Time Horizon
Immediate to Medium
Within the Time Horizon facet, Immediate to Medium time-horizon intelligence organises articles by the period over which a signal is expected to matter. The page helps readers distinguish immediate operational changes from longer-cycle governance, investment, standards, and infrastructure shifts that may unfold across quarters or years. It connects timing assumptions with public evidence, related actors, market context, customer exposure, policy pressure, and infrastructure planning so readers can judge whether a development is urgent, strategic, or still waiting on confirming evidence. The page also explains how time horizon changes the meaning of a signal, which organisations may be exposed, and which infrastructure decisions require short-term action or long-cycle monitoring.

Europe and Middle East Institutional Trends
The EU’s Sandbox Proposal Does Not Create a Regulatory Pass
The European Commission has put common principles for regulatory sandboxes beside its proposed European Innovation Act rather than inside it. That drafting choice is the news: one text could become a binding Regulation, while the sandbox principles sit in a proposed Council…

ICANN
ICANN’s ITP Contract Has a Release Gate, Not a Date
ICANN’s Board has approved the authority to contract for the next generation of the organization’s publishing platform while concealing several negotiating particulars. That is not unusual procurement hygiene. The more interesting governance fact is that ICANN has also named who…

CASE FILE
The FTC Withdrew a Health-App Statement, Not the Breach Rule
A one-page withdrawal can produce a dangerously large misunderstanding. On 9 September, the US Federal Trade Commission rescinded a 2021 policy statement about health apps and connected devices. It did not say that the Health Breach Notification Rule had disappeared. The…

CASE FILE
Ofcom’s NCII Hash Programme Separates Detection From Judgment
The most important word in Ofcom’s new intimate-image-abuse measure is not “hash”. It is “judgment”. A digital fingerprint can tell a service that an uploaded image resembles material represented in a database. It cannot, by itself, establish consent, context or every element of…

CASE FILE
California’s AI-Audit Laws Separate Registration From Verification
California has enacted two gates for a market that promises to check artificial-intelligence systems. One law will require people selling covered AI audits to enter a public registry and follow conduct rules. The other tells the state to decide which auditors merit the more…

CASE FILE
UK AI-Health Blueprint Would Put Device Versions in Patient Records—but Is Not Yet Policy
The most important field in Britain’s new blueprint for governing artificial intelligence in healthcare may be a version number. The National Commission into the Regulation of AI in Healthcare wants the device state used in a patient’s care recorded so that an outcome can later…

IETF
IETF Opened an AI Standards List Without Defining Its Decision Path
The IETF has given a disputed question a dedicated address. On 9 September, its Secretariat created `[email protected]` for discussion of artificial intelligence in the standards process. That is a useful institutional act: it makes participation and the public archive…

ICANN
ICANN Kept Its Strategy Unchanged Without Showing the Trigger Test
ICANN’s latest annual strategy review ended with a clear Board decision and an incomplete public chain of reasoning. After eight environmental-scan sessions involving nearly 210 entities, the Board affirmed on 6 September that its FY26–30 Strategic Plan would remain unchanged.…

CASE FILE
The EU’s Cyber-Product Reporting Clock Is Running Before Its Main Security Rules
Europe has switched on one of the Cyber Resilience Act’s most consequential mechanisms fifteen months before the law’s main product-security duties take effect. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents on…

CASE FILE
The EU Named Three Very Large Services. Their Exact DSA Compliance Dates Are Not Public
The European Commission has put ChatGPT, Reddit and Roblox inside the Digital Services Act’s highest-supervision tier. It also says their additional duties apply by January 2027. What the public record does not yet provide is the day that matters in law: four months after each…

CASE FILE
The UK Rejected a VPN Age Gate. Its Platform Enforcement Test Is Still Pending
Britain has made a clear choice about where not to enforce its child-safety policy: it will neither ban VPNs nor require VPN services to age-gate their users. Control has not disappeared, however. The government plans to place the burden on in-scope platforms to detect and…

ICANN
ICANN’s New Reversal Rule Opens the Record After the Board Acts
The GNSO has finally written down how the ICANN Board should reverse its adoption of a policy recommendation that has not finished implementation. The new procedure creates dialogue, voting thresholds and a public explanation. Yet the public record becomes mandatory only after…

IETF
A Physical-Site Receipt Can Be External to the Issuer—and Still Controlled by the Site Owner
Revision 03 of a proposed receipt for work at physical sites fixes several ambiguities with admirable candour. It also names a trust edge its own bytes cannot carry. A transparency service may be independent of the receipt issuer yet operated by the owner of the site whose…

IETF
A New MOA PDU Can Withdraw Authority. Its Validation Order Is Still Missing
Revision 01 of a proposed RPKI-to-router message now tells a cache how to withdraw all or part of a Mapping Origin Authorization and tells a router when stale MOA data must disappear. That is useful state discipline. But the draft places the order and fallback between MOA and…

CASE FILE
A GitHub Actions OIDC Token Is Not a Cloud-Authorization Verdict
A GitHub Actions OIDC token can identify a bounded workflow context to an external provider. It does not, by itself, establish that a cloud trust policy matched, that a cloud session was issued, that a resource permitted an action or that a target changed.

CASE FILE
A GitHub Actions Concurrency Group Is Not a Deployment-Serialization Verdict
A GitHub Actions concurrency group can reduce conflicts between named jobs or workflow runs. It does not, on its own, establish the order of every consequential action against a target or the effect of those actions.

IETF
A Finality Sink Cannot Protect the API That Routes Around It
Put the strongest possible verifier in front of one tool call. Bind the exact act, check the signer, reject stale authority and consume every nonce once. The result may still be an unprotected system if the same agent holds a credential for a second endpoint. A new individual…

IETF
PT-03 Puts Its Trust Summary Inside the Signed Request. The Hash Is Not the Authority
A human is asked whether an agent may proceed. Beside the action sits a tidy trust summary: judgment 0.88, self-assessment 0.82, trend improving. The summary's hash matches. That still does not answer the governing question: was this the summary the enforcement component signed…

CASE FILE
A SLSA Attestation Is Evidence, Not the Acceptance Decision
A SLSA provenance statement can say something precise about one artifact and the build that produced it. That precision matters. But it does not choose which builders a verifier trusts, define a package’s expected source and parameters, declare a release complete, or decide what…

IETF
AICP's Progress Percentage Is Neither a Success Forecast Nor a Safe Stop Point
An agent reports 80 per cent complete. The number looks like a promise about the destination and an invitation to interrupt before the last fifth begins. In revision 00 of the Agent Infrastructure Control Protocol, it is neither. The proposed model makes completed, active and…
