracking cookies, to score individuals for employment purposes does not meet the legal definition of a Consumer Reporting Agency under the Fair Credit Reporting Act. The complaint names Microsoft, Morgan Stanley, Starbucks, BNY, PayPal, Chevron, and Bayer as companies using Eightfold in their hiring process. Co-Founder and CEO Ashutosh Garg responded with a public statement on responsible AI, noting that the platform undergoes third-party bias audits and that data comes from candidates or employers, not third-party scraping. The bet is not about whether the algorithm is accurate. It is about jurisdiction: whether the FCRA, written before algorithmic hiring existed at this scale, reaches far enough to cover what Eightfold built.

 

The Assumption

The single belief the whole framework rests on: that an AI platform scoring candidates for employers is categorically different from a consumer reporting agency, because the platform does not produce a consumer report in the form the FCRA contemplates. Eightfold filed a 35-page motion to dismiss arguing precisely that. The hearing was held on 4 August 2026 before U.S. District Judge Yvonne Gonzalez Rogers in Oakland. No ruling has been published. If the assumption is wrong, the compliance obligations the FCRA places on consumer reporting agencies, including disclosure, consent, and accuracy mechanisms, apply to every AI hiring platform operating on third-party data at comparable scale.

 

The Sequence

20 January 2026. Class action filed by former EEOC Chair Jenny R. Yang and the nonprofit Towards Justice. The complaint: Eightfold AI functioned as an unregistered consumer reporting agency across a dataset of over one billion workers.

18 June 2026. Plaintiffs’ opposition to Eightfold’s motion to dismiss filed.

22 June 2026. In the parallel Mobley v. Workday case, a federal judge denied Workday’s motion to dismiss claims of race, age, and disability discrimination through AI hiring tools.

9 July 2026. Eightfold reply brief filed.

4 August 2026. Motion to dismiss argued in Oakland before Judge Yvonne Gonzalez Rogers. No ruling published as of 16 August 2026.

13 August 2026. Eightfold AI named “Agentic AI HR Solution of the Year” at the HR Tech Breakthrough Awards.

 

The Pager

Kistler et al. v. Eightfold AI Inc., No. 3:26-cv-01768 names Eightfold AI as defendant. No talent acquisition leader or CHRO at Microsoft, Morgan Stanley, Starbucks, or any other company deploying the platform has been named as a defendant, and no deploying company has publicly committed to disclosing the tool’s existence to applicants. The pager sits with the vendor. The question of who carries it at the companies deploying the platform remains unanswered.

Garg’s public statement on responsible AI is a creditable position. It does not address what obligations the companies using Eightfold carry, or what those companies owe to the candidates who may have been scored and discarded before a human saw their application.

 

The Proof

The motion to dismiss ruling is the first proof point. A denial advances the FCRA question to discovery and the merits. It would be the first federal answer on whether AI candidate scoring constitutes consumer reporting. A grant sends the question back to the FTC and Congress, where progress has not matched the scale of deployment. The outcome measure worth watching is not which side wins the motion. It is whether any major Eightfold client commits to applicant disclosure before the court decides whether disclosure is legally required.

 

Verdict

If Judge Gonzalez Rogers denies the motion to dismiss, the case advances and the FCRA question gets its first federal answer in the context of AI hiring tools. That ruling will matter to every organisation using algorithmic screening, not only Eightfold’s clients. A denial does not mean Eightfold loses; it means the question gets answered in a setting with evidence, argument, and binding precedent. If the motion is granted, the accountability gap returns to regulatory and legislative channels, where the pace has not matched the scale of the deployment. What would change this assessment is action of a different kind: a major employer publicly committing to applicant disclosure before the court makes the decision for them.

Pre-Mortem: The Accountability Question the Mills Review Left Open

On 6 July 2026, the Financial Conduct Authority published the Mills Review, its examination of how AI will reshape retail financial services in the UK. The review covers seven recommendations across the regulatory perimeter, oversight architecture, and the transition to autonomous decision-making. It names the accountability gap at the centre of autonomous AI trading. It does not close it.

This is the thirteenth piece in the Pre-Mortem series. Five questions, applied to the public record, before the outcome is known.

 

The Bet

UK firms deploying autonomous trading AI are betting that the Senior Managers and Certification Regime (SMCR), the framework that holds named executives personally accountable for conduct failures in their area of responsibility, covers their position through general senior manager oversight. The FCA has been clear that delegating a decision to an algorithm does not transfer senior manager liability to the algorithm. The bet is that this principle, correctly stated and on the public record, can be demonstrated in practice before an enforcement case defines what demonstrating it actually requires.

 

The Assumption

Seven recommendations. One question still without an answer:

When an autonomous trading system executes a decision at machine speed, without pausing for human approval of the individual trade, which specific senior manager function is accountable if that decision causes a customer loss, and what does demonstrating adequate oversight of a system like that actually require?

The Mills Review acknowledged the problem directly. Without guidance, the review found, the combination of greater opacity in AI-mediated decisions and factors such as model drift makes it harder for the regulator to identify a de facto responsible individual, or for senior managers to evidence meaningful human control. Stakeholder feedback throughout the review called for clearer guidance on what constitutes the “reasonable steps” expected of senior managers. The review recommends the FCA develop it. The FCA has not yet published it. Every firm currently deploying autonomous trading AI is operating on the assumption that its existing accountability structure covers the gap. That assumption has not been tested in an enforcement case.

 

The Sequence

December 2019. SMCR extended to all FCA solo-regulated firms, completing its rollout across financial services.

27 January 2026. The FCA launched the Mills Review, acknowledging that AI in retail financial services had developed faster than the regulatory frameworks designed to govern it.

24 February 2026. Call for input closed.

6 July 2026. The review published seven recommendations. The FCA committed to adapting its regulatory frameworks as the transition to autonomous models continues. No guidance named a specific senior manager function as accountable for autonomous trading decisions. No guidance defined what “reasonable steps” requires for a system executing at machine speed without human review of individual decisions.

The capability reached the market before SMCR was tested against it. The review arrived after the capability. The guidance has not arrived yet.

 

The Pager

The FCA has confirmed there will be no dedicated Senior Manager Function for AI, and that accountability falls on existing functions. That is a clear policy position and it deserves credit for being stated plainly. The Treasury Select Committee has urged the FCA to publish guidance specifying the level of assurance expected of senior managers for AI-related harm. The Mills Review carried that request forward into its recommendations. The harder question is the one seven recommendations did not answer: when an autonomous trading system causes a customer loss, which specific function holder carries the call?

 

The Proof

There are no enforcement cases. The first case will establish what “reasonable steps” means in an AI trading context. The Mills Review is a process measure: it produced recommendations. The outcome measure worth watching is whether the FCA’s follow-on guidance names a specific function and defines the oversight standard in operational terms rather than principles alone. A principle restated is not a gap closed.

 

Verdict

If the FCA’s follow-on guidance names the senior manager function accountable for autonomous trading AI and defines what “reasonable steps” requires at the operational level, UK financial services will have resolved an accountability gap that every other major jurisdiction is still navigating. The review’s existence, the named individual who led it, and the seven published recommendations are genuine evidence that the FCA identified the problem and moved on it. Without operational guidance, the gap stays open. The first enforcement case will write the rule in the least comfortable setting available. That is a considerably worse way to write it.

Pre-Mortem: The Liability Chain Medicare’s AI Prior Auth Model Has Not Drawn

On 1 January 2026, the Centers for Medicare and Medicaid Services in USA launched the WISeR model in six states, introducing prior authorisation to procedures that traditional Medicare had always provided without it. Contracted companies now assess medical necessity using AI. Human clinicians are required to sign off on any denial. The Senate voted 46-50 in July 2026 to keep the programme running. One question has not been answered.

This is the twelfth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

CMS is wagering that AI-assisted prior authorisation reduces unnecessary Medicare spend without producing the patient-safety incident that forces a political reversal. If WISeR delivers measurable waste reduction without a documented causal chain from AI denial to patient harm, it becomes the template for prior authorisation across Medicare nationally. If it produces that chain, a documented line from AI recommendation to denial to patient harm, it does not just end WISeR. It becomes the reference point that makes AI prior auth politically untouchable in federal health programmes for a generation.

 

The Assumption

CMS has answered every operational question about WISeR except this one:

When an AI recommendation leads a contracted clinician to deny care and a patient is harmed as a result, where does liability sit?

The model design places a human clinician between the AI output and the denial decision. That establishes a paper trail. It does not establish a liability framework. Contractors earn between 10 and 20 per cent of the savings generated by denials and lose that payment when a denial is overturned on appeal. That is a commercial penalty, not a clinical one. The Federal Tort Claims Act does not cover contracted entities. No federal court has tested whether a contracted clinician reviewing AI recommendations at volume carries the same duty of care as a treating physician making an independent clinical judgement.

The assumption doing all the work in this model is that the human review layer is accountability enough. That assumption has not been tested.

 

The Sequence

1 July 2025. CMS published the WISeR notice in the Federal Register and did not submit it to Congress under the Congressional Review Act. That omission would matter later.

1 January 2026. WISeR launched in New Jersey, Ohio, Oklahoma, Texas, Arizona, and Washington.

17 March 2026. The Washington Post published an exclusive: Medicare’s new AI gatekeeper was delaying care for seniors. The University of Washington’s medical system had nearly 100 patients waiting for epidural injections. In Arizona, Phoenix pain specialist Dr Matthew Crooks told Medscape that every epidural injection submitted in the first three months had been denied and described the system as completely nonfunctional and unsustainable. In Texas, initial AI approval rates ran at 62 per cent, against a 92 per cent national approval rate across Medicare Advantage.

25 March 2026. The Electronic Frontier Foundation filed a FOIA lawsuit against CMS in federal court in California, seeking records on WISeR’s AI algorithms, training data, bias safeguards, and the financial incentives paid to contractors. The suit confirmed that CMS had not made its AI methodology or vendor compensation structure publicly available seven weeks after launch.

6 April 2026. CMS published a Federal Register notice delaying prior authorisation implementation for certain services within the model to allow additional time for operational readiness. CMS also issued a corrective action order against one of its AI contractors. Both confirmed that the model’s operational design had not performed as intended in the first quarter.

12 May 2026. The Government Accountability Office issued its determination: WISeR met the Administrative Procedure Act definition of a rule and was subject to the Congressional Review Act. CMS had not made the required submission to Congress before the model took effect.

20 May 2026. Senator Ron Wyden and Representatives Suzan DelBene and Greg Landsman introduced resolutions of disapproval in both chambers, seeking to repeal WISeR under the CRA.

6 July 2026. Gold carding launched in Washington state. Providers achieving a 90 per cent affirmation rate across a minimum of ten prior authorisation requests become exempt from further review for covered services. Quarterly rollout to the remaining five states is planned.

16 July 2026. The Senate voted 46-50 against advancing the disapproval resolution. Party line. WISeR survived. The liability question the GAO had exposed survived with it.

The Pager

Dr Mehmet Oz, Administrator of the Centers for Medicare and Medicaid Services.

The message: WISeR’s accountability chain has not been drawn. The model places a contracted clinician between an AI denial recommendation and a Medicare beneficiary, but no published document establishes where negligence sits when a patient is harmed following an AI-assisted denial. The Federal Tort Claims Act does not cover contractors. Contractors point to the human clinician. Clinicians are reviewing AI output under volume pressure with no published duty-of-care standard for that specific context. When the first federal lawsuit tests this configuration, and one will, CMS will need a published framework, not a contract clause. That framework is easier to write before litigation than after.

 

The Proof

Gold carding is the model’s self-correction mechanism. If quarterly rollout reaches all six states and the 90 per cent affirmation threshold functions as a genuine quality signal, the AI layer contracts over time as trust is established. Proven providers exit prior auth. New entrants face the review. The model becomes calibrated rather than blanket.

If gold carding stalls or rollout criteria are applied inconsistently across jurisdictions, the AI layer expands without a release valve. Prior auth burden accumulates regardless of provider track record. The model becomes a cost-reduction instrument with no exit for providers who have earned one.

The proof of the bet is not the aggregate savings figure. It is whether WISeR, by the end of 2026, has published a liability framework and delivered gold carding in all six states. Without both, the model is running on the same untested assumption it started with.

 

Verdict

If CMS publishes a liability framework for AI-assisted denials before a federal case forces the question, and gold carding delivers consistent rollout across all six states, WISeR will be the strongest government evidence yet that AI-assisted utilisation review can reduce Medicare waste without a patient-safety crisis. The accountability design would become the reference for every federal health programme that follows.

Without the liability framework, WISeR accumulates its risk quietly. Not through a single dramatic incident, but through the gap between AI recommendation volume and human review capacity, compounded by an accountability vacuum no published document has yet closed. That gap does not stay open indefinitely.

Pre-Mortem: The US Government’s 3,611 AI Use Cases

On 3 April 2025, the White House issued OMB Memorandum M-25-21, directing every major federal agency to appoint a Chief AI Officer, expand the use of artificial intelligence across government operations, and manage risk proportional to each system’s impact on citizens. Twelve months later, the Federal Agency AI Use Case Inventory records 3,611 AI use cases across 56 agencies, more than double the prior year’s total. A May 2026 survey of more than 200 technology executives across civilian and defence agencies found 53% are actively planning agentic AI pilots. Only 8% of those agencies have incident response frameworks in place.

This is the eleventh piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

The US government is betting that embedding AI across 3,611 federal workflows covering benefits decisions, immigration adjudications, healthcare determinations, and law enforcement, will make government faster and more efficient before the accountability architecture governing those decisions is clarified. OMB M-25-21 requires Chief AI Officers, public AI inventories, and risk management proportional to impact. The hard compliance deadline for role-specific AI training arrives in September 2026. If that architecture catches up to the deployment before a consequential wrong decision reaches a citizen with no named relief, the bet holds.

 

The Assumption

The expansion’s credibility turns on one unanswered question: whether the Federal Tort Claims Act, designed to govern negligent acts by human federal employees, applies without amendment to decisions made by AI agents running inside federal systems. The same May 2026 survey found only 44% of agencies include vendor liability clauses in AI contracts, and only 29% have documented kill-switch procedures. The legal architecture governing accountability in federal government was designed for humans acting on behalf of the state. No court has ruled on whether it extends to the agents they built.

 

The Sequence

In 2024, federal agencies reported 1,757 AI use cases. By 2025, that figure had grown to 3,611. In March 2026, the Department of Veterans Affairs expanded AI use in claims processing, with 215 of its 367 AI systems classified as high-impact, covering benefit eligibility, healthcare access, and fraud detection. In May 2026, the majority of agencies were planning agentic pilots, with only 20% having defined pre-deployment testing policies. The AI reached citizens before the accountability reached the AI.

 

The Pager

Russell Vought, Director of the Office of Management and Budget, carries the M-25-21 mandate at the centre of the federal AI expansion. Every covered agency has designated a Chief AI Officer responsible for inventory, risk management, and AI governance at agency level. The VA alone runs 215 high-impact AI systems. No single published document names what relief is available to a veteran whose claim was influenced by one of those systems, which official carries accountability for that decision, or whether the Federal Tort Claims Act applies when the acting party is software, not a civil servant.

 

The Proof

The measure that would settle this is a published legal standard: a named accountability chain clarifying who carries liability when a federal AI agent makes a consequential wrong decision, whether government, vendor, or joint, and whether the Federal Tort Claims Act applies or new legislation is required. No such standard has been published. OMB M-25-21 requires risk management proportional to impact. It does not name the relief available to a citizen when that risk management fails, nor the date by which that question must be answered.

 

Verdict

If OMB publishes, before the September 2026 training compliance deadline, a named accountability standard for AI-driven decisions in high-impact federal systems, covering who carries liability when the AI is wrong and what legal remedy a citizen holds, the expansion will stand as the most deliberate attempt the US federal government has made to govern AI before it reaches citizens at scale. Without that, the US government has put AI into 3,611 workflows and left the question of who carries the call when the AI gets it wrong to be answered in court, by accident, or not at all.

Pre-Mortem: The UK’s Critical Third Party Regime

On 13 July 2026, Amazon Web Services, Google Cloud, Microsoft Azure, and Oracle became the first companies formally designated as Critical Third Parties to the UK financial system. The Bank of England, the Prudential Regulation Authority, and the Financial Conduct Authority now hold powers to gather information, assess resilience, and make enforceable rules against the four providers for the services they supply to the financial sector. A 2024 Bank of England and FCA survey found the top three cloud providers accounted for 73% of all cloud providers named by respondents across the UK financial sector. The designation names the risk. It does not resolve it.

This is the tenth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

The UK is betting that direct regulatory oversight of four technology providers, applied specifically to their financial-sector services, will reduce the systemic risk from having most of the sector’s cloud infrastructure concentrated in three companies. The Financial Services and Markets Act 2023, which created the CTP regime, gives the Bank of England, PRA, and FCA powers to assess resilience and enforce CTP-specific rules. The designation is a supervisory relationship, not a structural remedy. If that supervisory relationship produces documented, published improvements in resilience before the first major cloud incident in UK financial services, the bet holds.

 

The Assumption

The regime’s credibility turns on one scoping decision: that overseeing four providers for the services they supply to the UK financial sector is sufficient to contain risks generated by four companies whose infrastructure decisions are made globally, across legal jurisdictions and customer bases far larger than the UK financial system. Microsoft Ireland Operations Limited is the designated entity. Its architecture decisions are made in Redmond. The supervisory perimeter covers the financial-sector slice. The concentration risk does not stop there.

 

The Sequence

The concentration risk pre-dated the regime by years. The Financial Services and Markets Act 2023 established the legislative basis for the CTP framework. A 2024 Bank of England and FCA survey confirmed the scale: three providers controlling the majority of UK financial-sector cloud infrastructure. HM Treasury announced the first four designations on 10 July 2026, effective 13 July. The sequence is legislation, then evidence, then designation. The risk was present throughout.

 

The Pager

Rachel Blake MP, Economic Secretary to the Treasury and City Minister, made the designation announcement. The Bank of England, PRA, and FCA share oversight of the four providers under the regime. Three regulators. Three separate mandates. No published document names which of the three leads incident coordination when a designated provider’s outage affects UK financial services. The CTP framework assigns supervisory responsibility. It does not assign the call.

 

The Proof

The measure that would settle this regime’s effectiveness is a published resilience outcome: a before-and-after comparison of systemic vulnerability at a named date after the CTP rules take effect. No such commitment has been published. The three regulators hold powers to gather information from the four providers. No public document names what information will be published, in what form, and by when. The first formal review cycle has no published date.

 

Verdict

If the three regulators jointly publish a named lead for CTP incident coordination and commit to a quantified resilience outcome before the first formal review cycle, the designation will stand as the most substantive step the UK has taken to address cloud concentration risk in its financial sector. Without that, four of the world’s most powerful technology companies have been formally named, and the framework that names them has not yet named who is in charge when one of them goes down.

Pre-Mortem: The EU AI Act’s Accountability Gap


On 2 August 2026, the EU AI Act gives the EU AI Office the power to fine the developers of general-purpose AI models up to three per cent of global annual turnover, demand documentation, and commission independent access to source code. Three weeks before that date, the high-risk AI compliance deadline moved from August 2026 to December 2027, enacted as binding law on 29 June. The two facts share a date. They do not share a plan.

This is the ninth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

The EU is betting that extending the deadline for high-risk AI compliance by 16 months, agreed in May 2026 and enacted on 29 June, produces better enforcement outcomes than a met deadline inside a half-prepared enforcement architecture. The logic holds. As of August 2026, only nine of 27 member states have shown advanced public implementation of enforcement infrastructure. Germany has designated the Bundesnetzagentur as its market surveillance authority and adopted draft transposition legislation. Spain built the AESIA, a dedicated supervisory agency, from scratch. Ireland deployed fifteen coordinated authorities under a central National AI Office. Those are genuine structural commitments. Eighteen member states have not reached that point. The extension gives them time. Whether they use it is the bet.

 

The Assumption

The entire framework rests on this: that national competent authorities, operating under 27 different legal frameworks, will converge on consistent enforcement before December 2027. The AI Act is a directly applicable regulation. Its enforcement infrastructure is not. The regulation sets the rules uniformly across the bloc. The authorities responsible for applying them have been built at very different speeds, under very different political conditions. That divergence is the risk the extension is buying time to close. There is no public commitment that the time is sufficient.

 

The Sequence

The AI Act entered into force in August 2024. Member states were required to designate their national competent authorities by August 2025. At least twelve missed that deadline. Seven months later, in May 2026, the Council and Parliament agreed to simplify the rules as part of the Digital Omnibus package. On 29 June, the high-risk AI deadline moved. What remains in force on 2 August is a narrower set: general-purpose AI model obligations and transparency requirements for new deployments. The high-risk AI rules, the Act’s original centre of gravity, are no longer in that set. Governance was adjusted to fit the readiness gap. That is not the order in which enforcement architecture is supposed to be built.

 

The Pager

Lucilla Sioli, Director of the EU AI Office, carries accountability for general-purpose AI enforcement from 2 August. For high-risk AI systems, including credit-scoring models, recruitment tools, and systems used in border control, healthcare, and law enforcement, accountability rests with national competent authorities. In 17 of 27 member states, no public designation exists. The Act names the category. Seventeen member states have yet to name the person.

 

The Proof

The measure that would settle this in 2028 is year-one enforcement consistency: the share of member states that have conducted at least one formal high-risk AI enforcement action, under the same evidentiary standard, in the first twelve months after the December 2027 deadline. No EU institution has publicly committed to publishing that figure. The AI Office’s annual progress reporting is the closest mechanism on the public record. It tracks activity. No published mechanism commits to measuring whether enforcement actions are consistent across member states.

 

Verdict

If the Commission designates a public accountability owner in each member state before December 2026 and commits to publishing year-one enforcement data by name, the 16-month extension holds up as a governance decision made under realistic conditions. Without that, a framework that took two years to reach enforcement hands itself an extension with nobody carrying it.

Pre-Mortem: Eight Companies, No Published Accountability Standard

The Pre-Mortem is a weekly series on this blog. Each piece applies five questions to a major technology commitment before the outcome is known.

In February 2026, the United States Department of War signed agreements with eight of the world’s leading artificial intelligence companies, OpenAI, Google, Microsoft, SpaceX, Oracle, Amazon Web Services, NVIDIA, and Reflection, to deploy their advanced AI models inside its classified networks. Impact Level 6 (IL6) covers data classified at the Secret level. Impact Level 7 (IL7) covers compartmented intelligence and the most sensitive operational systems, where the United States military runs its actual warfighting decision support. This is the first time that large language models have operated within IL7 environments. What has not been published is who carries accountability when one of them gets something wrong.

 

The Bet

The Department of War’s stated aim is to establish the United States military as an AI-first fighting force, achieving what its AI Acceleration Strategy calls decision superiority across all domains of warfare. The eight agreements are the mechanism. The AI systems will summarise surveillance feeds, synthesise intelligence data, and suggest tactical options to human operators. The Department of War’s five AI ethics principles, responsible, equitable, traceable, reliable, and governable, are on the record. The bet is that those principles are sufficient architecture for what happens inside a classified environment.

 

The Assumption

The whole bet turns on this: that “humans remain accountable for AI outcomes” as a stated principle is equivalent to a published accountability framework.

That distinction is where there is a gap. The Department of War’s Responsible AI Strategy and Implementation Pathway establishes process. It does not name the specific individual, command role, or governance layer accountable when an AI-assisted intelligence summary inside an IL7 environment shapes a decision that turns out to be wrong. Principle and framework are not the same thing, and in a classified environment that distinction cannot be tested publicly.

 

The Sequence

In July 2025, Anthropic’s Claude became the first frontier AI model approved for use on classified networks. The Pentagon subsequently sought to renegotiate those terms, demanding Anthropic permit its models to be used for all lawful purposes without limitation. Anthropic declined, citing concerns about mass domestic surveillance and autonomous weapons. On 27 February 2026, President Trump ordered all federal agencies to stop using Anthropic. The following day, OpenAI signed its classified deal with commitments that included prohibitions on domestic mass surveillance and human responsibility for the use of force, positions that aligned with the guardrails Anthropic had sought to retain. By May 2026, the remaining seven of the eight, Google, Microsoft, SpaceX, Oracle, Amazon Web Services, NVIDIA, and Reflection, had signed equivalent agreements.

The sequence reveals something structural. The accountability architecture for classified military AI was settled by commercial negotiation and political designation, not by a published governance framework.

 

The Pager

Legal scholars on autonomous weapons identify the same accountability fracture that applies in the decision-support context here. When an AI-assisted output causes harm in a classified environment, accountability distributes: software developers could not have anticipated all operational contexts, commanding officers disclaim responsibility for machine-generated outputs, vendors invoke contractual limitation of liability. The human-in-the-loop design means a person reviews AI suggestions before acting. It does not mean accountability for acting on a wrong AI output has been named anywhere in the command chain.

No published document names the specific individual role, command layer, or governance body accountable for a wrong AI-assisted output inside an IL7 environment. No congressional oversight mechanism covers classified operational AI use. No published error reporting standard exists. By the nature of classified operations, none can.

 

The Proof

Eight companies, the highest classification levels, large language models operating on top-secret data for the first time: the scale of the commitment is confirmed. The outcome data will not follow. Classified operational AI performance is not publicly reviewed, by design. This is the only deployment in this series where the proof question cannot be answered from the outside, not because the data is not collected, but because it cannot be published.

The accountability question is not whether humans are in the loop. They are, by stated commitment. The question is whether the framework for who carries it specifically, when they get something wrong, inside a system that cannot publish what it got wrong, exists in any enforceable form.

 

The Verdict

If the Department of War’s five principles are operationalised into a named, enforceable command accountability chain for AI-assisted decisions at every classification level, if the commercial guardrails in all eight agreements are independently verifiable by a body with appropriate clearance, and if a congressional oversight mechanism specific to classified AI operational failure is established, then this is what responsible military AI deployment at scale should look like.

Without all three, eight of the most powerful AI systems on earth are running inside the most classified networks in the world. The decisions they shape will not be publicly reviewed. The wrong ones will not be counted.

The accountability is a principle. The framework has not been built yet.

Pre-Mortem: Apple Intelligence at Work

The Pre-Mortem is a weekly series on this blog. Each piece applies five questions to a major technology commitment before the outcome is known.

On 9 June 2026, Apple used its annual developer conference to announce that Siri had become something different. Not a smarter assistant. An agentic AI layer that could take actions across applications, services, and workplace workflows on behalf of its users, across a hardware ecosystem of more than 2.5 billion active devices. The world’s most valuable company had turned its operating system into an AI agent. The question the keynote did not answer was straightforward: when it gets something wrong at work, who is responsible?


The Bet

Apple is betting that privacy and accountability are the same problem. Its Private Cloud Compute architecture is genuinely novel: stateless, ephemeral, cryptographically auditable, with production builds published within 90 days for independent inspection. At WWDC 2026, Craig Federighi stated: “data is only used to execute your request, and outside experts can continue to verify this promise at any time.” The claim is that if Apple cannot read your data, no one can. What this architecture was not designed to answer is what happens when Apple Intelligence takes a workplace action on your behalf and gets it wrong. That is a different question. Apple has framed the privacy answer as if it covers both.


The Assumption

Everything turns on one distinction: that an architecture designed to prove Apple cannot access your data also constitutes a framework for enterprise accountability when AI actions produce incorrect outcomes.

It does not. Privacy means Apple is not the party reading your data. Accountability means someone is responsible for what the AI produces from it. Those are different obligations. No document currently published by Apple closes the gap between them. The existing AppleCare for Enterprise terms explicitly disclaim liability for lost profits, damage, corruption, or loss of data, or interruption of business. There is no AI-specific carve-out, no enterprise service level agreement for Apple Intelligence outputs, and no accuracy standard committed to publicly.


The Sequence

Three weeks before WWDC 2026, Apple settled a $250 million class action over Siri AI features it had promoted during the iPhone 16 launch but did not deliver. The settlement included no admission of wrongdoing. In April 2026, Apple’s CEO Tim Cook announced his departure from the role, with John Ternus, the head of hardware engineering, confirmed as his successor from September 1, 2026. Ternus had no publicly stated role in shaping Apple Intelligence. At WWDC 2026, enterprise MDM controls for Apple Intelligence were available in beta only, with general availability expected in autumn 2026. The agentic deployment was announced. The governance controls that enterprises need to deploy it responsibly were not yet generally available.


The Pager

Craig Federighi, Senior Vice President of Software Engineering, is the named face of Apple Intelligence. Amar Subramanya, Vice President of AI, is the operational lead, reporting to Federighi since the retirement of John Giannandrea earlier this year. Neither has made any public commitment regarding enterprise accountability for AI outputs. By September 2026, John Ternus will carry the CEO accountability for a deployment he did not architect, operating under governance terms that were written before agentic AI was part of the product. No named individual or governance body is publicly committed to what Apple Intelligence does in enterprise workflows when it goes wrong.

The Proof

Apple has published no enterprise outcome measure for Apple Intelligence. No accuracy benchmark, no error rate commitment, no service level agreement for business customers. The company’s transparency commitments for Private Cloud Compute are real: production code published within 90 days, a cryptographically auditable log, a virtual research environment for security testing. These are privacy verification mechanisms, not performance standards. A survey of approximately 100 enterprise IT administrators published in May 2026 found that the primary concern was data exfiltration to unmanaged providers, and that eight per cent of organisations had already moved to prohibit AI features entirely. No one at Apple has publicly committed to a measure that would settle that question.

The Verdict

Apple has done more than most technology companies to make its cloud AI architecture independently verifiable. Private Cloud Compute is a credible attempt to resolve the privacy half of the enterprise AI problem. The accountability half remains open. If Apple publishes enterprise terms that define who carries responsibility for agentic errors in business workflows, and if John Ternus names a specific accountable owner for enterprise AI governance before the full iOS 27 rollout, the MDM controls announced at WWDC 2026 become the foundation of something credible. Without both, the hundreds of millions of Apple Intelligence-enabled devices deployed into enterprise settings are operating on a privacy promise. That is not the same thing as an accountability framework.

Pre-Mortem: KPMG’s AI-Powered Audit

The audit opinion is the most consequential document most public companies produce. Not the annual report. Not the investor deck. The audit opinion, because it carries a named partner’s signature, and because that signature means something in law. On 9 June 2026, KPMG and Microsoft announced the deployment of Microsoft Agent 365 and Copilot across 276,000 KPMG professionals in 138 countries, including inside KPMG Clara, the firm’s global smart audit platform. Scott Flynn, KPMG’s Global Head of Audit, called it “a pivotal milestone in our AI-powered, human assured audit transformation.” The word “assured” is doing a great deal of work in that sentence.

A pre-mortem asks the same five questions, every time, applied before failure is possible rather than after. This is the fifth in the series. The first looked at vendor accountability in regulated finance. The second at clinical safety in healthcare. The third at execution accountability in defence procurement. The fourth at clinical AI infrastructure. This one looks at professional services, the sector that has built its entire business model on the premise that human expertise is the product.

 

The Bet

KPMG is betting that efficiency and accountability can coexist at this scale. That 276,000 professionals deploying AI agents, with a governance layer running underneath, will not dilute the professional accountability the audit opinion rests on. It is a reasonable bet. It is also an untested one. The commercial logic is clear: 276,000 professionals, 138 countries, and an AI-powered workflow running through KPMG Clara creates the kind of structural productivity gain that redefines the firm’s cost base, and potentially its fee model. Analysis of recent audit fee movements suggests clients are already pressing the case that AI efficiency should flow through to lower fees. The deeper bet, the one sitting beneath the headline deployment, is that “AI-powered, human-assured” constitutes a defensible operating model before any regulatory body has defined what “human-assured” actually requires in practice.

 

The Assumption

The single assumption carrying all the weight: that governing agents is the same thing as being accountable for them. Microsoft Agent 365 provides what its own documentation describes as a control plane, a centralised registry of agents with lifecycle rules, identity controls, and audit logging. That is a meaningful capability. It answers the question: how many agents do you have, and what can they touch? It does not, on its own, answer the question a claims lawyer or a regulator will eventually ask: who is accountable when the agent was visible, governed, and still wrong? KPMG’s Trusted AI framework lists ten ethical pillars, including one labelled Accountability, which calls for human oversight and responsibility to be embedded across the AI lifecycle. That is a principle-level commitment. None of the publicly available documentation specifies what happens to the partner’s signature when an AI-assisted conclusion is signed off and later found to be materially incorrect.

 

The Sequence

KPMG has deployed agents at scale before any authoritative regulatory framework specifies what AI-assisted audit evidence must look like, or how human review of AI-generated conclusions must be documented to meet existing standards. The IAASB approved a project proposal in March 2026 to revise ISA 500, Audit Evidence, to address technology use in audit, but the project is still in early research and information gathering, with no exposure draft issued and no effective date. The PCAOB has stated publicly that it is considering developing risk management guidance for audit firms using AI. Considering, not publishing. The capability is deployed. The standard that surrounds it is still being drafted.

 

The Pager

Lisa Heneghan, KPMG’s Global Chief Digital Officer, was specific about what this deployment requires: “strong foundations in governance, visibility and accountability.” That framing is responsible, and Agent 365 provides the visibility that most enterprises currently lack. The harder question is structural and specific. The audit opinion is signed by a named partner. Professional indemnity is priced around that signature. When an agent embedded in KPMG Clara surfaces a conclusion, the partner reviews it, signs the opinion, and the work later contains a material error, the liability has historically sat with the partner and the firm. What KPMG, Microsoft, and the client have not yet published is a clear allocation of responsibility for the agent’s contribution to that error. Is it a tool failure, an oversight failure, or something existing frameworks do not yet classify? The governance layer provides the audit trail. It does not specify who reads it, or what reading it is worth, when a claim is filed.

 

The Proof

The announcement commits 276,000 professionals and earns KPMG the designation of Microsoft “Frontier Firm.” Neither is a performance measure. No published metric connects this deployment to audit accuracy improvement, reduction in deficiencies, or quality outcomes. What the deployment actually demonstrates is that KPMG can deploy Agent 365 at scale and maintain visibility over its agent estate. That is a meaningful operational achievement. It is not the same as demonstrating that AI-assisted audit conclusions are more reliable than human-only ones, which is what regulators, courts, and insurers will eventually need to see. KPMG Clara’s existing framing covers adoption and workflow integration. No published figure connects it to audit opinion accuracy or deficiency rates. The proof that matters most is still outstanding.

 

Verdict

If KPMG publishes a clear framework specifying how AI-assisted audit evidence is reviewed, validated, and documented, paired with a liability position that survives regulatory scrutiny, this becomes the reference model for professional services AI at scale. The governance commitment is genuine. The scale of deployment is unmatched in the sector. Scott Flynn’s “AI-powered, human-assured” is the right aspiration. The question is whether “human-assured” describes a documented, auditable review process that a regulator will accept and an insurer will cover, or whether it is a positioning statement waiting for a definition. At 276,000 professionals across 138 countries, the audit opinion at the centre of this deployment is too consequential to leave that question open. The answer should come before the first material claim, not after.