I write about software architecture, artificial intelligence, and European compliance—the AI Act, digital sovereignty, sourcing—read as architecture to build, not as an obstacle to dodge.
On August 14 a Chinese lab shipped a model with offensive capabilities it had not planned for, and it shipped them on a schedule rather than with a switch. This is the moment the word "open" stops being enough.
On September 11 the Cyber Resilience Act's reporting obligations kick in: 24 hours for the early warning, on a platform that goes operational the very day the duty binds. No API, no test environment, an address that isn't public yet. Onboarding is a compliance requirement nobody wrote down, and whoever registers on September 12 has already lost.
Around the third month of using an agent, someone says the model has got worse. Almost always it isn't the model: it's the scaffolding, which came apart without throwing an exception. What degrades quietly is exactly what nobody is required to check, and in Europe, from September, that friction costs a non-conformity.
ATMs didn't kill the bank teller, and the spreadsheet created more accountants than it destroyed bookkeepers. The fastest typist in the office disappeared anyway. Agents are repeating that move on entire processes, and the one function no workflow can expel is already written into European regulations.
An Advanced rating measures an organisation’s maturity. It does not show that a specific product conforms to the CRA. The distinction is not self-assessment versus outside scrutiny. It is diagnosis versus a declaration that carries responsibility.
The Digital Omnibus pushed the AI Act's high-risk obligations to 2027, and healthcare software breathed a sigh of relief. But the pressure never came from that deadline: it comes from three clocks, enforcement, engineering and the market, and none of them was touched.
Five European regulations, written by different hands for different sectors, are converging on the same demand: prove you know what you have in the house. Whoever can't answer isn't non-compliant, they're ungovernable. And the inventory that's needed isn't compiled: it's generated.
On artificial intelligence as a political fact before a technical one, on the translation that never quite lands, and on what a country loses when it imports the words along with the machines.
On the Cloud and AI Development Act, on the ten thousand repositories dressed up as honest projects, and on the distance between being inspectable and actually being inspected.
Brussels moved a few AI Act deadlines and confirmed everything else. For a small or mid-sized IT company that had just started getting serious about compliance, this is the moment to accelerate, not to slow down.
On June 9 the Commission ordered Meta to reopen WhatsApp to rival AI assistants within five days. It is the rarest interim measure in European competition law, and it is a meditation on time disguised as an administrative order.
Apple says it can't bring Siri AI to Europe because it has to protect our privacy. The technical problem it invokes is real. The way it uses that problem is not—and the press release is a round of ammunition in a war that has stopped being merely regulatory.
My father never once told me he loved me. He showed me, and that was all, and it took me forty years and a child of my own to understand it. For once I am not writing about code or European rules.
I am an atheist, I come from philosophy, I work in European compliance. Leo XIV's first encyclical on artificial intelligence is not something I signed, it is something I argued with. And I found in it a vocabulary that Brussels still lacks.
The first national European standard on AI professional profiles was published on 30 April. It is worth taking seriously, and it is worth mistrusting in the right way.
At night I say no to my three-year-old who wants the tablet for a little longer. I say it for one specific reason, and from that reason a free book was born.
A map of the Italian compliance market drawn from the inside: specialist advisory at the top, platforms at the bottom, the middle layer crushed between them. And the one specifically Italian piece—ACN—that bends the rules.
A long reckoning with European digital regulation seen from the outside—by those who hate it—and a counter-reading from inside, by those who translate those rules into technical objects every working day.
On why the software supply contract, as we have known it, has stopped being the central instrument of the relationship between vendor and client — and how much it costs to keep pretending it still is.
On why the document that certifies the system ages worse than the code that implements it, and why the next generation of civil software-liability cases will be fought over the specification.
There's a diffuse tiredness we don't know how to name. It doesn't come from doing more: it comes from living inside a time that has lost its shape. AI doesn't speed the activity up — it replaces it with another, and the body, calibrated over years, can no longer read the day.
Treating regulatory compliance as the adversary of the technical project means you haven't understood what the technical project is. An essay on the category error weakening Europe's software industry — and on how the European framework, read as a system rather than as a list, configures a structural competitive advantage for those who learn to inhabit it.
The EDPB's DPIA template, released in April, isn't a longer form. It codifies a form. On the shift from module to genre, and what changes for anyone who writes compliance as continuous writing practice.
Buildings learn, Stewart Brand argued. Software, instead, accumulates comments that apologize. On why digital objects can't grow old — and what that says about the civilization that has put them at its center.
Cybersecurity is undergoing a transition that deserves more attention than it gets: online authentication is shifting from what you know to how you behave.
Nobody knows what they’re doing—not as a cliché, but as a structural fact: our technical systems are now too complex for any single person to understand.
A manifesto for people who build tech and are also parents: on engagement, attention extraction, and a simple rule—build as if your child were the user.
Three roles, three lenses on the IT market: corporate, startup, and a client portfolio. A non-linear path that clarifies what really matters in sourcing.