← Back to the news
How this is built
What is materially new in the privacy, security, legal and risk dimensions of AI: agentic systems, generative AI and LLMs, models and the model supply chain, and robotics and embodied systems?
Register last reviewed 2026-08-13 · 56 sources
How sources are weighted
Every source sits in one of three tiers. A claim rests on primary sources; the rest widen what gets seen and help confirm a story.
Primary
Original reporting or a primary document: research papers, CVEs and vendor security advisories, regulator and standards-body texts, first-party vendor engineering/security posts, and incident post-mortems. Weighted highest.
Secondary
Journalism and analysis that reports on primary sources: the security trade press and analyst blogs. Used for discovery and corroboration, not as the sole basis for a claim.
Tertiary
Aggregators and community surfaces (subreddits, link aggregators, roundups). Used to widen recall and surface items the curated feeds miss; every hit is confirmed against a primary or secondary source before it enters the store.
What gets in
- Published within the last 10 days on a daily run; the window is widened by hand when a run comes back thin.
- Carries a privacy, security, legal or risk angle on AI. Capability and product news is out unless it does: a faster model or a funding round is not this beat.
- Covers agents, generative AI and LLMs, models and the model supply chain, or robotics and embodied systems.
- Verifiable: the item must trace to a fetchable page, and for the deep synthesis the underlying paper is read in full.
- Deduplicated by URL; a material update to a known story is a new item.
What stays out
- Vendor marketing with no technical or policy substance.
- Capability, benchmark and funding news with no privacy, security, legal or risk angle.
- Stories older than the window on a normal run.
- Paywalled items that cannot be verified.
How a story gets here
The counts here are read out of the running configuration when this page is generated. They describe the pipeline as it stands today.
- Collect. A scheduled job runs once a day, reads all 54 feeds and 2 query APIs, and keeps anything published in the last 10 days.
- Filter on keywords. A plain text match, with no model involved. 38 feeds must match both an agentic-AI term and a privacy, security or legal risk term. 13 regulator and standards feeds need only the risk term, because their wording rarely says "agent". 3 low-volume release feeds skip the gate.
- Drop what has been seen. URLs are normalized and compared against everything already stored. A story that circulates for a week is recorded once.
- Select and summarize. What survives goes to claude-opus-5, which picks what to keep and writes the summary and the per-lens notes. Any item whose URL is not taken verbatim from the candidate list is discarded before it is stored. The model cannot introduce a source of its own.
- Score on three lenses. Each item is rated 0–3 for privacy engineering, security, law and risk independently, given an overall importance of 1–5, and tagged from fixed vocabularies of 11 security, 11 privacy, 10 legal and 10 risk subtopics. Tags outside those vocabularies are discarded.
- Write the digests. A daily digest is generated for each lens. Once a week a deeper pass fetches the articles and papers themselves and reads them in full.
Each card carries a full text read or from abstract marker. Day to day, summaries are written from the title and abstract the source published in its own feed. Only the weekly pass opens the article itself.
What this cannot do
The keyword gate in step two is the weakest part. An attack described in language nobody uses yet will not match, and nothing downstream can recover a story that was never collected. Reviewing the register on a cadence is partly meant to catch that.
The summaries are written by a language model. They can be wrong, or can flatten a detail that mattered. Every card links to its source, which is the authority. Coverage is English-language and weighted toward the sources below, mostly EU and US regulators.
The sources
The full register, kept in the open. Each daily run reads these feeds plus the query APIs below, then an AI pass selects and summarizes what is genuinely new. Most feeds are keyword-filtered first for agentic-AI privacy, security, and legal relevance. Primary regulator and standards feeds skip that gate and go straight to the AI pass, since their wording rarely says "agent".
Primary 29
A2A protocol changes at the source
academic preprints (keyword-filtered)
cloud vendor security (primary)
biometrics, face recognition and digital identity; the main trade outlet for the surveillance beat
cloud/agent security guidance
EU data-protection regulator (primary)
digital-rights advocacy and analysis
Johann Rehberger; leading agent-exfiltration research
US privacy litigation, comments and legislative tracking; covers AI and biometrics directly
EU Commission; AI Act at the source
US enforcement (primary)
privacy think tank
cloud vendor security (primary)
AAIF agent framework; changes at the source
governance of the agentic stack; the Agentic AI Foundation (MCP, goose, AGENTS.md) is a directed fund here and has no feed of its own
official MCP announcements
MCP spec changes at the source
NIST guidance and framework work, including AI-enabled vulnerability management
EU privacy-enforcement advocacy
model vendor announcements
OWASP LLM/agent security standards
agent connector/data-flow research
security + policy analysis
threat research
high-signal agent/LLM security commentary and original tests
appsec/supply-chain research and product
deep technical audits
vendor threat research
cloud/agent security research
Secondary 23
privacy/tech investigative journalism
monthly MCP/agent CVE roundups
tech press AI desk
agent-security work often publishes under AI, not CR (keyword-filtered)
ML-side attacks and PETs (keyword-filtered)
multi-agent systems: agent-to-agent trust and delegation (keyword-filtered)
robotics and embodied systems; strict gate so only privacy/security work surfaces
agent tooling and supply chain (keyword-filtered)
security press
security press/analysis
AI safety/policy analysis
security press
security press + product
privacy profession news
AI policy/research newsletter
AI engineering newsletter
open-source supply-chain security; kept on the strict gate so only agent/AI items surface
security leadership analysis
security news digest
security press
security press
security + policy journalism
tech press AI desk
Tertiary 2
community aggregator
community aggregator
Query APIs 2
arXiv API securityprivacy primary
targeted queries: LLM-agent privacy, MCP, prompt injection, multi-agent security
Hacker News (Algolia) security tertiary
points-thresholded story search; catches feedless blogs
Keeping it honest
The register is audited on a regular cadence. The audit checks that every feed is still reachable and flags the ones that have gone quiet. It also looks for gaps the current list would miss. Feeds get added, moved between tiers, or dropped on that evidence, and the change takes effect on the next daily run.
The register is a single configuration file, and this page is generated from it on every run. The source list, the counts, the filter split and the model name above are read out of the live configuration. Add a feed or change a rule, and this page changes on the next build.