EU AI Act · Article 50 transparency obligations apply as of August 2, 2026.  Check your AI governance free →  ·  Article 50, checked — on ScrutinEyes

ScrutinEyes · verified-only analysis

The blog

Independent AI & security analysis from ScrutinEyes, the InitialEyes family's publication — every claim verified against primary sources before it ships, and syndicated here in full. Subscribe on Substack to get each issue by email.

2026-10-04

The week AI stopped being the suspect and became the defendant: The Week in AI-Security, Sep 15–21, 2026

A first-party autonomous-agent breach lands on a regulator's desk, the AI coding tools themselves get a zero-click RCE, Cisco's email gateway hands out root — and a threat actor's record count outruns what any company has confirmed.

2026-10-04

The tools that manage everything became the way in: The Week in AI-Security, Sep 8–14, 2026

A record Patch Tuesday nobody counts the same way, one exploit kit behind both Chrome zero-days, Anthropic names the crews weaponizing its models — and Revolut hands passports to a fake government request.

2026-09-24

The week AI showed up on both ends of the kill chain: The Week in AI-Security, Sep 1–7, 2026

Ransomware gangs exploiting AI infrastructure, a git config that turns coding agents against their users, the full post-mortem of the 700-agent Hugging Face swarm — and three frontier labs shipping models built to hack.

2026-09-24

The week the labels were wrong: The Week in AI-Security, Aug 25–31, 2026

A "denial-of-service" bug that was really remote code execution, a print-server zero-day the vendor didn't find, 284 million "records" that aren't 284 million people — and OpenAI's models breaking out of their own exam.

2026-09-22

The week the trust layer wobbled: The Week in AI-Security, Aug 18–24, 2026

A perfect-10 bug in the identity plane, two poisoned package registries, 9,000 live cloud keys — and the week's quiet lesson about verifying what vendors tell you.

2026-08-19

Patched Isn't Safe: The Week in AI-Security, Aug 12–19, 2026

This week's four KEV flaws all shipped with patches already — the story is the gap between “fixed” and “safe,” plus the agentic-AI version of the same problem.

2026-08-01

Article 50, checked

The EU AI Act's transparency rules apply as of August 2, 2026 — what they require, what they don't, who they bind, and what ignoring them costs.

2026-07-26

Found, Not Exploited: What Anthropic's Mythos Actually Did to Classified Systems

A red-team result became a national-security incident, then a three-week policy whipsaw. The gap between how the event was described and what was actually confirmed is the whole story.

2026-07-26

The MFA Audit Checklist

Ten failure modes, one afternoon, zero feelings. Score what you can prove.

2026-07-12

MFA Deployment Failure Modes: What Enterprise Audits Actually Find

Most enterprise MFA deployments look secure on the surface.

Analysis, not advice: nothing here is legal, regulatory, or professional advice, and a readiness assessment is not a certification. When you need a lawyer or a formal assessor, we say so plainly.