
What GDPR actually requires from any company deploying AI agents
Most teams shipping an AI agent in Europe treat GDPR as a checkbox at the end of the project: add a cookie banner, write a privacy policy, done. That's not what
Deeper dives into how we build and what we've learned.

Most teams shipping an AI agent in Europe treat GDPR as a checkbox at the end of the project: add a cookie banner, write a privacy policy, done. That's not what

"Agentic AI" gets thrown around loosely enough that it's worth being precise about what actually happens when an agent decides to take an action, instead of jus

Every healthcare software vendor says their product is "secure." Almost none of them can explain what that word actually covers. For an AI agent that touches pa
Radiology is one of the few corners of medicine where AI has moved past pilot projects into daily clinical use in some hospitals — and also one of the clearest

The pitch for a healthcare AI agent usually assumes a clean, unified patient record sitting somewhere waiting to be queried. In practice, that record doesn't ex

The traditional security model for a hospital network assumed a hard perimeter: firewall the outside world out, trust everything inside. That model was already
Anyone can wire an agent up to a large language model in an afternoon. The hard part — the part most agent builders skip — is what happens to your data once tha

Telemedicine solved a real access problem — patients who couldn't easily reach a clinic can now see a doctor from home. It also created a category of privacy ri

A consumer smartwatch tracking your heart rate is a lifestyle gadget. The same sensor, prescribed by a cardiologist to monitor a patient recovering from a proce

A model that's right 95% of the time but can't say why is, for most clinical uses, less useful than a simpler model that's right 85% of the time and can point t

No organization plans to have a breach. Every organization handling health data should have a plan for what happens in the first 72 hours after discovering one

Replacing a manual monthly roster with an automated one sounds simple until you actually sit with the department that owns the current process. Here's what we l

ArcCare exists because clinics don't always have reliable internet, and a medical records app that stops working without a connection is worse than useless — it
An agent that can read or change anything in a system is a much bigger risk than the human employee it's assisting, because it can act at machine speed and does

A CRM agent's whole job is to touch sensitive information: deal values, contact details, internal notes about why a prospect went cold. Getting the automation r
No client has ever opened a conversation with "make sure I can audit every action your agent takes." They ask for it the first time something looks wrong and th

Locate Me is a small app with one job: share your location with people you trust, reliably, without draining the battery or leaking that data anywhere it should

7aba FPS is our firstperson shooter built on top of the OpenFPS Godot framework. Game dev isn't our main line of work, but building it taught us things that sho

Streaming recommendation engines have a reputation problem: they either feel eerily precise or embarrassingly wrong. We wanted MagicStream to feel useful withou

The pitch for a "knowledge base agent" is easy to say and easy to get wrong: an agent that answers questions using your own documents, policies, and records ins