The Hamberger Report Weekly #10: Shown, Not Proven

VerifiedIntelligence

Edition 10 · Week ending 2026-09-26
THR
The Hamberger Report Weekly

Shown, Not Proven

The Red Thread

Seven artefacts this week each stand in for a harder question they do not answer alone. A vendor register tracks purchases, not what a team installed itself. A sustainability index sharpens while no treaty obliges anyone to reverse the decay it measures. A public pledge on evaluator access sits beside a private narrowing of access for an evaluator that already had it. A new statute names who answers for free code, on two different clocks. Ninety-eight per cent of surveyed firms hold a governance policy; under half report following it under pressure. A support contract binds the packager, never the open-source foundation beneath it, and a new AI code of conduct refuses default trust in unverified content without checking it against anything outside itself. On this week's evidence, the pattern is a gap between what an organisation can show and what it can prove.

Executive Digest
Cyber Guide for NZ Boards

Nobody Put the Reporting Tool on the Register

Six organisations across five countries were breached through the same open-source tool, and none had it on a vendor register: a register built to track purchases misses self-installed software.

Read the full analysis

Space AI Monday

Orbital Debris: The Sustainability Index Just Went From Four to Fifty

ESA's own orbital sustainability index worsened tenfold in a single year, while no treaty obliges anyone to remove what is already up there: the measurement got sharper, the accountability gap did not close.

Read the full analysis

Gen AI 2026

Permanent Access, Except For You

The same week Anthropic's chief executive pledged permanent evaluator access, the company had reportedly narrowed pre-release access for an evaluator it already had: a pledge and a private decision are different things.

Read the full analysis

History of Linux

Fifteen Months Behind the Manufacturer

The EU's Cyber Resilience Act makes manufacturers report vulnerabilities within 24 hours but gives open-source stewards fifteen months' grace: the first time a government, not a market, has said who answers for free code.

Read the full analysis

EA in the Agentic Age

AI Governance: The Exception Log Boards Should Be Asking For

Ninety-eight per cent of surveyed firms have a formal AI governance policy; forty-seven per cent admit setting it aside under pressure at least once, proof a document exists, not that anyone follows it.

Read the full analysis

Free as in Theft

Selling What You Give Away: Open Source Under Every AI Vendor

Red Hat's 1999 listing proved a company can sell certified access to code it does not own.

Read the full analysis

Project V.E.R.A.

AI Verification: Tool Output Carries No Authority

Microsoft's new draft governance code denies AI tool outputs default authority, a written rule that refuses trust but never checks content against an outside source, and governs no model that has yet shipped.

Read the full analysis

The Boardroom Question

Which of your organisation's governance artefacts, a register, a policy, a pledge, would survive being asked not whether it exists, but whether anyone can prove it held the last time it mattered?

Te Pono Limited · The Hamberger Report.Content stays true.
Next
Next

The Hamberger Report Weekly #9: The Control That Covers Half the Job