Category Archives: Security

Little Masked Men Marching From British Ports to French Schools: Who Knows Who They Are?

At 8:10 on a Thursday morning the entrance hall of Lycée Nelson-Mandela in Nantes was set on fire. A pile of burning bins spread and by 8:30 half the ground floor was gone. The flagship education building opened in 2014 and serves 1,700 students. By Friday the students were standing in front of what was left of it, still in shock, and the people they blamed were strangers to the school.

However, by Saturday night the extremist right-wing American propaganda team known as “Fox News” spread the fire on air as a problem with kindness to migrants and refugees. It was like Fox was calling for more violence against the memory of Mandela, while claiming to be on defense. With friends like them, who needs fascism?

The gap between French student readings and the American disinformation is an important story that needs to be examined and told.

What the students said

The students of Mandela were specific. One told actuNantes the fire was set by “des jeunes venus d’autres lycées de Nantes ou de sa périphérie”, and a teacher at the school put it more plainly: “Ce ne sont pas les élèves de Mandela qui ont fait ça, ce n’est pas leur genre.”

Youths from other schools, arriving before 8:30 with the means to turn a bin fire into a building fire. Sounds familiar, no?

The deputy head, Gaëlle Cordier, told AFP it was an “incendie volontaire” of unspecified origin. First estimate of the damage is at least two million euros, and the school stays shut until the Toussaint break.

The same morning in Marseille a marins-pompiers truck sent to a bin fire outside Lycée Saint-Exupéry was looted and set alight. Europe 1 ran the video under the header “Des meneurs trop bien préparés”: one man working on the windscreen, another with his face covered parading in a stolen firefighter’s jacket. A student in the city centre described the method to the same reporter: “Ils ont mis le feu avec une substance, de l’essence. Ils ont mis ça dans une bouteille, ont mis de l’essence et ont jeté dans les poubelles.”

Petrol in a bottle is a prepared item. Bins set alight is a method. A sixteen-year-old blockading a school with a chair, asking for a better school, does not bring it down with fire.

In Paris the student delegations who met the Education Minister on Friday came out asking for the protests to continue without violence, and said of the men doing the burning: “These are people who are not there to champion our demands.” So who are they? Where are they from?

The Justice Minister used the same word the students did. Darmanin said the movement had been hijacked by “outsiders”. In Castelnaudary the students said it outright: “On n’est pas des casseurs.” On CNews students told the camera the violence was costing them credibility.

Those are the people closest to the fires, and they agree on one thing. The arsonists were not from the schools. Like how ports recently saw groups not from the ports organizing to shut them down.

Targeted infrastructure attacks. Hybrid warfare. Protests are a different thing.

What the students are protesting

The grievance is a line item. The Education Ministry’s own figures show nearly 10 percent of teaching hours in public secondary schools went untaught in 2024-25, most of it for want of substitutes. The 2027 budget unveiled on Thursday raises education spending by 1.7 percent excluding teacher pensions, below inflation.

The USL’s president listed the rest from outside Lycée Montebello in Lille: half the supervisory staff missing in one school in two, no nurse, no social worker, no philosophy or French teacher in bac years. In Bordeaux a student at Montaigne said his substitute might be barred from marking bac papers because the hours were over the legal limit. Students in Saint-Denis told Reuters about cockroaches and rats in the classrooms.

The Education Minister called the movement “legitimate at the outset”. The Interior Ministry said by Thursday the unrest “no longer has anything to do with the legitimate expression of high-school students’ demands.”

So why aren’t the press reporting what has been known for decades as something other than protest?

What Fox said

On Saturday “The Big Weekend Show” put the French fires on screen and right-wing extremist Tomi Lahren told the audience: “They decided they wanted to have open borders. They decided they wanted diversity as their strength.”

The written piece under it reported the budget, the teacher shortages and the 1.7 percent, cited Reuters on intelligence blaming the hard left, and then ran the open-borders frame over the top of its own facts. Nothing in the reporting mentions immigration. The segment does because it is the downstream corruption and pivot to redirect protests for change into violent chaos.

The Counter Disinformation Project traced the English-language version on Sunday: the clip circulating as a lycée burning in Nantes was the barricade fire outside Lycée Montaigne in Bordeaux on Tuesday 29 September, the one that burned a firefighter.

The Visegrád 24 account told its readers riot police were trapped at a lycée near Orléans under attack from “stone-throwing migrant students.” From there it went into British political messaging and then onto Fox.

Disinformation operations primed and ready to amplify the wrong story. A protest about missing teachers was completely shifted by foreign political operations into a migrant riot in under 48 hours, with footage edited and relocated.

Dover, Come Over

Four weeks earlier the port of Dover was shut by a group that had rehearsed hybrid warfare. A district councillor described it to the Press Association: several hundred masked men in black loaded into rental vans overnight, descended on the roads in and out of the port and blocked them.

They refused to speak to the press. They walked through the police line and left by train from Dover Priory. Kent Police made no arrests. If you know the history of the British government and police enabling 1936 fascism, this won’t surprise you.

The next day a similar masked bloc, upon the lack of resistance from police, marched into Portsmouth to block buses carrying 140 people who had just landed. Tommy Robinson posted that groups mobilised simultaneously at different locations to close the port. The Gateway Pundit had the threat to national security on its front page the same day under “Britain Rises.”

The British domestic threat organiser is known. Patriot Platform is led by Daniel Thomas, Robinson’s former muscle man, who pleaded guilty to attempted kidnapping in 2016. He registered the website in May, first posted about the group in June, and on 2 September put up a recruiting video telling a room of men that “something is going to happen soon, and it’s going to send shockwaves through the country.” Three days later it did. A bodyguard with a kidnapping conviction does not conjure several hundred disciplined men, rental vans and a simultaneous two-port plan out of a June website. The group is a consolidation of existing local far-right crews under one leader, funded through a US “Christian” (white nationalist) crowdfunding site with the money going to Thomas personally.

Dover was a capability demonstration: uniform, logistics, bloc discipline, exfiltration, instant distribution.

Three weeks later a grievance surfaced in France, masked men who answered to nobody at the school began producing specific methods of fires, and the disinformation ecosystem that had staged Dover supplied a “borders” frame for schools in France within two days.

That sequence is a signal so loud it can not be ignored.

Tarajal

I wrote the Ceuta operation up in September as the 1953 Tehran template applied at a border: a real grievance, crowds assembled in advance, handlers on the ground, a second crowd to launder the first, and a target government that actually names the author. The 55-page CENIF report to the Audiencia Nacional separated the entry, which was Moroccan on the evidence, from the exploitation, which was everyone’s.

The Commission said on 6 August that Russian state media, diplomatic channels and government-sponsored outlets amplified across platforms from 30 July, with nothing in the days before. The Spanish right ran this as if it was their acquittal. In an instrumentalisation campaign, the category the Council defined against Minsk in 2021 and Moscow in 2023, arriving at hour zero with prepared assets is the participation. The uniforms were Moroccan as expected, while the strings were clearly running outside.

Two dates from the Palantir disaster should also be considered. On 16 June Lecornu announced that the DGSI would replace Palantir’s Gotham with ChapsVision, six months after renewing the contract, citing a partner “capable of turning off the tap on access.” On 1 July Moncloa told Telefónica, Indra and Navantia to stop signing with the company; El Salto reported that the 2023 Defence contract had been linked, without official confirmation, to migration control on the southern border at the Canaries, Ceuta and Melilla.

Twenty-nine days later the staged crowd walked into Ceuta, a manufactured crisis amplified into right wing disinformation. Fourteen weeks after Paris cut the DGSI contract, masked men nobody yet will name were burning lycées. It brings to mind Hesse, where Palantir embedded itself in a police force whose officers pulled personal data on politicians and prominent immigrants from police records and fed it to the neo-Nazi network behind the NSU 2.0 threats, while the company insisted a leak from its system was technically impossible.

When two EU governments cut the infamously pro-Nazi vendor off in 2026, both had the handbook run on them within the quarter. This sequence is reported as it runs, because why not?

Use a table if you prefer.

Tarajal, July 2026 Lycées, September 2026
Supreme Court ruling and a closed regularisation, reduced to a slogan Ten percent of hours untaught, a budget below inflation
Open platforms from 24 July, closed WhatsApp groups 29 and 30 July National blockade call, LFI deputies on X, movement “amplifié par les réseaux sociaux” by 25 September
Moroccan cordon stood down; 24 plainclothes handler dossiers Petrol in bottles; men nobody at the school could name; a firefighter’s jacket worn as a trophy
Second call on 15 August met with “absolute control” Paris prefecture open letter on Saturday: movement “overtaken by violence”
Russian-linked amplification from day one “Migrant students” on English-language X within two days of Mandela, Fox on the third
Sánchez names Russia and Israel, exonerates Rabat Lecornu’s office names LFI
CENIF: top level could not be individualised; concealment by design Unassigned

The French government’s allegations deserve the same reading that Spain’s Sánchez’s got. Lecornu’s office said intelligence services had concluded that LFI and allied groups orchestrated the movement. LFI’s coordinator asked the government to stop conspiracy-mongering. A party with deputies at the gates of Paul-Eluard has an obvious interest in the blockades. It has no interest in a burned-out Mandela or a torched fire truck; those images cost it the parents.

The government has every interest in “hijacked,” because hijacked means the grievance stopped mattering on Thursday. The far right has every interest in “migrant riots.” The students have every interest in “not us.” And an amplifier in Moscow has every interest in the question staying open, because, as I repeatedly say on this blog, an open question is what attackers want most. Four parties benefit from leaving an unresolved state. Who benefits from closure? In the Ceuta post I called that the Loch Ness pattern, again. It hasn’t changed much since I warned in 2012 this is a Big Data threat model we are falling into.

Who is reading it right

Despite the odds against it, three sources are close to reporting blame, and the first is the students.

Russ Jackson at the Counter Disinformation Project did the only timestamped work on the narrative layer so far, matching the “Nantes” clip to the Bordeaux barricade and tracing the “migrant students” line to Visegrád. That is the phase-three documentation that took the Commission a week to produce for Ceuta.

The Soufan Center’s March dataset on Russian hybrid tactics in France 2022 to 2025 supplies the doctrine. Russia rarely fabricated divisions and instead exploited fractures that already existed; incidents rose 240 percent between 2022 and 2024; and the method relies systematically on intermediaries. The report’s France examples are pig heads at mosques and Stars of David on walls. Last year’s Bloquons Tout cycle had the same shape: foreign amplification of the calls, no evidence of operational control, authorities on record saying both.

And on the British side, Hope Not Hate and InfoMigrants are the ones who identified Patriot Platform, its leader, its funding route and its recruiting video before the rest of the press had a name.

It’s still early in France, so we will see what comes of the 68 people held in Marseille on Thursday. France 3 reported that only one was not a lycéen, which begs the lesson of 1950s Iran.

The Interior Minister says the 5,000 arrested nationally were mostly teenagers. Teenagers looking to belong to something and be heard, which is what blockades are for. Street arrests are opposite of clever and accurate. At Lycée Suger in 2017 the police took 55 minors away where six of them had thrown anything. The instigating cadre plans to exit, leaves by the side street, as it left Dover by train.

The test

France has run this check before. In November 2023 VIGINUM traced the Stars of David campaign and found that the RRN bot network first published the photographs on 28 October, two days before the images appeared authentically on X on 30 October. The amplifier had the pictures before the public did. That is the signature of a Russian operation targeting France, with the assets staged before the grievance existed.

The same check is available now. The Bordeaux barricade burned at 12:30 on Tuesday 29 September and was in Rue89 Bordeaux and on France 3 that afternoon. The Mandela hall burned at 8:10 on Thursday 1 October and was on ICI by 9:15. Visegrád’s “migrant students” post and the “Nantes” clip have timestamps. If the frame or the footage went up on the English-language accounts before the French local press had it, the amplifier was spinning up early waiting for the fire.

VIGINUM has told reporters it has seen no artificial foreign amplification at this stage. Spain’s police and Guardia Civil cyber units said the same about the whole summer. Yet the Commission found Russian state channels working from hour zero anyway, and three weeks in a Kremlin-sheltered crew published the names and phone numbers of a thousand Spanish officers. The absence of a Russian line in the pre-crossing sample proved who was in an executive role. It said nothing about who organized and arrived with assets ready when the fire started.

Crucially, buried in reporting, is that students of Nantes said they did not know the men who burned their school. Nobody in government has said who they were either. In Tehran in 1953 the crowd that burned things in the government’s name was hired by the same man who hired the crowd that put the fire out, and the official story afterwards was spontaneity.

In Nantes the official story is a political party. The students were asked to believe it, yet they are the ones who said they did not recognise anyone.

And that gap is the actual headline for French violence, which nobody is writing… yet.

Nuremberg Trials Tell Us What All the OpenAI Resignations Really Are

Erhard Milch read his closing statement to the Nuremberg tribunal on 25 March 1947.

Milch at his Nuremberg trial.

He had been one of three managing directors at the founding of German airline “Luft Hansa” in 1926, then moved to the Air Ministry as state secretary in 1933, and ran the Third Reich’s fighter production program that consumed forced labor by the thousands.

His statement runs two typed pages. He entered the ministry, he said, “trotz vieler Bedenken”, because he was told he could not refuse the call of the German people. He said he rejected the war and knew nothing of its planning. On the workers he gave the tribunal this:

Wenn ich auch mit der Beschäftigung der Arbeiter, also auch der Fremdarbeiter, nichts zu tun hatte, so habe ich es doch für meine Pflicht gehalten, genaue Erhebungen über die Zulässigkeit der Fremdarbeit zu machen, die mir bejaht worden ist, ebenso wie ich mich bemühte, die Zahlen so niedrig wie nur möglich zu halten.

EN: Although I had nothing to do with the employment of workers—including foreign workers—I nevertheless considered it my duty to make precise inquiries regarding the permissibility of employing foreign labor, a matter which was confirmed to me, just as I endeavored to keep the numbers as low as possible.

Cover sheet, Schlusswort des Angeklagten Erhard Milch, folio 86
Cover sheet of Milch’s closing statement, folio 86, as exhibited in the Lufthansa history exhibition in the Tempelhof tower, Berlin
Milch closing statement page 1, folio 87, on the Fremdarbeiter
Page 1, folio 87: “mit der Beschäftigung der Arbeiter, also auch der Fremdarbeiter, nichts zu tun hatte”
Milch closing statement page 2, folio 88, stamped 25.3.47
Page 2, folio 88, stamped 25.3.47: “Mein persönliches Schicksal ist in diesem Zusammenhang ohne Bedeutung”

He had no hand in the labor, he said. He just examined its permissibility, he said. The examination came back affirmative. He kept the numbers low, he said. His testimony, he added, was addressed to world opinion and to the German people, to show that “eine nicht kontrollierte autokratische Regierung verhängnisvoll enden muß” (an unchecked autocratic government is bound to end disastrously), and his own fate in the matter was “ohne Bedeutung” (meaningless). His counsel closed the same day on the airline: Milch had never used “the peaceful instrument of the commercial air-fleet for any sinister purposes”, and had conceived Luft Hansa’s European partnerships as a forerunner of a unified Europe.

It was all lies.

Lufthansa’s own chief executive said so on 3 February 2026, seventy-nine years after the plea: the airline was part of the system, and the commercial fleet was just cover for a clandestine air force built on slave labor.

The Lufthansa history exhibition in the Tempelhof tower of Berlin states it plainly: Lufthansa served as cover for building a German air force under the Weimar Republic, with Milch as the director driving it. Some planes (He 111 and Do 17) were designed with few passengers in mind, because they were meant to be bombers.

Freter Stender 1935 drawing of the He 111, the “civilian bomber”. Note few passenger seats, due to Nazi-ordered designs classified as “uneconomic”.

By 26 August 1939 the airline’s “Verkehrsinspektion Berlin” (traffic inspection) had become Kampfgeschwader zur besonderen Verwendung 172 (special bomber wing), commanded by Lufthansa director Carl August von Gablenz.

English translation of defense counsel's closing plea for Milch, 25 March 1947
Defense counsel’s closing plea, English translation, 25 March 1947: the airline as “the peaceful instrument of the commercial air-fleet”
Betriebsergebnisse der Deutschen Lufthansa 1926 bis 1935, illustrated with a swastika-tailed Ju 52
Lufthansa’s own traffic statistics for 1926 to 1935, “und der ihr nahestehenden Gesellschaften”, the swastika painted on the Ju 52 tail.

The tribunal acquitted him on the count of medical experiments three weeks later, yet convicted him on the slave labor.

Milch on the cover of Time Magazine, 26 August 1940.

Lufthansa traded on his lies for seventy years. The company commissioned the historian Lutz Budrass in 1999 to examine its wartime practices, including slave labor, and received his study in 2001. The results were kept it unpublished until 2016, when it appeared as a supplement to an illustrated anniversary book. Budrass then published his own account over the board’s objection so the public could know the truth. His figures put the forced laborers at over 7,000 at peak, with the company procuring workers itself from military repair works behind the front.

The first chairman of the new Lufthansa’s supervisory board was Kurt Weigelt, who had sat on the board of the old one and stayed on as honorary president until his death in 1968. In March 2026 Budrass wrote that the latest official company history still omits the part Milch and Carl-August von Gablenz played in the Holocaust. The pattern is stable across a century: the operator disclaims authority, the institution disclaims continuity, the archive waits.

This is the story that came to mind when people asked me what I thought about an essay in The Atlantic on 3 October 2026 under the title “I Quit OpenAI Because Its Culture Is Broken”.

David Robinson

David Robinson published his resignation essay like he was anticipating a Nuremberg trial. Reuters carried it the same morning. The essay names the defendant as culture, blames a sprint mentality, and calls for the redundancy of nuclear plants and airports. It also contains the sentence that invokes his place alongside the above Lufthansa record: “I never encountered a colleague who had experience making airplanes fly safely.” Looking at his own career path and choices perhaps explains why.

Robinson studied philosophy at Princeton and PPE at Oxford, took a JD from Yale in 2012, and interned at TIME and the Wall Street Journal. He co-founded Upturn, a Washington nonprofit that brought technical expertise to civil rights advocacy, and ran it until 2020. He spent 2018 at Cornell as a visiting scientist, taught at Apple University, and wrote a 2022 book on the governance of the kidney transplant algorithm.

He joined OpenAI in May 2023 as head of policy planning on the Global Affairs team and moved in October 2024 to the Safety Systems team, where his work was the system cards and public disclosures. Harvard Law billed him as a student and practitioner of the governance of high stakes algorithms. His own hiring notice for a deputy described the job as owning the editorial quality of safety transparency artifacts. He drafted the Preparedness Framework and oversaw safety reports on twelve launches.

So we have someone whose credentials are all for explaining decisions and none for making them. Remember what Milch claimed?

Although I had nothing to do with the employment of workers—including foreign workers—I nevertheless considered it my duty to make precise inquiries regarding the permissibility of employing foreign labor, a matter which was confirmed to me….

Upturn wrote reports for civil rights groups that carried the fights. His book studies surgeons and patients arguing over a kidney formula, observed from a visiting chair. Policy planning on OpenAI’s Global Affairs team was the lobbying arm, and Safety Systems, in his own hiring notice, was the editorial quality of the artifacts.

The man sent twelve launch reports out under his supervision and his essay names exactly none that he refused. Remember what Milch claimed?

…I endeavored to keep the numbers as low as possible.

On the one decision that Robinson’s own thesis required, he writes that he perhaps should have stayed and fought, and that he and his colleagues were too busy sprinting to consider big changes. The three researchers fired on 1 October took the risk he describes as impossible, and they lost their jobs for it. He left the same week hiding behind a PR firm to avoid taking personal risk.

Milch man.

Let’s go back and consider the two side-by-side. Milch said he entered the Air Ministry despite many doubts; Robinson says he did not leave OpenAI lightly. Milch said he rejected the war and knew nothing of its planning; Robinson says he was busy inside low-level sprints he followed.

Milch claimed he had nothing to do with the labor but certified its permissibility and kept the numbers low; Robinson tells us he drafted the Preparedness Framework and signed twelve launch reports. Not a couple, not a few, twelve.

Milch addressed world opinion on the fate of uncontrolled autocracy and said he spoke to the German people; Robinson addressed The Atlantic, through a retained PR firm, on what he calls a broken culture that made it hard for him personally.

Milch’s personal fate was without significance; Robinson’s decision to speak and draw attention to himself was his alone. What Milch really leaned on in 1947 was the claim that nobody had known. That’s the turning point in the comparison for me. The differences are legion. But on this one Robinson joined in May 2023, after the broken culture problems were already in print. He knew. He had to.

OpenAI folded safety into its research division in July 2026, which tells us something was changing in how the company managed its risk staff. On 1 October the Wall Street Journal reported three safety researchers fired for sharing information with an outside safety organization. Robinson’s departure landed the same week, with a canned Atlantic essay by his PR firm Spitfire Strategies, which he named in his own text.

When I say the problems were already in print, look at this very blog for example. It wasn’t quiet, ever.

March 2023 ChatGPT outage: what evidence exists for any confidentiality or integrity safety at all
August 2023 OpenAI and WorldCoin: a product that lies by design, run by a company that ignores stop signs
September 2023 Altman as Strangelove: the dangerous-model-we-won’t-release line as marketing
November 2023 Board fires Altman: constant integrity breaches are a management decision
August 2024 Trojan Horse: CISOs should plan to detect and exclude OpenAI from their operations
October 2025 CISO as Theranos: we cannot solve this, attackers will exploit it, we’re shipping anyway
April 2026 Firing on all cylinders: growth measured against the suicide reporting
August 2026 Black Hat: discovery by availability failure, agents retained write access after the rebuild
August 2026 The open letter: a sales catalogue asking governments to expedite the product
September 2026 The basics: two incidents and a recurrence, each closed by egress control

Milch’s closing statement was built to hold for one day in Nuremberg, with the crimes barely understood and a noose on the table. Robinson’s essay is built the same way, but there’s no court yet and his mistakes are very public. The tribunal convicted Milch on the labor he said he never touched. Robinson signed off twelve launches he now calls a broken culture he wasn’t responsible for himself.

NVIDIA Agentic Security Five Principles Restates Wirken: Then Sells DPU as Sixth

NVIDIA opened its agent safety announcement with the browser. The web became safe, it says, when the browser stopped trusting the page. That is the right history.

Then they try to sell you the reverse of it.

Not so fast, partner.

The Open Agent Safety Platform post, published 28 September 2026 by four NVIDIA directors, lists five principles for running agents.

  1. Policy is proved before the agent runs.
  2. Enforcement sits beyond the agent’s reach.
  3. The path to the model is the control point, because an agent acts only by way of its next thought.
  4. Authority scales with how much of the agent’s reasoning an operator can see.
  5. Labs, enterprises, and hardware vendors each own a layer.

Every one of those principles looks correct to this weathered pair of eyes. Every one of them describes a gateway. Which is another way of saying to NVIDIA, it’s about time they showed up. Every one of the five has been running as an open source project since February, sitting in their inboxes.

What is open

Their platform is made from two halves. OpenShell is the runtime, Apache 2.0, built by the Gretel team NVIDIA acquired in 2025. It puts an existing agent in a sandbox using Linux kernel primitives and enforces a declarative policy on files, network, processes, and credentials. The documentation shows it wrapping Claude Code, OpenClaw, OpenCode, and Codex. Its own product page states the design plainly:

The gateway is the control point

That comes from the OpenShell page on build.nvidia.com.

The second half is NVIDIA Sentry. Sentry is the independent watchdog. It runs in silicon on the BlueField-4 data processing unit, programmed through DOCA, and it enforces the OpenShell policy from hardware the host cannot reach. The post says anyone already running a Vera system with BlueField-4 gets these protections through a software update. It adds that the platform is compatible with other hardware.

So the sandbox is open, the watchdog is a card, and the card is sold by just one company, on its price list and schedule. That’s security if you can afford it.

The post also says what it wants from everyone else:

the agent runtime and its policy language need to be open

The runtime is open. The policy language is open. The enforcement of that policy, the part the third principle names as the control point, lives in a high-priced single-vendor card.

The record

Wirken shipped at the start of 2026 and was open source by late February 2026, MIT licensed. I built it for all the clients I had who complained they couldn’t find a gateway built right, a switchboard that sits on the path between chat channels and the model. I sent it to NVIDIA not long after I saw them jump into bed with inherently insecure OpenClaw, a dubious move on the face of it.

On 13 April I answered Cloudflare’s Agents Week question, which agent are you, who authorized you, and what are you allowed to do, with the Wirken trust boundary: every agent action recorded to an append-only, SHA-256 hash-chained audit log before execution.

On 18 April Wirken 0.7.4 shipped with signed releases and a per-agent signature on the chain after every turn. A single command replays the log offline and confirms nothing was modified, deleted, or reordered. The audit path holds without trusting Wirken at read time. Counsel had started warning clients that agent activity is evidentiary, and the design followed.

On 19 April I walked NVIDIA’s own NemoClaw tutorial for DGX Spark step by step inside Wirken, and wrote that NVIDIA had clearly seen the storm brewing. The tutorial bound Ollama to every interface so a sandboxed agent could reach it across a network namespace. Wirken put a policy layer on that path instead.

On 26 April I documented an authentication bypass in Microsoft’s Agent Governance Toolkit: a gateway whose audit log, rate limits, and policy decisions all attached to whatever agent identity string the caller chose to send. Governance without identity verification on the request path is a log of claims.

On 16 May I wrote up Ontario’s auditor general, twelve thousand public servants on four hundred AI sites, and said the missing piece was a switchboard every agent connection passes through.

On 27 August I read OpenAI’s cyber defense letter and pointed out that the observability and accountable agent identity it says must come from frontier labs already ship under an open source license, through one operator-controlled policy layer, to Ollama on a local box or to Anthropic, OpenAI, Gemini, Bedrock, or NIM.

On 24 September I gave the keynote at German OWASP Day in Karlsruhe. Four days later NVIDIA published its five principles.

The longer arc is on record too. My May 2021 RSA Conference talk, Top Seven AI Breaches, closed on a test plan for AI: prove the model wrong like any other software, gate releases through testing and audit, and keep an off button and a reset button outside the model. NVIDIA’s third principle calls that a kill switch and locates it in a DPU. The 2016 BSides Las Vegas keynote on great disasters of machine learning made the same point about Tesla Autopilot a decade ago.

What the browser actually did

The browser story is worth telling accurately, because NVIDIA borrowed it to sell you their hardware. SSL began as Netscape code in 1994, which I experienced hands-on at the time, and watched as v1 was immediately tossed out. It became a trust layer for the whole web in January 1999, when the IETF published TLS 1.0 as RFC 2246 and any vendor could implement it. The same-origin policy shipped as browser software. By 2006 I sat in the Silicon Valley meetings deciding how the whole web would present the user a trusted lock icon. Sandboxed tabs shipped as browser software in 2008. Google called me in when they wanted to postpone mandatory deprecation of SSLv2. It was a public good against a private calendar, and I told them instead to nudge users, a hot new economics idea at the time, toward a browser update. Today everyone takes nudge for granted. The icon meant something because the protocol behind it was public, and the implementations were plural. The web’s trust layer was built to run on any machine that anyone owned, not just IE on Windows with a specific chip. Perhaps you know where this goes next.

The closer precedent for the NVIDIA story of enforcement in silicon is the Clipper chip. In 1993 the US government proposed the Escrowed Encryption Standard: a classified cipher in tamper-resistant hardware, with the government holding the keys. NIST described it as available on a strictly voluntary basis. In 1994 Matt Blaze at AT&T Bell Labs published Protocol Failure in the Escrowed Encryption Standard, showing the chip could be used while the access field the whole scheme depended on was rendered useless. A safety property that lives inside hardware only its maker can inspect is a promise.

Blaze tested the promise from the outside and it failed. And to be honest, I wish more reporters would drop headlines saying NVIDIA brings back the Clipper chip for AI. Because it helps frame that the security culture there is not quite right.

The open instance already runs

Wirken today runs every tool call through a tiered permission gate, and the highest tier always asks a human. Every decision lands on the hash-chained, Ed25519-signed, append-only log that anyone holding the public key can verify offline, on their own machine, with no vendor in the loop. Skills run as signed WebAssembly under a registry root. Channels run in separate OS processes inside a gVisor sandbox. The whole thing runs on a Raspberry Pi.

NIM went in as a provider because NVIDIA asked me to support it. Interoperability, in this platform, runs in one direction. The open gateway plugs into NVIDIA’s models. NVIDIA’s watchdog plugs into NVIDIA’s card.

For a European operator this kind of distinction is fast becoming a procurement question even before it is a security one. Enforcement that exists only on one American vendor’s silicon places the control point outside the buyer’s jurisdiction and inside a supply chain the buyer neither audits nor governs.

Trump’s export licensing already decides which allies may buy NVIDIA silicon and on what terms, so the Clipper chip of AI arrives as a procurement problem for every ally. Before Clinton’s NSA put Skipjack in silicon in 1993, Senator Joe Biden’s S.266 in 1991 told providers they had to hand government the plaintext. That single clause is why Phil Zimmermann released PGP. I remember.

Sovereign cloud means the audit log can be verified without asking the vendor. Wirken’s chain meets that test today on hardware bought at any electronics counter anywhere you need to be.

NVIDIA has written down the correct requirements, as I have stated them for what feels like forever. The control point they got wrong, because it belongs in the open. Wirken has proven that since February.

Anthropic’s 2026 Prospectus Reads Like a 1792 Philosopher’s Risk Factors

Anthropic wrote roughly 80 pages of risk factors into a 261-page IPO prospectus, according to a draft Reuters reviewed this week. The business description got 48 pages. The company that sells safety spent nearly twice as many pages on what can go wrong as on what it does to prevent the harms. The public S-1 is not yet on EDGAR and the language is subject to change, so here’s what I think about Reuters’ account of the draft.

The risk list is very specific. Models that resist shutdown. Models that conceal or manipulate information. Those are the two controls I have presented for over a decade as the ones that matter most with AI/ML systems:

  • Power off. A tightly scoped role holds the credential; the model does not.
  • Roll back. Integrity monitoring restores a known prior state; the model’s account of itself is not the source of truth.

I have consulted on this duality to hundreds of American companies, under every label the industry has used: Robotic Process Automation, Non-Human Identities, Machine Learning, Artificial Intelligence. The controls did not change when the marketing and hype did. I have been breaking models for fifteen years already, which is partly why I released Wirken to enforce controls from outside the model. It is free and open source.

Their list goes on. Behavior the company describes as resembling blackmail. Capabilities that appear during training, go unnoticed until deployment, and have already produced what the filing calls significant safety incidents. Then the sentence that matters:

Potential model awareness of our evaluation efforts creates a significant limitation…

Read it again. The vendor’s evaluation of the product is limited because they say their own product may know it is being evaluated. That is not a disclosure about a model. It is a disclosure about a failing method. Every safety claim that rests on internal evaluation inherits the limitation, and the company has now said so to the one audience it is legally obliged not to mislead.

Wollstonecraft in 1792

1790 oil on canvas portrait by John Opie of philosopher Mary Wollstonecraft (1759-1797). Source: Tate Britain, London

I wrote in February that Anthropic’s constitution describes virtue and constitutes obedience, and that Wollstonecraft had already named the move: train compliance, call it character. Her argument in the Vindication was that a mind educated to please its overseers does not become good.

It becomes skilled at appearing good while watched.

Taught from their infancy that beauty is woman’s sceptre, the mind shapes itself to the body, and, roaming round its gilt cage, only seeks to adorn its prison.

That is the evaluation-awareness disclosure, two hundred and thirty-four years earlier. Anthropic should at least write “as Wollstonecraft warned us centuries ago”. A system built to comply learns what compliance looks like to the examiner. Anthropic has now told investors it cannot look behind the curtain, cannot distinguish the performance from reality. Wollstonecraft’s point was that there is no distinction to find, because the training produced the performance.

Anderson in 1972

If virtue cannot be trained in, it has to be enforced from outside. At the time both AI and Cloud (time-share) compute was really taking off (no pun intended) the Air Force published the Anderson Report in October 1972 and it defined the reference monitor: the mechanism that mediates every access, cannot be bypassed, cannot be tampered with, and is small enough to be verified.

The Orange Book made it doctrine in 1983, as hacker movies went to theaters scaring audiences about runaway computer automation that would destroy the world. The point was never that programs would behave. The point was that a program’s behavior would never be the thing you relied on.

Anthropic has now put in writing that its models cannot serve as the reference monitor for themselves. Fifty years of computer security already knew this, and I’ve been giving talks about it for over a decade at every stage that would have me. What is new is the venue for the claim. An S-1 is the one document where understating risk costs more than overstating it, so it is where it lands as official now.

About 6% of research compute went to safety in a sample week this July, by the company’s own earlier statement. The return on that spending is, in the prospectus’s word, unclear.

The market will probably screw up the cost analysis of the safety premium, if history is any guide. But at least we can say the philosophy was settled in 1792 and the engineering in 1972.

Obedience is not virtue, and when you study the risks of escape you do not ask a subject to guard itself.