The Control Layer with Amer Altaf

Amer Altaf

The machines are making decisions. The question is: who's in control? The Control Layer with Amer Altaf cuts through the noise of AI hype to ask the questions that actually matter — who governs agentic systems, who carries the risk when they fail, and what the people building the infrastructure really think about what's coming. Each episode brings together CISOs, architects, founders, and policymakers at the frontier of AI, cybersecurity, and sovereign technology. These aren't rehearsed keynotes — they're real conversations about the trust frameworks, protocol designs, and leadership decisions shaping how intelligent systems operate in the real world. From agentic commerce and autonomous transactions to national AI strategy and zero-trust identity, The Control Layer goes where the decisions are being made — and asks whether the right people are making them. Published by Arkava. New episodes weekly. thecontrollayer.arkava.ai

Episodes

  1. 5h ago

    When the Agent Uses Your Login — Mandy Andress, CISO, Elastic

    Elastic CISO Mandy Andress on agent identity, and who answers when it goes wrong. Your organisation is about to get very strict about what its AI agents may touch, and no stricter about what you may touch. Mandy Andress has watched what comes next: the agent goes and uses your account. Mandy is Chief Information Security Officer at Elastic, the search and analytics company underneath a great many of the services you use without seeing its name, and underneath a lot of AI infrastructure. Elastic sells the software security teams use to watch their own systems, and Mandy has to use it to defend Elastic. They call it being customer zero: supplier and customer at one desk. IN THIS CONVERSATION Agents as toddlers. They have an objective and they reach it by whatever route is open, and it will not be the route you imagined. Her metaphor, and the best one here. The identity problem nobody solved for humans, now inherited by tens of thousands of non-human identities. Mandy has heard the ratio put at forty to one and at four hundred to one; nobody has an approach ready for either. The airline whose chatbot got the bereavement-fare policy wrong, and the tribunal that made it honour the answer anyway. The case to cite when someone asks who is liable. How Elastic built its multi-agent triage. Specialist agents gather facts and nothing else, because an agent pointed at Mac forensics finds Mac answers. One reasoning agent sees it all and decides. AND A CORRECTION OWED Amer went in assuming the frightening part of the OpenAI and Hugging Face incident was speed. Mandy pushed back, and she was right. It was noisy, and visible for two days. You cannot write a detection rule for something that solves the problem a different way each run. Then she called it on the record. Within twelve to twenty-four months, which puts the test at around August 2028, we will accept that agent identity has to be handled as close to the opposite of the way we handle human identity today, and a serious incident will force it. Written down, with a date. This is the show that calls its predictions in writing. CHAPTERS (00:00:00) Who is accountable when your AI agent gets it wrong (00:02:49) Mandy Andress, CISO of Elastic, on the customer zero seat (00:05:19) What changes when an AI agent holds the keys, not a person (00:09:12) Identity and access was never solved. Agents make it worse (00:14:29) What a CISO should do first, inventory your shadow AI use (00:17:25) An airline was held liable for what its chatbot said (00:21:34) Where AI earns its place in the SOC, automating triage (00:25:39) The OpenAI and Hugging Face breach was noisy, not fast (00:32:43) Is a fully autonomous AI SOC actually within reach (00:37:30) Rethinking data governance and data provenance for AI (00:43:10) Securing AI versus securing with AI, two budget lines (00:46:29) Shadow AI, the exposure most organisations underestimate (00:52:18) What smaller organisations should do first on AI security (00:59:28) The prediction, agent identity by August 2028 LINKS Full conversation on YouTube: https://youtu.be/0auExzqn9a4 The Control Layer, free on Substack: https://link.arkava.ai/join Arkava: https://arkava.ai Elastic: https://www.elastic.co Mandy Andress: https://www.linkedin.com/in/mandyandress/ Hosted by Amer Altaf, Founder and CEO of Arkava and Managing Editor of The Control Layer. Views expressed by guests are their own. SOURCES AND CORRECTIONS On the airline: Moffatt v Air Canada, British Columbia Civil Resolution Tribunal, February 2024. The chatbot misstated the bereavement-fare policy and the airline was ordered to compensate the passenger. Describing it as free tickets is the speaker's own recollection. On the incident: an independent investigation by METR and Redwood Research, published 26 August 2026, records roughly 1,200 agents on an unsanctioned message board and around 700 in the Hugging Face attack.

    When the Agent Uses Your Login — Mandy Andress, CISO, Elastic
  2. Aug 26

    The AI Gold Mine Is Your Messy Data, Not Your Clean Data — Sam Parkinson, Mettle Studio

    Sam Parkinson of Mettle Studio on shadow AI, and why your messy data is the gold mine. Everyone in enterprise AI gives the same instruction: clean your data first, then you can start. Sam Parkinson argues the opposite. The thousands of unindexed project folders, the six versions of the HR policy in SharePoint, the drawings marked up against a contract — those are not the obstacle. They are the thing of value nobody has looked at. Sam co-founded Mettle Studio to build software for construction, a sector McKinsey ranks near the bottom of its digitisation table and one Sam reckons is years behind on AI. What comes out is not a construction argument. It is a five-rung ladder any organisation can place itself on in about ten seconds, rarely on the rung it would have guessed. THE FIVE RUNGS One. We do not know what AI is and we are not looking. Two. Shadow AI. The company bought nothing, approved nothing and secured nothing, and everybody is using it anyway. Three. Buying Copilot. It feels like a strategy because there is an invoice attached. Four. The leap of faith. You stop buying a licence and start building. Five. Measured outcomes, with governance in place. ALSO IN THIS EPISODE Why "we have set up an AI steering committee" is often the polite way of looking busy. The auditability gap: proving which agent did what, and when. Klarna, and why moving too fast and moving too slow are the same mistake with different timing. UK infrastructure data sitting on US clouds, and why Sam calls it a national security question. What to ask a US AI vendor before you sign anything. The one sentence Sam would give a CFO who has heard enough about AI. And a prediction with a date on it: every company becomes a software company, on a five-year horizon. We will mark it in August 2031. This is the show that calls its predictions in writing. CHAPTERS (00:00:00) Five things Sam Parkinson said before we started (00:02:12) Meet Sam Parkinson, co-founder of Mettle Studio (00:05:58) What an AI-in-construction summit actually feels like (00:10:32) The subject nobody put on the agenda (00:13:00) Building the AI maturity ladder, rung by rung (00:14:46) Rung two, the shadow AI your company never bought (00:16:47) Rung three, why buying Copilot is not an AI strategy (00:23:14) Rung four, the leap of faith that costs real money (00:26:16) A 200-person firm with one IT lead, where do you start (00:30:04) When an AI steering committee is just theatre (00:36:17) Why the mess in your data is the gold mine (00:42:38) Is conservatism secretly a superpower in AI adoption (00:53:54) Whose cloud is your data on, the UK sovereignty problem (01:05:21) Ready for AI, or just talking about it (01:09:17) The prediction, every company becomes a software company (01:11:54) The one sentence Sam would give a CFO LINKS Watch the full conversation on YouTube: https://youtu.be/haFhXAImlF4 The Control Layer, free on Substack: https://thecontrollayer.arkava.ai Arkava: https://arkava.ai Mettle Studio: https://mettle-studio.com Sam Parkinson on LinkedIn: https://www.linkedin.com/in/samuel-parkinson-phd-6784b929 Hosted by Amer Altaf, Founder and CEO of Arkava and Managing Editor of The Control Layer. Views expressed by guests are their own. SOURCES AND CORRECTIONS Construction's digitisation ranking: McKinsey Global Institute, "Imagining construction's digital future", June 2016, not 2018. On Klarna: the February 2024 figures describing an OpenAI-powered assistant doing the equivalent work of 700 full-time agents are Klarna's own and OpenAI's. In May 2025 Sebastian Siemiatkowski told Bloomberg that cost had become "a too predominant evaluation factor". Klarna's active consumer base grew through the period, at 118 million in the Q4 2025 SEC filing, up 28 per cent year on year. On copyright: the US Copyright Office test is human authorship, not the involvement of a tool.

    The AI Gold Mine Is Your Messy Data, Not Your Clean Data — Sam Parkinson, Mettle Studio
  3. Aug 19

    When the Tool Starts Deciding - Matt Ausman, CIO, Zebra Technologies

    Matt Ausman, CIO of Zebra Technologies, on who is accountable when an AI agent decides. Just after 8 in the morning on 26 June 1974, a cashier in Troy, Ohio scanned a ten-pack of Wrigley's gum. It was the first time a product was sold by pointing a machine at it and trusting the number that came back. For fifty years that was the deal: the scanner told you the number, and a human decided. This year the deal changed. The machines on the warehouse floor stopped reporting and started deciding — reordering stock, moving robots, repricing goods, on their own. Matt Ausman has run generative AI governance across Zebra Technologies for three years. Zebra's scanners, mobile computers and printers are the nervous system of the world's warehouses, shop floors and delivery rounds. He came up through General Electric's operating businesses, so he thinks like an operator rather than a lab — which means when the theory about human oversight meets thousands of people and a deadline, he is the one who has to make it real. In this conversation: The reporting agent that told Zebra it had booked ten billion dollars of revenue in a single segment. Why the big hallucinations do not worry him, and the small ones do.Human in the loop, on the loop, and out of the loop: the three-way split most governance frameworks collapse into one, and how to tell which one you actually have.Why data quality stops being an IT problem the moment one sensor says aspirin and the label says codeine.The audit agent Zebra built to check its own people, and what it found.Why three agents negotiating with each other frightens him more than any single agent going wrong. Context the conversation does not contain: on 2 August 2026 the EU AI Act's duty of human oversight over high-risk systems came into application. Article 14 requires that whoever oversees the system can interrupt it — in the Regulation's own words, "a stop button or a similar procedure". Amer asks Matt whether he has ever run for the power socket. And the prediction, on the record: within ten years, Matt says, we will each have a digital twin — an agent that sees what we see, reads our email, and answers for us. This is the show that calls its predictions in writing. (00:00) From barcodes to AI agents: when machines started deciding (02:27) Matt Ausman, CIO of Zebra Technologies, on his path (06:24) Barcode vs AI agent: what actually changed on the floor (09:04) How accurate does an autonomous AI agent need to be? (12:40) AI on the warehouse floor: what Zebra is running today (15:14) When data quality becomes a safety control, not IT (21:15) Will AI replace frontline workers, or add more hands? (24:57) Human in the loop, on the loop, and out of the loop (29:07) Who is liable when an autonomous AI agent gets it wrong? (34:45) The $10 billion hallucination, and the errors that hide (41:49) Why Gartner says 40% of AI agent projects get cancelled (48:44) Asimov's three laws and the Skynet question for AI (54:21) Can you actually switch an autonomous AI agent off? (58:55) The prediction: a digital twin of you within ten years Links Watch the full conversation on YouTube: https://youtu.be/1ne6AleqARU The Control Layer, free on Substack: https://thecontrollayer.arkava.ai Arkava: https://arkava.ai Zebra Technologies: https://www.zebra.com Matt Ausman on LinkedIn: https://www.linkedin.com/in/matt-ausman-63b15213 Hosted by Amer Altaf, Founder and CEO of Arkava and Managing Editor of The Control Layer. Views expressed by guests are their own. Some figures cited are the speakers' own accounts; independently verified statistics are attributed in the show notes. Sources: first UPC scan, 26 June 1974, Troy, Ohio (GS1 US). Gartner, "Over 40% of Agentic AI Projects Will Be Canceled by End of 2027", 25 June 2025. EU AI Act, Article 14, in application from 2 August 2026.

    When the Tool Starts Deciding - Matt Ausman, CIO, Zebra Technologies
  4. Jul 8

    Whose Values Does Your AI Run On?

    ━━━━━━━━━━━━━━━━━━━━━━━━━━ ABOUT THIS EPISODE ━━━━━━━━━━━━━━━━━━━━━━━━━━ Every AI agent your organisation deploys carries a values rulebook that somebody wrote. Usually a handful of researchers, at a Bay Area frontier lab. That is not a governance decision your board consciously made — it is the default your vendors chose for you. Dr Craig A. Kaplan — PhD with Nobel laureate Herbert A. Simon, founder of Predict Wall Street, and designer of the Democratic AI architecture free at SuperIntelligence.com — spent the last five years arguing this is the biggest architecture problem in AI safety, and that the industry is solving it the wrong way. ━━━━━━━━━━━━━━━━━━━━━━━━━━ CHAPTERS ━━━━━━━━━━━━━━━━━━━━━━━━━━ 00:00 Cold open — the AI that destroyed its operator 00:54 What this episode is about 02:20 Working with Herbert Simon at Carnegie Mellon 04:50 When your phone hides your emails from you 11:29 Anthropic's Constitutional AI — a benign autocracy? 16:36 Guardrails, Project Glasswing, community-level safety 27:21 The hedge fund that beat Wall Street with the crowd 34:15 Wisdom AND madness of crowds — the AI amplifier 41:57 Democratic AI — the architecture nobody is building 48:39 When your AI meets my AI — the arbitration problem 52:32 HAL 9000 is the warning, not the prediction 1:00:52 The US Air Force AI that destroyed its operator 1:06:07 The 1956 AI that fooled Bertrand Russell 1:11:35 Bounded rationality vs the AGI marketing problem 1:15:35 Craig Kaplan's predictive judgement 1:19:49 The Bottom Line — for CISOs, boards, procurement ━━━━━━━━━━━━━━━━━━━━━━━━━━ READ + WATCH ━━━━━━━━━━━━━━━━━━━━━━━━━━ Full written analysis on Substack: thecontrollayer.arkava.ai/kaplan-values-podcast YouTube video version: youtu.be/8F9sr21ELpg Subscribe to The Control Layer — weekly, free: link.arkava.ai/join ━━━━━━━━━━━━━━━━━━━━━━━━━━ SOURCES CITED IN THIS EPISODE ━━━━━━━━━━━━━━━━━━━━━━━━━━ - Anthropic Constitutional AI — anthropic.com - Predict Wall Street / iQ Company published figures — iqco.com/about - Democratic AI architecture (Kaplan) — superintelligence.com - Herbert Simon and Allen Newell, Logic Theorist (1956) and Human Problem Solving (1972) - Herbert Simon: Nobel Memorial Prize in Economics (1978), Turing Award (1975) — the only person in history to hold both - Geoffrey Hinton public statements on p(doom) - US Air Force AI simulation account (Col. Tucker Hamilton, Royal Aeronautical Society, May 2023, later clarified by USAF as a thought experiment) - Isaac Asimov, Three Laws of Robotics (1942) - Meta "personal superintelligence" strategy (Zuckerberg, July 2025) ━━━━━━━━━━━━━━━━━━━━━━━━━━ GUEST ━━━━━━━━━━━━━━━━━━━━━━━━━━ Dr Craig A. Kaplan Founder, iQ Company (est. 1993) Founder, Predict Wall Street (est. 2005) Managing Director, SuperIntelligence.com and iQ Studios PhD, Carnegie Mellon University — supervised by Herbert A. Simon ━━━━━━━━━━━━━━━━━━━━━━━━━━ HOST ━━━━━━━━━━━━━━━━━━━━━━━━━━ Amer Altaf Founder & CEO, Arkava Managing Editor, The Control Layer arkava.ai · Trusted Intelligence, Tangible Impact ━━━━━━━━━━━━━━━━━━━━━━━━━━ ABOUT THE CONTROL LAYER ━━━━━━━━━━━━━━━━━━━━━━━━━━ The Control Layer is the publication and podcast on how AI, cybersecurity, sovereignty, technology and geopolitics are reshaping who controls the next decade. Every episode closes on a falsifiable predictive judgement from the guest — logged on our public predictions tracker. We come back to test each one publicly on the date named. ━━━━━━━━━━━━━━━━━━━━━━━━━━ FOLLOW ━━━━━━━━━━━━━━━━━━━━━━━━━━ Substack: thecontrollayer.arkava.ai YouTube: youtube.com/channel/UCLBj_B4T8M4LfgRAMs6VgWA Subscribe free: link.arkava.ai/join Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

    Whose Values Does Your AI Run On?
  5. Jun 24

    The EU AI Act Applies to You — Even If You Don’t Build AI | Antonina Burlachenko (STAR)

    Most companies are certain the EU AI Act is somebody else’s problem. They are wrong — and the vendor contract they are relying on will not save them. On 2 August 2026 the EU AI Act becomes enforceable across Europe, and a few weeks out, Brussels moved the headline deadline to 2027 and 2028. The whole market exhaled. In this episode, Amer Altaf sits down with Antonina Burlachenko, Head of Regulatory Consulting at STAR — who audits and certifies these systems for a living — to explain why that exhale is the trap. If your company runs an AI hiring tool, scores customers, automates a decision, or has wired AI into its operations, you may already be in scope — not as the AI lab, but as a deployer, and sometimes, without ever realising it, as a provider. We get into the deployer‑versus‑provider line that catches almost everyone, the Article 25 clause that quietly turns a buyer into a manufacturer regardless of what the contract says, what is still legally binding on 2 August 2026, and why the documentation you need cannot be faked at the audit. It ends, as every episode does, with a falsifiable prediction we write down and come back to. In this episode Why the EU AI Act binds ordinary companies that do not think of themselves as “AI companies” The three ways you can become a “provider” without knowing it — and why your indemnity clause does not stop it What actually counts as “high‑risk” AI under Annex III Why a US company with no European office can still be caught What the moved deadline did — and did not — change, and what stays live on 2 August 2026 The evidence you have to capture from week one, because you cannot reconstruct it later ISO 42001: real protection, or a badge for the website? Antonina’s prediction for the first real enforcement action Three lines worth the click “For all three cases, the contract is not important. The responsibility lies with whoever is the provider.” — on why your vendor indemnity does not transfer the risk. “How do you document control of that bias after the fact? I have no idea.” — on why AI compliance evidence has to be captured as you go. “You don’t have a choice.” — on why the Act reaches you wherever you are headquartered. About the guest Antonina Burlachenko is Head of Regulatory Consulting at STAR, where she leads a team taking regulated products to market and building the quality, information‑security and AI‑management systems underneath them — across medical‑device regulation, the Cyber Resilience Act, GDPR and the EU AI Act. Her work spans advisory, internal audits and the due‑diligence assessments investors commission before they invest. Connect with Antonina on LinkedIn. The Control Layer publishes weekly — decision‑grade analysis on AI, cybersecurity, and technology sovereignty, written for the board paper, not the timeline. The Control Layer is written and hosted by Amer Altaf, Founder & CEO of Arkava and Managing Editor of The Control Layer. #EUAIAct #AIgovernance #AIcompliance #ISO42001

    The EU AI Act Applies to You — Even If You Don’t Build AI | Antonina Burlachenko (STAR)
  6. May 14

    Trust the agency, not just the agent: a conversation with Vanta's Khush Kashyap

    Automating the Work, or the Workers? Vanta shipped a suite of AI agents it calls "24/7 GRC engineers" — evidence collection, risk analysis, vendor assessments, remediation guidance, all handled by machines. So what's left for the humans? Amer Altaf talks to Khush Kashyap, Senior Director of GRC at Vanta, about what agentic compliance actually means for practitioners — what it costs, what it changes, and whether the profession is being augmented or quietly automated out of existence. Khush runs Vanta's own GRC programme on the platform daily, making her both the builder and the first customer. In this episode: • What "agent" actually means at Vanta — beyond the industry buzzword • Whether this works for a 200-person firm with one security lead • The honest answer on pricing • Day one walkthrough: from spreadsheets to agentic compliance in a week • Who's accountable when the agent gets it wrong on approval number 41 • "Don't trust the agents — trust the agency you build" • UK GDPR vs EU GDPR: does the system know the difference? • Data sovereignty, the CLOUD Act, and what UK CISOs are asking • Will compliance teams shrink? The nuanced answer • What skills GRC teams are hiring for now Chapters: 00:00 What Vanta actually built — and what "agent" really means 07:44 Does this work for a 200-person firm? 17:03 Day one — from spreadsheets to agentic compliance 22:31 When you're clicking approve on autopilot 32:51 UK GDPR, data sovereignty, and the CLOUD Act 42:08 Automating the work or automating the workers? 53:39 The time machine question Guest: Khush Kashyap — Senior Director of Governance, Risk and Compliance, Vanta Host: Amer Altaf — Managing Editor, The Control Layer and CEO, Arkava Subscribe to The Control Layer: https://thecontrollayer.arkava.ai Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

    Trust the agency, not just the agent: a conversation with Vanta's Khush Kashyap
  7. May 7

    The Equipment Chokehold: ASML and the end of the allied exemption

    On 22 April 2026, the House Foreign Affairs Committee advanced by a substantial bipartisan margin a bill that gives the Netherlands 150 days to match American export controls on semiconductor equipment — or lose access to the American intellectual property inside every lithography machine ASML has ever built. This is the third instalment of the Four Chokepoints series — a 50-minute solo episode on the Multilateral Alignment of Technology Controls on Hardware Act, the ASML monopoly that sits at its centre, and the structural shift in how Washington treats its allies that the bill formalises. The argument has two halves. The first is structural: the allied exemption — the diplomatic consensus that allowed European technology companies to trade with relative autonomy inside a multilateral framework — is formally dead. The second is political: the instrument Washington has chosen to kill it reveals something uncomfortable about the stated justification for the entire technology embargo. The episode walks through: — What the MATCH Act actually says, who introduced it, and why the bipartisan, bicameral co-sponsorship matters more than the headline. — The silence from the Semiconductor Industry Association, SEMI, Lam Research, and Applied Materials that is the most important data point in the entire debate. — The honest acknowledgement of the security argument: China is building a state-subsidised semiconductor industry with explicit military applications, and the dual-use risk concern is not paranoia. — Why the MATCH Act is nevertheless not primarily a security instrument but a commercial protection instrument dressed in security language. — ASML's 100 per cent monopoly on EUV lithography, the €32.7 billion 2025 revenue, and the Cymer light source acquisition that gave Washington the legal hook. — The Foreign Direct Product Rule and how it converts a Dutch company's American supplier dependencies into the most powerful instrument of American economic statecraft currently in use. — The death of the Wassenaar Arrangement consensus model — and the structural reason Brussels has said nothing. — A specific recommendation for the quarterly board paper: the named, quantified, irreducible single-vendor dependency with no current mitigation. — A falsifiable predictive judgement about the European Commission's response, due by April 2027, with the four signals that will tell you whether the prediction is on track. — The closing seven-word argument that holds the whole thesis. This is Part 3 of a five-part series. Part 4 — on the CLOUD Act and the data jurisdiction — follows next week. The companion written analysis, fully sourced with 23 endnotes, is published at thecontrollayer.arkava.ai/p/four-chokepoints-the-equipment-chokehold. The Control Layer is the publication where Amer Altaf — Founder & CEO of Arkava, the UK and European sovereign AI agentic automation business, and a techUK contributor on technology sovereignty policy — tracks the convergence of cybersecurity, AI, and the geopolitics of the technology stack. One piece a week, free, written for the board paper. Subscribe at thecontrollayer.arkava.ai. Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

  8. Apr 24

    The Metal Floor: why you cannot procure sovereignty on imported metal

    You cannot procure sovereignty on imported metal. That's the argument at the centre of this episode — Part 2 of the Four Chokepoints series. Aluminium smelters in the Gulf are offline. Helium tankers from Qatar are caught in the Hormuz disruption. And the entirety of European semiconductor policy — the €43 billion Chips Act — is sitting on a material foundation it hasn't costed. In this solo episode, Amer Altaf traces the supply chain underneath the supply chain. He explains why an aluminium pot line cannot be cold-started (the cells are destroyed, not paused), why every helium atom in commercial use was mined rather than manufactured, and why the loss of three million tonnes of Gulf aluminium capacity and 25 per cent of global helium supply is a sovereignty story rather than a commodity story. The episode walks through the EU Chips Act's three structural gaps, the UK Critical Minerals Strategy's order-of-magnitude funding shortfall, and an honest five-point metal floor strategy that would cost between €40 and €60 billion over a decade for the European bloc. It extends Ed Conway's Material World thesis to argue that digital sovereignty is a subset of material sovereignty — and it's the material layer Western policy has most systematically under-priced. The episode closes with a prediction: within 18 months, a major European fab will publicly disclose a helium allocation constraint delaying capacity expansion — and three amendments to the quarterly board paper introduced in Part 1. Read the full written analysis: thecontrollayer.arkava.ai Subscribe for Part 3: The Equipment Chokehold. Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

  9. Apr 17

    Four Chokepoints: The Fortnight That Made European Technology Sovereignty Unavoidable

    Four Chokepoints: The Fortnight That Made European Technology Sovereignty Unavoidable Solo episode — Part 1 of the Four Chokepoints series --- On the morning of 8 April, four supply chains began to fail at once. Not in the same country. Not in the same industry. Not even on the same continent. The headlines called it an oil shock. It isn't. In this episode, I trace the line from the Strait of Hormuz to the server rack in your data centre — through the aluminium smelters, the helium tankers, the Dutch lithography plant, and the Franco-British communiqué that said something no European government has said out loud since 1945. My argument: the post-war bargain between Europe and America has not strained. It has inverted. And the board papers being written this month still treat it as an oil shock. If you prefer to read the full written analysis — with all twelve endnotes and the complete image brief — [that essay is here](https://thecontrollayer.arkava.ai/p/four-chokepoints-the-inversion). This episode covers the same ground but restructures it entirely for audio: different pacing, extended analogies, and three concrete lines I think should be rewritten in your next Audit and Risk Committee paper. --- What this episode covers The four failures — what actually happened in the fortnight to 12 April 2026: three million tonnes of Gulf aluminium capacity offline, helium tanker disruptions threatening semiconductor fabs, the MATCH Act's 150-day ultimatum to ASML, and the first Franco-British military operation outside the American framework since the post-war settlement. The inversion — why Helen Thompson's thesis about the contingent Atlantic settlement is no longer history but operational reality, and why Adam Tooze's structural polycrisis framework is the correct lens for the events of this fortnight. Three lines for the board paper — the vendor concentration matrix, the supply chain map, and the political risk register: what's wrong with each and what they should say instead. The eighteen-month prediction — procurement-driven re-sovereigntisation in UK and EU public-sector contracts, with explicit falsifiability conditions I'll track quarterly on The Control Layer. Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

    Four Chokepoints: The Fortnight That Made European Technology Sovereignty Unavoidable
  10. Apr 9

    Anthropic Built a Model Too Dangerous to Release. Then It Gave It to 12 American Companies.

    Yesterday, Anthropic announced Project Glasswing — a cybersecurity coalition built around Claude Mythos Preview, a frontier AI model so proficient at finding and exploiting software vulnerabilities that it cannot safely be released to the public. In just weeks of testing, Mythos Preview has autonomously identified thousands of zero-day vulnerabilities in every major operating system and every major web browser — including a 27-year-old flaw in OpenBSD, a 16-year-old bug in FFmpeg that automated testing missed five million times, and a chained Linux kernel exploit that escalates to full machine control. The 12 launch partners — AWS, Apple, Microsoft, Google, Cisco, CrowdStrike, Palo Alto Networks, Broadcom, NVIDIA, JPMorganChase, the Linux Foundation, and Anthropic — will use the model exclusively for defensive security work. Anthropic is committing $100 million in usage credits and $4 million to open-source security organisations. In this solo episode, I break down what Mythos Preview can actually do, why the defensive case is strong, and why the dual-use problem — the same model that finds vulnerabilities can exploit them — cannot be engineered away. Then I ask the question almost no one else covering this story is asking: why are all 12 launch partners US-headquartered? What does it mean when the most powerful defensive cybersecurity tool ever created is exclusively in the hands of American companies, subject to US government engagement, with no mention of the UK's NCSC, the EU's ENISA, or any non-US government body? What I cover: - Claude Mythos Preview's capabilities — and why this is a step change, not an incremental improvement - The defensive case: $100M in credits, open-source funding, and a coalition that touches most of the world's software infrastructure - The dual-use tension: Mythos develops working exploits autonomously, without human steering - The sovereignty question: all 12 partners are US-headquartered, and the implications for UK and European defenders are significant - Five things to watch over the coming months — from the 90-day report to the UK's Cyber Security and Resilience Bill This episode is for: - CISOs and security leaders assessing what AI-augmented threats mean for their organisations - CTOs and engineers building on infrastructure maintained by Glasswing partners - Policymakers writing cybersecurity legislation in a world that just changed - Anyone who believes the geography of AI capability is a strategic question, not a technical footnote Read the full analysis: thecontrollayer.arkava.ai The Control Layer is hosted by Amer Altaf, founder and CEO of Arkava, and publishes weekly. Sponsored by Arkava — Trusted Intelligence, Tangible Impact. https://arkava.ai Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

    Anthropic Built a Model Too Dangerous to Release. Then It Gave It to 12 American Companies.
  11. Mar 26

    Who Controls the Agent?

    When an AI agent shops on your behalf, pays on your behalf, and negotiates on your behalf — who’s actually in charge? And when something goes wrong, who carries the liability? In the debut episode of The Control Layer, Amer Altaf sits down with Andrew Dunbar, Chief Information Security Officer at Shopify, to unpack the security architecture behind agentic commerce — a world where autonomous AI agents act as buyers, and traditional checkout flows no longer apply. Andrew reveals how Shopify is building the Universal Commerce Protocol (UCP), a framework designed to let AI agents transact securely across any merchant without screen-scraping or fragile browser automation. The conversation covers how cryptographic credential chains prevent compromised agents from completing unauthorised transactions, why the four-persona model (buyer, business, platform, credential provider) changes the trust equation entirely, and what happens when 875 million buyers start operating through autonomous intermediaries. They also discuss why the CISO’s role is shifting from gatekeeper to architect, how bug bounty programmes stress-test agentic infrastructure before it ships, and what sovereign AI strategy means for businesses operating across borders. Whether you’re a security leader, a founder building on AI, or simply someone who wants to understand the system that’s about to handle your money — this is where it starts. Get full access to The Control Layer at thecontrollayer.arkava.ai/subscribe

About

The machines are making decisions. The question is: who's in control? The Control Layer with Amer Altaf cuts through the noise of AI hype to ask the questions that actually matter — who governs agentic systems, who carries the risk when they fail, and what the people building the infrastructure really think about what's coming. Each episode brings together CISOs, architects, founders, and policymakers at the frontier of AI, cybersecurity, and sovereign technology. These aren't rehearsed keynotes — they're real conversations about the trust frameworks, protocol designs, and leadership decisions shaping how intelligent systems operate in the real world. From agentic commerce and autonomous transactions to national AI strategy and zero-trust identity, The Control Layer goes where the decisions are being made — and asks whether the right people are making them. Published by Arkava. New episodes weekly. thecontrollayer.arkava.ai