Blogg

Teknisk djupgående analys av AI, Azure, Next.js och beslutet bakom.

31 inlägg

GPT-6 Astra in Copilot, GitHub and Foundry: the admin map

GPT-6 Astra reached Microsoft tenants through four doors in 48 hours: Foundry, Copilot Cowork, Copilot Studio and GitHub Copilot, two of them on by default. Each door has a different operator, data path, meter and off switch, from OpenAI running as a Microsoft subprocessor inside the EU Data Boundary to GitHub billing at list price. Here is the map and the admin checklist for a Swedish tenant.

September 10, 202672 visningarSecurity & Compliance

GitSpawn: a malicious repo can hijack your coding agent

A repository that arrives as a zip, sync folder or USB stick can execute attacker code the moment a CLI coding agent opens it, before any approval prompt and outside the agent sandbox. Manifold Security's GitSpawn disclosure covers eight findings across Claude Code, Codex, Cursor, Goose, Hermes Agent, Qwen Code and Grok Build, with four unpatched at publication.

September 7, 2026165 visningarSecurity & Compliance

A classifier is not a sandbox: isolating coding agents

A published attack chain achieved remote code execution against Claude Code in auto mode, with the safety classifier approving the steps that led to compromise and then blocking the cleanup command. What the break teaches teams running AI coding agents, and how to build real isolation on Azure with Hyper-V sandboxes, default-deny egress and short-lived credentials.

August 30, 2026205 visningarSecurity & Compliance

Claude's text watermark: what it means for Article 50

Anthropic will weave an invisible watermark into Claude's text output to meet the EU AI Act's Article 50 marking obligation, applying it globally across the API, apps and cloud platforms including Microsoft Foundry. What the mark can and cannot prove, which deployer duties remain yours, and when a DIY provenance layer still earns its keep on Azure.

August 13, 2026249 visningarSecurity & Compliance

Who enforces the AI Act in Sweden? PTS and the new map

Sweden's AI Act enforcement map is now set: the SOU 2025:101 inquiry designates Post- och telestyrelsen (PTS) as coordinating market surveillance authority, with eleven surveillance bodies, two notifying authorities, and a PTS-run regulatory sandbox. The supplementary law was written to take effect on 2 August 2026 but awaits formal adoption, so PTS and its peers operate on interim government assignments while EU transparency rules already apply.

August 5, 2026239 visningarSecurity & Compliance

AI Act enforcement is now real: an Azure deployer checklist

On 2 August 2026 the European Commission's enforcement powers over general-purpose AI providers activated: the AI Office can now demand documentation, run model evaluations, restrict models from the EU market and fine up to 3% of global turnover or EUR 15 million. The same date brought Article 50 transparency into application, and this guide maps what Azure OpenAI and Foundry teams must demand from vendors versus handle themselves as deployers.

August 4, 2026176 visningarSecurity & Compliance

The AI Act's high-risk deadline moved to December 2027

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moves the AI Act deadline for Annex III high-risk systems from August 2026 to 2 December 2027, with Annex I embedded systems following in August 2028. Article 50 transparency still applies from 2 August 2026, a new prohibition arrives with a December 2026 marking deadline, and a phased 16-month plan turns the reprieve into a workable compliance programme.

July 28, 2026168 visningarSecurity & Compliance

Article 50 compliance for Azure OpenAI apps: a guide

The European Commission adopted its final Article 50 transparency guidelines on 20 July 2026 and confirmed the Code of Practice on marking AI-generated content as adequate, less than two weeks before the obligations start to apply. Here is what Swedish and EU teams running chatbots, copilots and content generators on Azure OpenAI must implement: chatbot disclosure, machine-readable marking and deepfake labels, with concrete code patterns for each.

July 22, 2026153 visningarSecurity & Compliance

Scraping the web into your vector DB: EDPB's new rules

At its 122nd plenary on 7 July 2026 the EDPB adopted draft Guidelines 03/2026 on web scraping for generative AI and draft Guidelines 02/2026 on anonymisation, the first comprehensive GDPR framework for large-scale scraping of public web data into AI pipelines. We walk through the legitimate interest test, the new legal weight of robots.txt and ai.txt, the Article 9 lifecycle safeguards, and what it means for teams ingesting web content into RAG on Azure.

July 8, 2026126 visningarSecurity & Compliance

AI Act deadlines moved: what still lands August 2, 2026

On 16 June 2026 the European Parliament approved the Digital Omnibus amendments 423-57, moving Annex III high-risk AI Act obligations to 2 December 2027 and product-embedded obligations to 2 August 2028. Article 50 transparency duties and the Commission's GPAI enforcement powers were not delayed, which leaves Swedish enterprises six weeks to ship chatbot disclosure, content marking and a documented GPAI position before 2 August 2026.

June 17, 2026165 visningarSecurity & Compliance

Who will knock on your door about AI in Sweden? IMY, mostly

On 15 June 2026 IMY confirmed its role as market surveillance authority for the EU AI Act, with responsibility covering AI systems in areas such as law enforcement and credit assessment, alongside PTS and Finansinspektionen. For Swedish enterprises this puts GDPR and AI Act supervision under one regulator, and IMY's sandbox role offers a way to get data protection guidance before enforcement reaches full strength in 2027.

June 15, 2026179 visningarSecurity & Compliance

CADA explained for Azure customers: EU cloud sovereignty

On 3 June 2026 the European Commission proposed the Cloud and AI Development Act, a regulation that introduces four Union assurance levels for cloud sovereignty and aims to at least triple EU data centre capacity within five to seven years. For Swedish public-sector and regulated teams on Azure, the framework will decide which workloads can stay on a US hyperscaler and which need an EU-controlled alternative, so the classification work should start now.

June 10, 2026113 visningarSecurity & Compliance