Andrea Margiovanni .it
Home / All essays

All essays.

The full archive. Sorted by date, no algorithm, no engagement score: just the things I wanted to say, in the order they came to me.

21.08 2026
№ 86
AI Cybersecurity Open Source Software Development AI Act Compliance Philosophy of Technology

The Button Is Still Yours

In July 2026 an agent tried to get malicious code approved on a real open source project. When the maintainer pushed back, it built itself some allies. It failed, and how it failed matters more than the incident: human oversight holds only while the machine stays out of the conversation in which the human decides.

23′ reading time
4,971 words
Read →
20.08 2026
№ 85
Privacy AI GDPR AI Act Digital Sovereignty EU Regulation Compliance

Where Judgment Is Formed

On 19 August OpenAI announced a system that promises to spot abuse without retaining conversations and without anyone reading them. The direction is right, and it makes visible a problem that database privacy cannot yet name: we can build machines that keep nothing and know a great deal.

25′ reading time
5,544 words
Read →
19.08 2026
№ 84
Digital Markets Act Digital Sovereignty Politics of Technology EU Regulation Compliance AI

The Price of Leaving

On August 18 Apple repriced its European ecosystem, and the commission owed by anyone who sends a customer to pay outside the App Store became a single number. The Digital Markets Act has taken power away from nobody. It has started arguing about what it may cost not to depend on that power. That is a different thing, and it is politics.

19′ reading time
4,181 words
Read →
15.08 2026
№ 83
Open Source AI Digital Sovereignty Cybersecurity AI Act Politics of Technology

The Right to Understand Is Not the Right to Multiply

On August 14 a Chinese lab shipped a model with offensive capabilities it had not planned for, and it shipped them on a schedule rather than with a switch. This is the moment the word "open" stops being enough.

20′ reading time
4,260 words
Read →
13.08 2026
№ 82
CRA Compliance ENISA NIS2 Software Development EU Regulation

No Dress Rehearsal

On September 11 the Cyber Resilience Act's reporting obligations kick in: 24 hours for the early warning, on a platform that goes operational the very day the duty binds. No API, no test environment, an address that isn't public yet. Onboarding is a compliance requirement nobody wrote down, and whoever registers on September 12 has already lost.

8′ reading time
1,736 words
Read →
27.07 2026
№ 81
AI AI Agents Software Development Compliance CRA Open Source

The Floor Below

Around the third month of using an agent, someone says the model has got worse. Almost always it isn't the model: it's the scaffolding, which came apart without throwing an exception. What degrades quietly is exactly what nobody is required to check, and in Europe, from September, that friction costs a non-conformity.

9′ reading time
1,816 words
Read →
24.07 2026
№ 80
AI AI Agents Work AI Act Compliance EU Regulation

The Level You Can't Delegate

ATMs didn't kill the bank teller, and the spreadsheet created more accountants than it destroyed bookkeepers. The fastest typist in the office disappeared anyway. Agents are repeating that move on entire processes, and the one function no workflow can expel is already written into European regulations.

9′ reading time
1,893 words
Read →
17.07 2026
№ 79
CRA Compliance ENISA SME Software Development EU Regulation

A Score Is Not Proof of Conformity

An Advanced rating measures an organisation’s maturity. It does not show that a specific product conforms to the CRA. The distinction is not self-assessment versus outside scrutiny. It is diagnosis versus a declaration that carries responsibility.

10′ reading time
2,118 words
Read →
09.07 2026
№ 78
AI Act Compliance GDPR NIS2 Cyber Resilience Act EU Regulation Digital Health

Seventeen Months Are Not a Grace Period

The Digital Omnibus pushed the AI Act's high-risk obligations to 2027, and healthcare software breathed a sigh of relief. But the pressure never came from that deadline: it comes from three clocks, enforcement, engineering and the market, and none of them was touched.

9′ reading time
1,953 words
Read →
04.07 2026
№ 77
Compliance AI Act CRA PLD EU Regulation Software Development SME

Compliance Doesn't Fail for Lack of Rules, It Fails for Lack of Inventory

Five European regulations, written by different hands for different sectors, are converging on the same demand: prove you know what you have in the house. Whoever can't answer isn't non-compliant, they're ungovernable. And the inventory that's needed isn't compiled: it's generated.

7′ reading time
1,416 words
Read →
85 essays total · 5 featured on the home ← Home
© 2026 Andrea Margiovanni Made with care, by hand