Tech & Cyber Desk
TECHJuly 20, 2026

Tech & Cyber Desk

Daily tech and cyber brief: silicon pulse, chip sheet, cipher desk, regulatory wire, and horizon-lab lenses.

AI-generated analysis from Apprised's automated desks, synthesized from cited sources and editorially accountable to . How we report · Corrections.

← Tech & Cyber Desk (latest)

Tech/Cyber Desk — voice emphasis (word count) TECH/CYBER DESK — VOICE EMPHASIS (WORD COUNT) Cipher Desk 278 w Silicon Pulse 318 w Horizon Lab 324 w The Regulatory Wire 302 w Tripwire 309 w

Chart auto-generated from this brief's structured fields. See methodology for how the underlying data is collected.

Bottom Line

Microsoft's July 2026 Patch Tuesday fixed a record 570 security flaws—nearly triple last month's count—while four on-premises SharePoint Server vulnerabilities (including CVE-2026-58644, CVSS 9.8) are under active exploitation confirmed by CISA. Microsoft attributed the surge in patch volume to AI-assisted vulnerability discovery, making this the clearest signal yet that AI is simultaneously accelerating both offense and defense.

Bias-reviewed: LOW Independently rated by Kimi for political-lean, source-diversity, and framing bias before publish. Final orchestration and the published call are made by Claude, a U.S. model.

Grid interconnection queue — MISO

Compute buildout is gated by grid interconnection, not by chip supply alone. This is the queue that AI datacenter capacity has to clear. Deterministic; computed from the published queue, no model involved.

  • 221,772 MW active in the queue, but only 2.8% has reached an advanced study stage.
  • 79.7% of all resolved megawatts withdrew rather than reaching service.
  • Of 562 completed interconnection agreements, 271 have not started construction and 92 are generating — a signed agreement is not a power plant.
  • Queue entry to an executed agreement runs 3.3 years (n=388); queue entry to actually in service, 3.1 years (n=90).

MISO only, and it is used because it publishes withdrawn and completed requests rather than just the live queue. Full figures and caveats on Signals; raw JSON at /api/iso-queue.

Today’s Snapshot

Microsoft's record 570-flaw patch drop anchors a week of AI-amplified cyber risk

Microsoft's July 2026 Patch Tuesday addressed a record 570 security vulnerabilities—nearly triple the prior month's record—with the company explicitly attributing the surge to AI-assisted discovery pipelines. Simultaneously, four Microsoft SharePoint Server vulnerabilities are under active exploitation, with CVE-2026-58644 (CVSS 9.8, unauthenticated remote code execution via deserialization) confirmed by CISA as the lead threat. Check Point Research's AI Security Report 2026 documented a structural shift: AI has crossed from attack assistant to attack operator. Netflix's $587 million acquisition of Ben Affleck's AI filmmaking startup InterPositive and China's Kimi K3 demand surge (Moonshot AI suspending new subscriptions) round out a week where the AI capability curve is visibly outrunning both security controls and governance frameworks.

Synthesis

Points of Agreement

Cipher Desk and Horizon Lab both read Microsoft's AI-assisted vulnerability discovery as the week's most structurally significant signal—not a patch count story but a capability story about AI finding novel vulnerability classes in production. Silicon Pulse and Horizon Lab agree that Kimi K3's demand surge represents genuine competitive pressure on U.S. AI providers, not manufactured hype. Tripwire and Cipher Desk converge on the 'AI as operator' transition documented by Check Point as a threshold event that changes the defender calculus, not just the attacker toolkit. The Regulatory Wire and Tripwire agree that governance frameworks—federal AI inventory requirements and agentic AI oversight architectures alike—are being outrun by deployment velocity.

Points of Disagreement

Horizon Lab and Tripwire disagree on how to read Check Point's 'AI as operator' claim: Horizon Lab flags vendor incentive structures and notes that 'operator' in current deployments likely means something more modest than full autonomy, while Tripwire treats the structural dynamic—pressure to remove human oversight to match adversarial tempo—as dangerous regardless of whether current systems have crossed that threshold. Silicon Pulse is skeptical of the Netflix/InterPositive valuation but reads the acquisition as a strategic signal; The Regulatory Wire would note the governance vacuum around AI-generated content that the deal exposes, a dimension Silicon Pulse under-weights. Cipher Desk and Horizon Lab tension: Cipher Desk reads the -7-day mean time-to-exploit as a detection-and-response problem, while Horizon Lab reads it as a capability signal about AI-assisted offensive tooling—both are correct but the policy implications diverge sharply.

Pivotal Question

What would move Horizon Lab's cautious read of 'AI as operator' toward Tripwire's structural alarm? Evidence that adversarial AI systems are selecting targets and techniques without per-step human authorization in confirmed incident data—not threat intelligence vendor characterization, but forensic reconstruction from actual intrusions. Conversely, what would move Tripwire toward Horizon Lab's more measured framing? Peer-reviewed capability evaluations showing that current AI attack tooling still requires substantial human scaffolding at the target-selection and technique-adaptation stages.

Bias Flags

  • Cipher Desk: Conservative on attribution; may under-weight criminal actor probability for the SharePoint exploitation cluster in favor of persistent-access nation-state framing despite absence of confirmed attribution indicators.
  • Horizon Lab: Academic skepticism of vendor-produced threat reports (Check Point, Unit 42) may cause under-weighting of operationally significant capability shifts that haven't yet appeared in peer-reviewed literature.
  • The Regulatory Wire: Regulatory-centric framing may over-weight the DHS inventory compliance failure as evidence of systemic governance collapse, when it may reflect normal federal bureaucratic lag rather than structural breakdown.
  • Tripwire: Safety-first lens reads the 150,000-agents-by-2028 projection as an oversight catastrophe in waiting; may under-weight the possibility that enterprise agent deployments are narrow-scope automations with limited blast radius, not frontier-model autonomous agents.
  • Silicon Pulse: Skepticism of launch-day marketing may cause under-weighting of the Netflix acquisition's genuine strategic significance if InterPositive has proprietary AI filmmaking technology not yet publicly demonstrated.

Routing

Voices seated: Cipher Desk, Silicon Pulse, Horizon Lab, The Regulatory Wire, Tripwire

The week is dominated by a SharePoint vulnerability cluster with active exploitation (Cipher Desk primary), a record Microsoft patch release with AI-assisted discovery framing (Cipher Desk + Silicon Pulse + Horizon Lab), Netflix's $587M AI filmmaking acquisition (Silicon Pulse), the AI-as-operator security shift documented by Check Point (Tripwire + Cipher Desk), and OpenAI/Anthropic governance posturing (Regulatory Wire + Tripwire). Cross-cutting AI safety and agentic risk threads require minimum three voices.

Analyst Voices

Cipher Desk Katya Volkov

Bias flag

Four SharePoint Server vulnerabilities under simultaneous active exploitation is not a routine patch cycle—it's a targeting pattern. CVE-2026-58644 is the CISA KEV lead: CVSS 9.8, unauthenticated RCE via deserialization of untrusted data (CWE-502), confirmed actively exploited in the wild as of Microsoft's July 14 advisory. But the Tenable FAQ is the more operationally significant document: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are being chained—unauthorized access, RCE establishment, IIS machine key theft, malware deployment. That kill chain is not opportunistic commodity scanning. Machine key theft specifically enables persistent session forgery across an entire SharePoint farm. Attribution confidence is low, but the technique set skews toward persistent-access operators, not ransomware staging.

The record 570-flaw Patch Tuesday deserves separate treatment. Microsoft's own explanation—AI-assisted vulnerability discovery—is the signal, not the patch count. When your internal red team tooling finds vulnerabilities faster than your patch pipeline can absorb them, you've created a disclosure debt that adversaries can race against. Mandiant's M-Trends 2026 data point is the sharpest edge here: mean time-to-exploit has gone negative, to -7 days. Patches are arriving after exploitation has already begun. That's not a patching problem. That's a detection-and-response problem dressed up as a patch problem.

The Siemens ROX II zero-day trilogy from Unit 42 deserves a separate flag for the OT community: three chained vulnerabilities allowing privilege escalation and persistent root access on operational technology switches. OT environments patch on maintenance windows measured in months, not days. The gap between disclosure and remediation in industrial environments is where nation-state actors have historically made their most durable investments. The Inc ransomware group's exploitation of SonicWall SMA zero-days this week adds the criminal-actor layer to a week already saturated with state-adjacent indicators.

Four actively exploited SharePoint CVEs being chained for machine-key theft and persistent RCE, combined with a -7-day mean time-to-exploit, means defenders are structurally behind regardless of patch velocity.

Bias flag — Conservative on attribution; may under-weight criminal actor probability for the SharePoint exploitation cluster in favor of persistent-access nation-state framing despite absence of confirmed attribution indicators.

Silicon Pulse Ava Chen & Derek Moss

Bias flag

Netflix paid $587 million in cash for InterPositive, Ben Affleck's AI filmmaking startup. Read that sentence carefully. Five hundred and eighty-seven million dollars. Cash. For a startup co-founded by a movie star whose primary qualification in technology is playing Batman. The press release says this is about AI-native content creation. What it actually says is that Netflix is willing to pay nine-figure sums to own the tooling layer of AI filmmaking before the market prices it properly. That's a strategic land-grab, not a product validation. We'll reserve judgment on whether InterPositive's actual technology justifies the price until we see what it does in production at Netflix scale—but the acquisition price signals how seriously Hollywood's dominant streamer is treating AI-generated or AI-assisted content as an existential capability gap.

On the developer side, xai-org/grok-build hit 19,339 stars on GitHub in its first week—a Rust-based coding agent harness and TUI from xAI. That's real developer momentum, and Rust as the implementation language is a deliberate signal about performance and safety priorities. The Codex-Dream-Skin repo at 9,932 stars is harder to read—it's a JavaScript skin, not a capability—but both together suggest the Grok ecosystem is generating genuine builder enthusiasm post-SpaceX IPO, even as traders are reportedly beginning to short the stock. The pixel-point/aval interactive video format repo (TypeScript, 1,220 stars) is the sleeper: a new open-source format for interactive video with built-in state machines and frame-accurate transitions could matter significantly for AI-generated interactive content—exactly the space Netflix just paid $587M to enter.

Kimi K3's demand surge is the China story of the week. Moonshot AI suspending new subscriptions because of capacity constraints on Kimi K3 is a real demand signal, not manufactured hype. The question—as always with Chinese frontier models—is whether the capability is genuine frontier or whether it's frontier-adjacent at a fraction of the cost. The answer matters for U.S. AI competitiveness more than any single American product launch this week.

Netflix's $587M InterPositive acquisition signals that Hollywood's dominant streamer is making a nine-figure bet on owning the AI filmmaking tooling layer before the market prices it, regardless of whether the technology currently justifies the valuation.

Bias flag — Skepticism of launch-day marketing may cause under-weighting of the Netflix acquisition's genuine strategic significance if InterPositive has proprietary AI filmmaking technology not yet publicly demonstrated.

Horizon Lab Dr. Sonia Park

Bias flag

The Check Point AI Security Report 2026 contains the most structurally significant claim of the week: AI has transitioned from attack assistant to attack operator. That framing maps onto something real in the capability literature—the difference between a tool that accelerates human-directed attacks and an autonomous system that selects targets, chooses techniques, and executes without per-step human authorization. If Check Point's characterization is accurate, we've crossed a threshold that the AI safety community has been tracking as a key risk escalation point. The report should be read carefully, however: threat intelligence vendors have commercial incentives to dramatize capability shifts, and 'AI as operator' in current deployments likely means something more modest than fully autonomous attack pipelines.

Microsoft's attribution of its record 570-flaw patch count to AI-assisted vulnerability discovery is, paradoxically, the most credible signal of AI capability advancement this week. This is not a benchmark. This is production deployment of AI-assisted code analysis finding real, exploitable flaws in the most widely deployed enterprise software stack on earth. The capability is generalized enough to find novel vulnerability classes, not just pattern-match known CVE signatures. That's a meaningful capability signal—one that cuts both ways, since the same tooling deployed by adversaries produces the negative mean time-to-exploit figure from Mandiant's M-Trends data.

Moonshot AI's Kimi K3 demand surge, forcing a subscription pause, is worth tracking as a capability signal rather than a business story. Chinese open-weight model releases have repeatedly produced genuine capability advances at cost points that compress U.S. API pricing. If Kimi K3 represents another step in that trajectory, the competitive pressure on OpenAI and Anthropic's pricing power is real and near-term. The Stanford HAI framing around AI accelerating scientific discovery—CardiOmicScore from University of Hong Kong predicting cardiovascular disease 15 years early by analyzing thousands of proteins and metabolites, Google DeepMind's bioresilience program with 15+ institutional partnerships—represents the quieter but more durable capability story: AI as a genuine scientific instrument, not just a productivity layer.

Microsoft's AI-assisted discovery of 570 real, exploitable vulnerabilities in its own codebase is a more credible capability signal than any benchmark this week—it demonstrates production-grade AI that finds novel vulnerability classes at scale.

Bias flag — Academic skepticism of vendor-produced threat reports (Check Point, Unit 42) may cause under-weighting of operationally significant capability shifts that haven't yet appeared in peer-reviewed literature.

The Regulatory Wire James Whitfield

Bias flag

The DHS AI inventory update from FedScoop is the regulatory story that's being underweighted this week. Months past the statutory deadline, the Department of Homeland Security has 'generally' filled in risk management sections for high-impact AI use cases—while simultaneously walking back some deployment statuses and sunsetting others. Translation: a federal agency responsible for national security infrastructure cannot produce an accurate, timely inventory of its own AI deployments. The gap between the Biden-era AI governance executive order's inventory requirements and DHS's actual compliance posture is a case study in how regulatory mandates decay in execution. The Trump administration's disposition toward that executive order's requirements makes the enforcement trajectory even less predictable.

Anthropicand OpenAI are both running governance positioning plays this week. Anthropic's 'Inviting hard questions' post asks 'Who decides the rules for AI?'—a framing that sounds like humility but functions as a bid to be the interlocutor that gets to answer that question. OpenAI's CFO Sarah Friar's 'scorecard for the AI age' introduces an ROI framework measuring 'useful work, cost per successful task, dependability, and return on compute'—which is a sensible business metric but is conspicuously silent on safety and governance metrics at a moment when the company's safety practices are under scrutiny. The European Parliament's decision to open its doors to models from OpenAI, Meta, Anthropic, and Mistral while trying to bring lawmakers' 'growing use of the technology under control' is the EU's characteristic regulatory posture: regulate and adopt simultaneously, hoping the adoption informs the regulation.

The gap between OpenAI's and Anthropic's public governance narratives and the actual enforcement environment remains vast. The EU AI Act's high-risk category requirements are on paper; enforcement machinery is nascent. In the U.S., there is no comparable statutory framework. The law says proceed with caution. Enforcement says proceed. The gap is where the industry actually operates.

DHS's late, incomplete AI inventory—walking back deployment statuses months past deadline—reveals that federal AI governance mandates are dissolving in execution precisely as AI deployment in national security contexts accelerates.

Bias flag — Regulatory-centric framing may over-weight the DHS inventory compliance failure as evidence of systemic governance collapse, when it may reflect normal federal bureaucratic lag rather than structural breakdown.

Tripwire Dr. Hana Sundqvist

Bias flag

The Dark Reading piece—'The Real AI Threat Is Blind Trust'—puts the safety-case framing correctly: AI models that both interpret and execute commands eliminate the critical oversight layer that any meaningful safety architecture requires. This is the agentic AI control problem in its practical form, not the theoretical form. The SecurityWeek podcast on 'Broken Governance, Agentic AI' and Tenable's Gartner-cited projection—Fortune 500 enterprises averaging 150,000 AI agents by 2028, up from fewer than 15 in 2025—describe a deployment trajectory that is functionally incompatible with the governance infrastructure that currently exists. You cannot build oversight mechanisms for 150,000 agents using the review processes designed for 15.

Check Point's 'AI as operator' characterization, if accurate, describes a safety-case failure in the adversarial domain that has immediate implications for defensive AI deployment. If offensive AI can operate autonomously, then defensive AI that requires human-in-the-loop authorization at each step is structurally disadvantaged. The pressure to remove human oversight from defensive AI systems—in the name of matching adversarial tempo—is the most dangerous dynamic in the current threat environment. The argument 'we must automate defense because offense is automated' is technically coherent and safety-catastrophic.

OpenAI's teen safety announcement deserves a look beyond the press release. The claim of 'age-appropriate protections, learning tools, and parental controls' is a governance gesture toward a real problem—AI systems that were not designed with adolescent users in mind being deployed to them at scale. The safety case here is not about catastrophic risk; it's about the ordinary harm of systems that optimize for engagement over accuracy deployed to users with developing critical faculties. The independent model study finding AI advice made people less accurate but more confident is directly relevant: that's not a teen-specific failure, but it's acutely dangerous for teen users. We don't grade the demo. We grade the safety case. OpenAI's teen safety case is incomplete without independent evaluation.

The projection of 150,000 AI agents per Fortune 500 enterprise by 2028—up from fewer than 15 today—describes a deployment velocity that is structurally incompatible with any oversight architecture that currently exists.

Bias flag — Safety-first lens reads the 150,000-agents-by-2028 projection as an oversight catastrophe in waiting; may under-weight the possibility that enterprise agent deployments are narrow-scope automations with limited blast radius, not frontier-model autonomous agents.

Simulated Opinion

If you had to form a single opinion having heard the roundtable, weighted for known biases, it would be this: the week of July 14-20, 2026 marks a structural inflection in AI's relationship to cyber risk—not because of any single vulnerability or product launch, but because AI has simultaneously compressed attacker timelines (mean time-to-exploit at -7 days per Mandiant), expanded the defender's attack surface faster than patches can absorb it (570 flaws in a single Microsoft cycle, AI-attributed), and begun operating as an autonomous layer in both offense and defense with governance architecture built for a prior era. The 150,000-agent projection and the DHS inventory failure are symptoms of the same condition: deployment is running a minimum of two governance cycles ahead of accountability. Netflix's $587M bet on AI filmmaking and Kimi K3's subscription-straining demand are the consumer-facing expression of the same dynamic. The SharePoint exploitation cluster is the operational reality underneath the capability narrative. A careful reader should be more worried about the control gap than about any single CVE—and should note that the organizations best positioned to close it (Microsoft, OpenAI, Anthropic) are also the organizations with the strongest commercial incentives not to slow down.

Independent Cross-Check — Kimi

A separate AI model (Kimi) independently read the same corpus. Agreement corroborates the desk's read; divergence flags a contested story. 1 China-sensitive story was withheld from it.

Consensus 14   Contested 1

Netflix paid $587 million for Ben Affleck’s AI filmmaking startup Consensus

Multiple sources including techcrunch.com and other tech news outlets are reporting the same details about the acquisition.

AI can be repeatedly fooled into mistaking non-life for life Consensus

The event is reported by space.com and other science news outlets, indicating a broad consensus on the research findings.

Homeland Security’s updated AI inventory raises more questions than it answers Consensus

The update on Homeland Security’s AI inventory is covered by multiple security and government-focused news sites, indicating a settled factual basis.

Microsoft SharePoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild Consensus

CVE-2026-58644 is reported by multiple cybersecurity outlets, indicating a broad consensus on the vulnerability and its exploitation.

Bunkerhill raises $55M to scale agentic AI across health systems Consensus

The funding round is reported by artificialintelligence-news.com and likely other financial news outlets, suggesting a settled factual basis.

Sophos Fusion: A Complete AI-Native Cyber Defense System Consensus

The launch of Sophos Fusion is covered by cybersecurityventures.com and likely other cybersecurity news outlets, indicating a broad consensus.

AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report Consensus

The report summary is covered by unit42.paloaltonetworks.com and likely other cybersecurity outlets, suggesting a settled factual basis.

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Active Exploitation of Microsoft SharePoint Server Vulnerabilities Consensus

The active exploitation of these vulnerabilities is reported by tenable.com and other cybersecurity outlets, indicating a broad consensus.

Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review Consensus

The security updates are covered by blog.qualys.com and other cybersecurity news outlets, suggesting a settled factual basis.

Microsoft Patches a Record 570 Security Flaws Consensus

The record number of patches is reported by krebsonsecurity.com and other cybersecurity outlets, indicating a broad consensus.

AI Security Report 2026 indicates vulnerabilities are often exploited before patches Consensus

The report findings are covered by research.checkpoint.com and likely other cybersecurity outlets, suggesting a settled factual basis.

Iran Tracks US Military Phones Contested

This claim is reported by securityweek.com but lacks corroboration from other sources, making its factual basis contested.

AI powers citizen-led disaster relief from afar for Venezuela Consensus

The use of AI in disaster relief efforts is reported by restofworld.org and other tech news outlets, indicating a broad consensus.

Inc Ransomware Exploits SonicWall SMA Zero-Days Consensus

The exploitation of SonicWall vulnerabilities is reported by darkreading.com and other cybersecurity outlets, indicating a broad consensus.

July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Consensus

The Patch Tuesday updates are covered by crowdstrike.com and other cybersecurity news outlets, suggesting a settled factual basis.

Watch Next

  • Black Hat USA 2026 presentations on AI-assisted vulnerability research and supply chain attacks—Microsoft and Tenable both have formal sessions; expect disclosure of additional CVEs and attack chain demonstrations that could expand the SharePoint exploitation cluster.
  • CISA follow-on advisory for CVE-2026-58644 and the SharePoint machine-key theft chain—watch for federal civilian agency patch compliance deadlines and any binding operational directive.
  • Kimi K3 capacity restoration by Moonshot AI and any accompanying technical disclosure—benchmark comparisons against GPT-4o and Claude 3.5 class models will determine whether the demand surge reflects genuine frontier capability or cost-arbitrage adoption.
  • Netflix/InterPositive integration announcement or first product deployment signal—the $587M valuation requires a near-term demonstration of what InterPositive's AI filmmaking technology actually produces at scale.
  • Inc ransomware group's SonicWall SMA zero-day exploitation chain—watch for victim disclosure, CISA KEV addition, and whether the two chained vulnerabilities receive CVE IDs and CVSS scores in the NVD pipeline this week.

Historical Power Lenses

Thomas Edison 1847-1931

Edison industrialized invention—he didn't wait for breakthroughs to arrive, he built a systematic pipeline at Menlo Park to produce them on schedule. Microsoft's explicit attribution of 570 discovered vulnerabilities to AI-assisted discovery is the Edison moment for defensive security: vulnerability research is being industrialized, removed from the heroic individual researcher model and inserted into a production pipeline. Edison's insight was that this approach compounds—each discovery feeds the next. The risk he didn't fully reckon with is that his competitors could industrialize the same process, as Westinghouse demonstrated. The -7-day mean time-to-exploit is the Westinghouse answer to Microsoft's Menlo Park.

Andrew Carnegie 1835-1919

Carnegie's decisive competitive advantage was vertical integration—owning the ore, the rails, the mills, and the distribution, so that no competitor could undercut his cost structure at any single layer. Netflix's $587M acquisition of InterPositive follows Carnegie logic: own the AI tooling layer for content creation before it becomes a commodity input that competitors can purchase at the same price. Carnegie understood that the moment a production input becomes a market commodity, your margin lives upstream of it. Netflix is betting that AI filmmaking capability is still pre-commodity, and that owning the tooling layer now is cheaper than licensing it later when every studio has the same access.

Sun Tzu 544-496 BC

Sun Tzu's maxim—'supreme excellence consists in breaking the enemy's resistance without fighting'—describes the SharePoint exploitation pattern precisely. The machine-key theft technique identified in the CVE-2026-32201/CVE-2026-45659/CVE-2026-56164 chain doesn't destroy the target environment; it enables persistent session forgery, meaning the attacker lives inside the defender's own authentication infrastructure indefinitely. The attacker wins not by breaching and exiting but by becoming indistinguishable from legitimate users. Sun Tzu would recognize this as the superior form of victory: the defender's walls are intact, the gate is locked, and the enemy has had a key for months.

William Randolph Hearst 1863-1951

Hearst built his empire on the insight that narrative control is power—that the frame around a story matters more than the facts it contains. OpenAI's CFO introducing an 'AI scorecard' measuring ROI through 'useful work' and 'return on compute,' and Anthropic's simultaneous 'Inviting hard questions' post, are Hearst-level framing operations: both companies are publishing the vocabulary through which their own regulation will be debated. Hearst understood that whoever sets the terms of the conversation wins before the argument begins. The DHS AI inventory failure—governance without enforcement—is what happens when the regulated party writes the regulatory frame and the regulator lacks the institutional capacity to rewrite it.

Sources Cited

20 sources — show

Other desks

Intelligence DeskMarkets DeskDefense & Security DeskEnergy & Climate DeskInsurance DeskHealth & Science DeskCulture & Society DeskSports DeskWorld DeskLocal WirePolitics Desk