Blog

Straight talk on local AI

Context, hands-on knowledge and clear positions on sovereign AI, knowledge management and data protection — written for decision-makers at data-sensitive companies.

Timeline of Fable 5: launch on 9 June, worldwide shutdown on 12 June via export control, global return on 1 July — with a note that Mythos 5 returns only for around 100 US organizations and that the 30-day retention with no zero-data-retention remains.Sovereign AI

Fable 5 is back — and why data sovereignty matters more than ever

Fable 5 is back: on 1 July 2026 Anthropic re-enabled the model worldwide, a day after the US Department of Commerce lifted its export controls. The good news does not refute the lesson — it sharpens it. A frontier model was switched off worldwide within 72 hours by a non-public government letter, it took a lawsuit and two weeks to bring it back, and the mandatory retention with no zero-data-retention remains. Availability is rented; control is owned.

Diagram contrasting a remote frontier model in the cloud with a local AI stack grounded in your own documents, in the Lokalaise RASTER style.Sovereign AI

Fable 5 is here — and why the strongest AI model alone isn't enough

Anthropic unveiled Fable 5, the most capable publicly available AI model to date — and it was gone within days. What the episode reveals about frontier models, digital sovereignty and the real lever: AI grounded in your own knowledge.

Diagram of German AI supervision: a central Bundesnetzagentur node with the roles of market-surveillance authority, notifying authority and coordination and competence centre, with a status stamp Bundestag 11 Jun 2026, Bundesrat pending.AI Law

KI-MIG: who supervises artificial intelligence in Germany?

On 11 June 2026 the Bundestag passed the KI-MIG and designated the Bundesnetzagentur as Germany's central AI supervisor — as of 26 June 2026 only the Bundesrat's approval is still missing. We explain what the law governs, who will supervise what, which fines Germany itself sets versus those that come from the EU regulation — and what it means for regulated companies.

List of the ten OWASP agentic risks ASI01 to ASI10 in the Lokalaise RASTER style, marking the four risks reducible by a local architecture — ASI02, ASI03, ASI04 and ASI05 — and the limit at ASI01 Agent Goal Hijack driven by prompt injection.AI Security

OWASP Top 10 for agentic AI 2026: what a local, outbound-free architecture actually mitigates

In December 2025 OWASP released the first Top 10 for agentic AI (Version 2026, ASI01–ASI10). Using CVE-2025-6514 (mcp-remote, CVSS 9.6) and the GitHub MCP attack, we show which of these risks a local, outbound-free architecture with least privilege actually mitigates — and where, with ASI01 Agent Goal Hijack, the honesty limit lies. No tool replaces the operator's responsibility.

Two data paths for a client secret: via a US cloud AI with possible access under the CLOUD Act, or via a local AI on your own hardware with no provider access, in the Lokalaise RASTER style with the marks § 203 StGB, § 43e BRAO and 18 U.S.C. § 2713.AI in Law Firms

Sovereign AI for law firms: § 203 StGB, the US CLOUD Act and the DAT 2026 sovereignty debate

At the German Bar Association's DAT 2026 in Freiburg, Markus Beckedahl warned: no German office and no GDPR seal protects against the US CLOUD Act. At the same time, per a vendor survey, most AI-savvy firms use generic tools like ChatGPT. We explain what § 203 StGB and § 43e BRAO really require, why US providers are the core of the problem — and how sovereign, local AI keeps client confidentiality in-house. Not legal advice.

The prominent figure 50 percent: the share of doctors using private AI tools like ChatGPT for research, in the Lokalaise style with context tiles 28 percent and 54 percent.AI in Healthcare

Shadow AI in the clinic: why 50% of doctors use ChatGPT — and how sovereign AI keeps patient data in-house

Half of the doctors surveyed use private AI tools like ChatGPT — mostly for research. That isn't a discipline problem but a tool vacuum: a heavy documentation burden meets a missing compliant alternative. We read the Doctolib numbers correctly, explain why patient data must not go into a consumer cloud AI under Art. 9 GDPR and § 203 of the German Criminal Code — and how a local, sovereign AI opens the compliant in-house path.

The prominent figure 42 percent: the share of AEC companies naming data security as the biggest AI hurdle, in the Lokalaise style with context tiles 69 percent and 27 percent.AI in Construction

AI in construction: why 42% of the AEC sector call data security the biggest hurdle

The most-cited AI hurdle in construction isn't a technical problem, it's a trust problem: 42% of AEC decision-makers name data-sharing security as the biggest challenge — ahead of cost and complexity. At the same time, adopters see clear ROI. We frame the Bluebeam numbers honestly and show why construction firms in particular can't tip their project data into other people's clouds — and how a local AI resolves the conflict.

The prominent date 2 August 2026, split into the deferred high-risk deadlines and the still-applicable transparency obligations under Article 50.AI Law

2 August 2026: the AI deployer checklist — what stays binding despite the Digital Omnibus

Many read the Digital Omnibus as "everything is delayed". Wrong: the transparency obligations under Article 50 of the AI Act apply from 2 August 2026 — and they bind deployers, not just providers. We separate deferred from binding, explain the provider/deployer distinction, and give you a checkable checklist.

The prominent figure plus $670,000 as the surcharge per breach from shadow AI, in the Lokalaise style with metric tiles.AI Security

Shadow AI costs $670,000 more: what the IBM report means for regulated companies

IBM has put a price on ungoverned AI: breaches with high shadow-AI use cost $670,000 more on average. One in five breaches now involves shadow AI. We translate the numbers into a budget and risk case — and show why bans make it worse and a sanctioned, local AI removes the costliest variable.

An AI assistant ingests injected content and exfiltrates private data through a trusted-looking channel to an attacker — an image of a data leak.AI Security

When the AI assistant becomes the data leak: what EchoLeak and SearchLeak teach

One click on a real microsoft.com link — and the mailbox, MFA codes and files are at the attacker's. SearchLeak (June 2026) and EchoLeak (2025) reveal a pattern. We explain the lethal trifecta, why these leaks work, and what a local, permission-aware AI changes about the attack surface — and what it doesn't.

A sovereignty scale from data residency through operational autonomy to legal sovereignty, referencing the BSI C3A criteria catalogue.Cloud Sovereignty

BSI C3A: When is a cloud truly sovereign?

On 27 April 2026 Germany's BSI published the C3A criteria catalogue — the first yardstick for when a cloud is truly sovereign. We unpack 'Cyber Dominance', the six dimensions of sovereignty, and why data residency is not data sovereignty.