The AI Act from an engineer's desk: Articles 12-15
Human oversight, accuracy, robustness, cybersecurity. What AI Act Articles 12, 13, 14, 15 actually require of a high-risk system, in engineering terms.
Notes on building sovereign AI, EU regulations, and shipping software when cloud isn't an option.
Human oversight, accuracy, robustness, cybersecurity. What AI Act Articles 12, 13, 14, 15 actually require of a high-risk system, in engineering terms.
A case study from a regulated Polish SaaS: how Article 32 GDPR and Article 9 of the AI Act were mapped onto one working risk-management system.
Hardcoded secrets, SQL injection, path traversal, weak crypto. The CWEs that recur in AI-generated code, with a prevention pattern for each.
The seven questions that separate a serious AI consultancy from a generalist IT shop that added a slide about large language models.
AI running on infrastructure under your jurisdiction, with auditable data flows. The definition, the regulatory drivers and the case for a 50-person firm.
Most firms think sovereign AI = on-prem or nothing. That is a false binary. There are three tracks, and most regulated SMEs will end up on Track B.
Four open-weight models, hardware requirements that match reality, and a decision tree that does not lie about VRAM. As of May 2026.
EU AI Act enforcement starts 2 August 2026. Here is what a Fractional AI Architect actually does, and why most regulated SMEs need one now.
Qwen3-Coder-30B-A3B activates 3.3B parameters per token and fits a 48 GB workstation at AWQ 4-bit. Apache 2.0 licence.
Three EU regulations killed the cloud-AI default for regulated SMEs in 2025. Here's what replaces it, and what you should build instead.
Essays from the field.