Insights · Briefings for regulated firms
Two clocks are running on your firm. Here is what they say.
The first clock is cryptographic: the UK NCSC expects your migration plan by 2028 and your migration finished by 2035. The second is regulatory: the EU AI Act's transparency obligations apply from 2 August 2026, and the agents your staff already use leave questions a regulator will eventually ask. These briefings answer both — in plain English, with every claim tied to a primary source you can check.
Post-Quantum Cryptography
For firms whose client files must stay confidential longer than today's encryption will last. Companion site: pqc.asimov-ai.org.
Your client files have a 2035 deadline — and it isn't yours to negotiate
The NCSC timetable, the EU roadmap, and why for a 5–50 person firm this is a supplier-management exercise you must still evidence.
Harvest now, decrypt later: a file stolen in 2026 is still a breach in 2040
Professional confidentiality has no expiry date. Retrospective decryption is the threat that exploits exactly that.
You commissioned bespoke software. No one is coming to update it for you
The category of quantum risk most guidance skips: the client portal an agency built in 2018, and the migration nobody owns.
The five questions to put in your next IT-vendor renewal
A copy-paste supplier letter and a traffic-light grid for case-management, e-signature, email and backup vendors.
What actually breaks: a managing partner's map of RSA in a modern practice
Which parts of your stack fix themselves and which need attention — portal, email, VPN, signatures, archives.
The 2028 homework: a cryptographic inventory without hiring a cryptographer
A half-day exercise and a spreadsheet template aligned to the NCSC's first milestone.
Signed today, disputed in 2039: e-signatures, deeds and probate documents
Future forgery of classical signatures, and what to ask your e-signature vendor about ML-DSA.
UK vs EU vs Germany: one firm, three quantum clocks
For firms with cross-border clients: run to the earliest applicable clock — it is usually a client's, not a regulator's.
Agentic AI & the Service Firm
AI agents now do research and knowledge work. These briefings cover what that changes: identification and authorization of agents, human-in-the-loop supervision, the benefits, the pitfalls, and the audit trail.
The agent did the research. Who signed the opinion?
A tribunal has already rejected "the bot did it". What sign-off must capture when an agent drafts the work.
Engagement letters for robots: what delegated authority actually means
Agent identity and authorization explained through the trainee analogy — who authorised the act, and can you prove it.
The audit trail is the product: EU AI Act logging before August 2026
Automatic logging is becoming a legal duty, there is no finished technical standard, and your chat tool doesn't retain what you think.
Your firm already has 90 employees you've never met
Non-human identities outnumber staff. What an agent register looks like, modelled on lateral-hire onboarding.
47% as good as your associates, 100× cheaper — and wrong in ways you won't notice
The honest capability numbers, and the review-sampling regime that turns "human in the loop" into evidence.
Prompt injection is your new social-engineering problem
Your clients' documents are the attack vector. Containment, not trust — and the incident playbook.
No new rules ≠ no rules: SM&CR, Consumer Duty and the partner who owns the agents
A named senior manager already owns agent risk, whether or not anyone told them.
From pilot to policy: an ISO 42001-shaped operating model for agents
The 90-day plan: register agents, assign sponsors, define sign-off gates, switch on logging, sample-review.
Not sure where your firm stands? A 30-minute AI Risk Diagnostic with a named practitioner establishes your exposure. No charge, no jargon.
Book an AI Risk Diagnostic