<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Kai Hackbarth · Reading list</title>
    <link>https://kaihackbarth.com/reading</link>
    <atom:link href="https://kaihackbarth.com/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Five pieces a week on industrial AI, IoT and European tech sovereignty, each with Kai Hackbarth's own commentary.</description>
    <language>en</language>
    <lastBuildDate>Thu, 03 Sep 2026 06:00:00 GMT</lastBuildDate>
    <item>
      <title>On 11 September the update path becomes a legal duty</title>
      <link>https://kaihackbarth.com/reading-2026-08-30</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-08-30</guid>
      <pubDate>Sun, 30 Aug 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on the Cyber Resilience Act, because on 11 September the update path stops being a good idea and becomes a legal duty. What exactly has to be reported and by when, where the report lands and how late the instructions for it arrived, what &quot;actively exploited&quot; really means, the two paragraphs of the regulation that put your installed base in scope, and the open-source dispute that is still unresolved. Curated and commented, not aggregated.</p><ol><li><strong>European Commission</strong> — <a href="https://digital-strategy.ec.europa.eu/en/policies/cra-reporting">Cyber Resilience Act: Reporting obligations</a><br/>The primary source, and short enough that every product owner should read it once themselves. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. Early warning within 24 hours, full notification within 72, final report no later than 14 days after a corrective measure is available. The part that gets underestimated: the clock starts once a prompt initial assessment gives you reasonable certainty, and the Commission expects that assessment immediately, not at your next release date. Anyone without a process that produces a first report inside one working day does not have a future compliance problem. They have one from September.</li><li><strong>ENISA</strong> — <a href="https://www.enisa.europa.eu/topics/product-security-and-certification/single-reporting-platform-srp">Single Reporting Platform (SRP)</a><br/>Where the report actually lands, and the reason this particular date makes me uneasy. ENISA’s Single Reporting Platform is meant to be operational on 11 September, with every national CSIRT getting its own notification endpoint inside it. The registration guide for authorised representatives carries a revision date of 3 August 2026. Five weeks between the instructions for the platform and the duty to report through it. The 24-hour clock does not wait for your access to be set up. Registration is not a formality for later, it is the first task.</li><li><strong>usd AG</strong> — <a href="https://www.usd.de/en/cyber-resilience-act-reporting-obligations-sep-2026/">Cyber Resilience Act: Reporting Obligations from September 2026</a><br/>The practical read that settles the definitional question every discussion gets stuck on. Phillip Ansorge, Managing Security Consultant at usd AG, sets out what &quot;actively exploited&quot; means: evidence of real attacks, not theoretical exploitability. Proof-of-concepts and research results are not enough. That is less of a relief than it sounds, because it inverts the task. You have to be able to tell whether a vulnerability is actually being exploited across your installed base. Anyone who does not observe their devices in the field cannot answer that question, and from September will have to answer it anyway.</li><li><strong>Regulation (EU) 2024/2847</strong> — <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">Article 69(3) and Article 13(8) and (9)</a><br/>The regulation itself, because the distinction that matters usually gets lost in the summaries. Article 69(2) says products placed on the market before 11 December 2027 come under the regulation only if they are substantially modified from that date on. Paragraph 3 takes that straight back for reporting: Article 14 applies to all of them. So your installed base falls under the reporting duty from September even if you never touch it again, and the Commission’s guidance is explicit that no Annex I vulnerability handling duty comes with it. Report yes, fix no. For anything placed on the market after that date, Article 13 applies: the support period has to reflect how long the product is expected to be in use, and five years is the floor rather than the answer. Recital 60 names industrial settings specifically. Sell a machine against a twenty-year service life and you are arguing for twenty years of vulnerability handling, not five.</li><li><strong>LWN.net</strong> — <a href="https://lwn.net/Articles/1023306/">Open source and the Cyber Resilience Act</a><br/>The part that was fought over hardest and stayed least clean. The regulation creates the open-source steward, a distinct role for organisations that carry a project without being manufacturers, but where commercial activity begins exactly is still unclear. The thought from the discussion that captures the position best: a manufacturer using a thousand open-source projects is responsible for fixing bugs in a thousand projects. I spent four years on the OSGi board and four on the steering committee at the Eclipse Foundation. Governance for shared code does work. It just does not come about by passing liability downwards.</li></ol>]]></description>
    </item>
    <item>
      <title>Standards outlive platforms</title>
      <link>https://kaihackbarth.com/reading-2026-08-23</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-08-23</guid>
      <pubDate>Sun, 23 Aug 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on standards, platforms and middleware — and on which of them will still be load-bearing in ten years. The moment MCP was given away, the industrial answer to it, an alliance doing it right, the historical lesson about captured standards, and what none of the new protocols can do. Curated and commented, not aggregated.</p><ol><li><strong>Anthropic</strong> — <a href="https://www.anthropic.com/news/donating-the-model-context-protocol-and-establishing-of-the-agentic-ai-foundation">Donating the Model Context Protocol and Establishing the Agentic AI Foundation</a><br/>The primary source on the standards moment of the year: Anthropic handed the Model Context Protocol to the Linux Foundation’s Agentic AI Foundation, co-founded with Block and OpenAI, with AWS, Google, Microsoft, Cloudflare and Bloomberg in the platinum tier. The numbers explain why: over 10,000 active public servers and more than 97 million SDK downloads a month. My uncomfortable reading: this was not given away out of altruism but at exactly the right moment — once the protocol had already won and neutral governance was worth more than control. That is smart strategy, and it deserves to be called that.</li><li><strong>OPC Foundation</strong> — <a href="https://opcfoundation.org/news/press-releases/opc-foundation-advances-opc-ua-for-the-ai-era-with-companion-specifications-optimized-for-agentic-ai/">Companion Specifications Optimized for Agentic AI</a><br/>The industrial answer that almost nobody in the AI feed picks up: the OPC Foundation is making over 430 Companion Specifications RAG- and MCP-ready, positioning OPC UA as the semantic layer between agents and the plant. Exactly the gap we discussed here in July — an agent is only as good as the context it can reach. The difference from the software world: these information models have existed for years, from CNC machines to packaging, with cross-vendor semantics. Industry does not have to invent the context. It only has to make it reachable.</li><li><strong>LoRa Alliance</strong> — <a href="https://lora-alliance.org/lorawan-news/lora-alliance-unveils-3-year-roadmap-for-scaling-lorawan-globally/">A Three-Year Roadmap for Scaling LoRaWAN Globally</a><br/>How an alliance does standardisation properly, with dates rather than declarations of intent: satellite discovery and walk-by reading in 2026, crypto agility in 2027, a standard application data format in 2028. The last one is the most interesting — it removes exactly the custom integration that makes every LoRaWAN project more expensive than it needs to be. Over ten years of alliance discipline, incidentally, is why LoRaWAN is still here while much from the same era is not.</li><li><strong>Greg Wilson</strong> — <a href="https://third-bit.com/2026/05/20/standards/">Setting the Standard</a><br/>The most uncomfortable read of the week, and the most historically literate: Wilson traces railroad gauges through &quot;embrace, extend, extinguish&quot; to Apple’s handling of Android messaging, showing how reliably standards get captured. His line belongs in every architecture review: every choice between an open standard and a proprietary API is a bet on the future behaviour of the platform that owns the API — and history says it is a bad bet. I spent four years on the OSGi board and four on the Eclipse steering committee. The technically better standard does not win. The one with better distribution wins.</li><li><strong>Kang &amp; Diponegoro</strong> — <a href="https://arxiv.org/abs/2606.31498">Governance Gaps in Agent Interoperability Protocols</a><br/>And the fact-based critique to close, the one missing from the protocol euphoria: the authors test five interoperability protocols against six governance dimensions and find that voting and the preservation of dissent are absent in all of them, with deliberation partial at best. Their conclusion: governance for agent communities is a missing architectural layer above today’s standards — not something you retrofit with a few fields in a spec. Anyone wiring agents together today is wiring technology without a constitution. In regulated industry that is precisely the question procurement will ask.</li></ol>]]></description>
    </item>
    <item>
      <title>New roles, or just new names?</title>
      <link>https://kaihackbarth.com/reading-2026-08-16</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-08-16</guid>
      <pubDate>Sun, 16 Aug 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on a question two readers raised here: which roles is AI genuinely creating — and which are simply being renamed? The fight over forward deployed engineering, what boards are actually restructuring, the one function that did not exist before, the academic finding, and Europe’s reality check. Curated and commented, not aggregated.</p><ol><li><strong>Steve Banker · Forbes</strong> — <a href="https://www.forbes.com/sites/stevebanker/2026/07/10/palantir-and-forward-deployed-engineering-what-should-we-believe/">Palantir and Forward Deployed Engineering: What Should We Believe?</a><br/>Exactly the question Stefan Kiendl put to me here a few weeks ago: is forward deployed engineering genuinely new, or consulting with a fresh label? Banker gives both sides — Palantir has grown its commercial business to 46% of revenue on the model, while Anaplan’s CEO dismisses it as sales theatre: a polished POC, a nice dashboard, and then engineers you pay for in perpetuity, plus lock-in. My reading: both are true. The role is old — complex B2B always had solution engineering. What is new is the proportion. When a model carries 46% of revenue, it has stopped being a job title and become a business model.</li><li><strong>IBM Institute for Business Value</strong> — <a href="https://newsroom.ibm.com/2026-05-04-ibm-study-ceos-are-reshaping-c-suite-roles-for-the-ai-era">CEO Study 2026: Reshaping C-Suite Roles for the AI Era</a><br/>What boards are actually doing, from 2,000 CEO interviews across 33 countries: three quarters of organisations have a Chief AI Officer in 2026 — a year ago it was around a quarter. 85% say every functional leader must become technology-literate. So titles are being created fast; the question is whether accountability sits behind them or only a signal. The most honest finding comes last: 83% say success depends more on people’s willingness to adopt than on the technology. That matches everything I see in mandates.</li><li><strong>Daniel Keller</strong> — <a href="https://danielkeller.com/tech/verification-not-generation/">Verification Is the New Bottleneck — Not Generation</a><br/>And here is the function that genuinely did not exist before. Keller’s line is the best of the week: &quot;Generation is a commodity. Verification is a moat.&quot; When AI writes the code, the bottleneck moves from producing to checking — he would put 30% of engineering resources into generation workflows today and 70% into verification infrastructure. Wolfgang Strunck told me last week that his firm is piloting exactly that as a role: someone who defines and verifies what counts as an outcome. When the same function appears simultaneously as a product feature and as a job description, it is structural.</li><li><strong>Wang, Wei &amp; Wang</strong> — <a href="https://arxiv.org/abs/2605.23159">Generative AI and the Reorganization of Labor Demand</a><br/>The academic finding behind the intuition: generative AI does not displace uniformly, it reorganises demand. The authors decompose employment change into shifts between occupations and shifts within them — and find both. For the roles debate that means most &quot;new roles&quot; are old roles with recomposed task bundles. That is not reassuring, quite the opposite. Rebuilding tasks is organisationally much harder than posting a vacancy.</li><li><strong>Golo Henseke · UCL</strong> — <a href="https://arxiv.org/abs/2604.18849">From Exposure to Adoption: Generative AI in European Workplaces</a><br/>The European reality check to close, drawing on the European Working Conditions Survey: there is a considerable gap between workers being exposed to generative AI and actually using it in daily work — and it varies sharply by country and sector. So before we argue about new org charts: across much of European industry the technology has not arrived in daily work yet. The roles debate is running ahead of reality. That is not an argument for waiting, but for settling usage first and structure second.</li></ol>]]></description>
    </item>
    <item>
      <title>Pricing when the AI does the work</title>
      <link>https://kaihackbarth.com/reading-2026-08-09</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-08-09</guid>
      <pubDate>Sun, 09 Aug 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on the question every software company is wrestling with right now: how do you price something that does the work itself? The thesis, the data, the toolkit, the accounting reality — and what manufacturing already knows from experience. Curated and commented, not aggregated.</p><ol><li><strong>Bessemer Venture Partners</strong> — <a href="https://www.bvp.com/atlas/the-ai-pricing-and-monetization-playbook">The AI Pricing and Monetization Playbook</a><br/>The thesis of the week, well argued: software is no longer a tool that extends human capacity — it completes work itself. So pricing shifts from access to outcome. The number that explains everything else: AI companies see 50 to 60 percent gross margins against 80 to 90 for classic SaaS. Every model call costs real money — a cost line that did not exist in the SaaS era. Bessemer’s recommendation is refreshingly unromantic: hybrid. A base fee covering fixed costs, an outcome component for the upside.</li><li><strong>Kyle Poyar · Growth Unhinged</strong> — <a href="https://www.growthunhinged.com/p/the-state-of-b2b-monetization-in-2026">The 2026 State of B2B SaaS and AI Monetization</a><br/>The data behind the thesis, from 230 companies: hybrid is already the most common model at 37 percent, AI margins average 50 percent, and a third plan to introduce AI credits within six to twelve months. The finding that interests me most sits there almost in passing: AI spending is mostly cannibalising existing software budgets rather than unlocking new ones. Anyone who believes AI opens a fresh pot of money is in fact selling against the budget the customer already has.</li><li><strong>Manny Medina · Growth Unhinged</strong> — <a href="https://www.growthunhinged.com/p/ai-agent-pricing-framework">A New Framework for AI Agent Pricing</a><br/>The most usable toolkit in the debate: four models — per agent, per action, per workflow, per outcome — drawn from an analysis of 60-plus agent companies. The sharpest commercial observation in it: pricing per agent draws on the headcount budget, which is at least ten times larger than the tools budget. Outcome pricing has the strongest customer alignment but demands clean attribution. That is where most negotiations actually break down — not on the price, but on who measured the result.</li><li><strong>Deloitte</strong> — <a href="https://dart.deloitte.com/USDART/home/publications/deloitte/industry/technology/accounting-outcome-based-pricing-agentic-ai">Accounting for Outcome-Based Pricing in Agentic AI</a><br/>The unglamorous part almost nobody reads amid the excitement: how do you actually book outcome pricing? Under ASC 606 revenue becomes variable consideration that must be estimated and constrained — operationally complex and volatile. And behind it the real question: do you owe continuous availability of the agent, or a specified quantity of successful outcomes? Without contractually clear success criteria, an elegant pricing model turns into an accounting problem. Pricing models rarely die in the market. They die in the back office.</li><li><strong>Korkeamäki, Kohtamäki &amp; Parida</strong> — <a href="https://www.sciencedirect.com/science/article/pii/S0148296321002113">Worth the Risk? Outcome-Based Services and Manufacturer Profit</a><br/>And now the part Silicon Valley overlooks: manufacturing already ran this experiment. Rolls-Royce has been selling flight hours instead of engines since the 1960s. This study in the Journal of Business Research (2021) analysed 1,566 manufacturers and finds that providers of outcome-based services carry on average 4.4 percentage points higher gross margin — but the large ones earn less, unless they invest heavily in digital servitization. That is exactly the curve AI companies are driving onto: outcome pricing is attractive until it scales. Switching to outcomes today does not buy you a price tag, it buys you an operating model.</li></ol>]]></description>
    </item>
    <item>
      <title>The AI Act is here, just not the one everyone expected</title>
      <link>https://kaihackbarth.com/reading-2026-08-02</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-08-02</guid>
      <pubDate>Sun, 02 Aug 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on the EU AI Act — parts of which became enforceable this Sunday, while many believe the whole thing was postponed. What applies since 2 August, what was actually deferred, what else changed, the practical checklist, and the technical reality underneath. Curated and commented, not aggregated.</p><ol><li><strong>European Commission</strong> — <a href="https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content">Guidelines on Transparency Obligations (Article 50)</a><br/>The primary source, published four days before it took effect — and the reason this week matters: since 2 August, the Article 50 transparency obligations apply. A chatbot has to identify itself as a machine, synthetic content needs machine-readable marking, deepfakes and unreviewed AI text on matters of public interest must be labelled. Alongside it a Code of Practice: follow it, or demonstrate &quot;alternative equivalently adequate means&quot;. Read the original, not the summaries — and treat it as a design input, not legal cleanup after the fact.</li><li><strong>Pinsent Masons</strong> — <a href="https://www.pinsentmasons.com/out-law/news/law-delaying-eu-high-risk-ai-rules-finalised">Law Delaying EU’s High-Risk AI Rules Finalised</a><br/>The part everyone heard — and from which most drew the wrong conclusion. Now final: stand-alone high-risk systems (Annex III) have until 2 December 2027, AI embedded in regulated products (Annex I) until 2 August 2028, and watermarking for systems already on the market until 2 December 2026. For my world Annex I is the one that counts: machinery, medical devices, vehicles — the longest runway of all. But a runway is not a cancellation, and anyone reading it as a pause will be two years behind in 2027.</li><li><strong>Gibson Dunn</strong> — <a href="https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/">EU AI Act Omnibus: Postponed Deadlines and Other Key Changes</a><br/>The details almost nobody reported. The AI-literacy obligation was softened (companies must support the development of literacy, not guarantee a level), a new Article 5 prohibition targets &quot;nudifiers&quot; and abuse imagery — and the underrated one: the EU AI Office gains new enforcement tools, including investigations and on-site inspections. The deadlines slip while the teeth grow. Anyone reading &quot;simplification&quot; as &quot;deregulation&quot; is misreading the package.</li><li><strong>Blythe &amp; Dodding · Sidley</strong> — <a href="https://datamatters.sidley.com/2026/06/24/eu-ai-act-transparency-obligations-preparing-for-compliance-by-2-august-2026/">Transparency Obligations: Preparing for Compliance by 2 August 2026</a><br/>The most usable practical checklist I found: map AI use cases, review existing disclosures, evaluate content workflows, set labelling standards, document exemption analyses — and the point almost everyone misses: review vendor arrangements and clarify who carries the obligation. That is the build-vs-buy question in legal form. If a supplier’s model generates your customer-facing content, whose disclosure duty is it? You settle that in the contract, not in the audit.</li><li><strong>Cloud Security Alliance</strong> — <a href="https://labs.cloudsecurityalliance.org/research/csa-research-note-eu-ai-act-article-50-transparency-20260729/">Article 50: Transparency Obligations Take Effect</a><br/>The trap and the technical reality — for me the most important piece of the week. The Omnibus deferred high-risk but left Article 50 untouched: anyone who assumed &quot;everything moved&quot; has had a compliance gap since Sunday, at up to €15 million or 3% of global turnover. Then the sober part: a watermarking scheme adopted in good faith today can be publicly defeated within months — research demonstrates attacks in the $50 range. Compliance is a floor, not proof. Here too: the model is the easy part.</li></ol>]]></description>
    </item>
    <item>
      <title>When agents act: the new attack surface</title>
      <link>https://kaihackbarth.com/reading-2026-07-26</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-07-26</guid>
      <pubDate>Sun, 26 Jul 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on the security side of agents — after the Hugging Face incident, the week &quot;cool&quot; turns serious. The core vulnerability, the risk catalogue, the supply-chain attack, the defence architecture, and the real question of trust. Curated and commented, not aggregated.</p><ol><li><strong>Simon Willison</strong> — <a href="https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/">The Lethal Trifecta for AI Agents</a><br/>The piece everyone handing an agent tools should read. Willison’s &quot;lethal trifecta&quot;: access to private data + exposure to untrusted content + the ability to communicate externally — together, one poisoned input is enough for an agent to exfiltrate data, with no classic software flaw involved. The core: an LLM cannot reliably separate an operator’s instruction from an injected one, and guardrails alone do not fix it. Which is exactly why the Hugging Face incident was structural, not a one-off.</li><li><strong>OWASP GenAI Security Project</strong> — <a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">Top 10 for Agentic Applications 2026</a><br/>When a discipline gets a Top 10, it has grown up. Over 100 experts sorted the agent-specific risks — from goal hijack (the agent pursuing the wrong objective) through tool misuse, identity and supply chain to rogue agents. Not an academic paper, a build checklist for anyone putting agents into production. For regulated industry, this is the list you audit a pilot against before it goes near real equipment.</li><li><strong>Unit 42 · Palo Alto Networks</strong> — <a href="https://unit42.paloaltonetworks.com/model-namespace-reuse/">Model Namespace Reuse: An AI Supply-Chain Attack</a><br/>The most concrete supply-chain attack of the year: when a developer deletes their Hugging Face account, the namespace frees up — and an attacker uploads a poisoned model under the trusted name. Pipelines that pull models by name alone (including on Azure AI Foundry and Vertex AI) then auto-import code execution; thousands of repos are exposed. The real lesson for me: &quot;which model, from whom, verified how&quot; is procurement and governance, not IT hygiene. Open source does not mean unchecked.</li><li><strong>Anthropic</strong> — <a href="https://claude.com/blog/zero-trust-for-ai-agents">Zero Trust for AI Agents</a><br/>Finally the constructive side: Zero Trust applied to agents — cryptographic agent identity, permissions scoped per task rather than per role, sandboxing, deny-by-default. OWASP calls the extension &quot;least agency&quot;: not just constraining what an agent can access, but what each tool may do, how often, and where. What stands out: none of it is newly invented — it is OT security discipline (segmentation, least privilege) applied to agents. That the principles come from a model vendor does not make them any less vendor-neutral.</li><li><strong>Bruce Schneier</strong> — <a href="https://www.schneier.com/blog/archives/2025/12/building-trustworthy-ai-agents.html">Building Trustworthy AI Agents</a><br/>The deepest point last, from the security authority: no AI system today has the integrity controls to be genuinely trustworthy. Schneier’s proposal — decouple the personal data stores from the model, so security can advance independently of model performance. Underneath sits the uncomfortable truth of the whole week: we are asking a probabilistic model to enforce deterministic access boundaries. That is the frontier — and exactly why trust is the real work, not the model.</li></ol>]]></description>
    </item>
    <item>
      <title>Physical AI: the industrial stack, and where Europe stands</title>
      <link>https://kaihackbarth.com/reading-2026-07-19</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-07-19</guid>
      <pubDate>Sun, 19 Jul 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on Physical AI and the industrial stack — and on where Europe stands. The frame, the US wake-up call, the European reality, a practitioner’s answer, and the vision behind it all. Curated and commented, not aggregated.</p><ol><li><strong>WEF × BCG</strong> — <a href="https://www.weforum.org/publications/physical-ai-powering-the-new-age-of-industrial-operations/">Physical AI: Powering the New Age of Industrial Operations</a><br/>The sober institutional frame: robots that perceive, learn and adapt — reinforcement learning, imitation learning and multimodal foundation models make variability tractable. The most important line sits in there almost as an aside: robotics belongs in the long-term strategy, not on the quick-win list. And the workforce changes with it — the machine operator becomes a robot technician, maintenance goes predictive. Exactly the maturity question my clients actually face.</li><li><strong>Casado &amp; Neuberger · a16z</strong> — <a href="https://a16z.com/america-cannot-lose-the-robotics-race/">America Cannot Lose the Robotics Race</a><br/>The US wake-up call with hard numbers: China’s robot density passed the US in 2021, then Japan and Germany in 2024; Unitree sells humanoids for $5,900. Casado and Neuberger call for permissionless innovation and allied alignment — otherwise the gap becomes irreversible. Read from Europe it is doubly uncomfortable: in the America-versus-China frame we do not even appear. A German industrial reader should argue less with the thesis and more with our own pace.</li><li><strong>Pavlo Zvenyhorodskyi · Carnegie</strong> — <a href="https://carnegieendowment.org/posts/2026/03/europe-general-purpose-robotics-trade-economics">Europe Is Falling Behind in General-Purpose Robotics</a><br/>The European answer to the a16z alarm, and it is uncomfortable: in general-purpose robotics Europe has hardly any manufacturers that can match China and the US — against forecasts of ten million AI robots shipping per year within a decade, a dangerous dependency. The recommendations are right: prioritise strategic sectors, improve access to capital, protect hardware strengths from acquisitions. But papers do not replace factories — the classic European gap between analysis and execution remains.</li><li><strong>Jérôme Laplace · DirectIndustry</strong> — <a href="https://emag.directindustry.com/2026/05/26/op-ed-robotics-ai-security-european-sovereignty-cannot-be-decreed-it-must-be-built/">Robotics, AI, Security: European Sovereignty Cannot Be Decreed, It Must Be Built</a><br/>The practitioner’s point of the week, from a robotics CEO: more than half the technology in Europe’s critical infrastructure comes from outside the continent — and sovereignty is not created by decree, taxonomy or investment plan. It is created by companies doing the patient work of engineering, production and deployment, Mittelstand included. Exactly my line since the sovereignty week: posture is not a strategy. Building is.</li><li><strong>a16z · Big Ideas 2026</strong> — <a href="https://a16z.com/podcast/big-ideas-2026-physical-ai-and-the-industrial-stack/">Physical AI and the Industrial Stack (podcast)</a><br/>For once, listening instead of reading: the a16z vision of the electro-industrial stack — simulation, autonomous design and AI-driven operations as a new industrial base, not a modernisation of the old one. The ambition is American-sized, but the bar is right: whoever builds AI-native starts with simulation and software-first, not with a retrofit. The right closing question for European industrials: are we building what comes next — or digitising yesterday?</li></ol>]]></description>
    </item>
    <item>
      <title>Agentic AI, industrial reality</title>
      <link>https://kaihackbarth.com/reading-2026-07-12</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-07-12</guid>
      <pubDate>Sun, 12 Jul 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on agentic AI in industrial reality — and the uncomfortable truth underneath: the model is the easy part. Context, reliability, evals and infrastructure decide whether an agent makes the jump from demo to production. Curated and commented, not aggregated.</p><ol><li><strong>Pieter van Schalkwyk · XMPro</strong> — <a href="https://www.linkedin.com/pulse/agents-context-hungry-pieter-van-schalkwyk-xd3mc/">Agents Are Context Hungry</a><br/>The most useful industrial-agent piece I have read this month, and it names the real bottleneck: context, not model. &quot;An agent is only ever as good as the context it can reach.&quot; Pieter’s move — an open, standards-based context layer and an external control harness for governance, both before the agent — is exactly the open-standards discipline I have argued for 25 years. On a plant, an agent has to know what sits upstream and downstream, and what its decision does to both. That is engineering, not prompting.</li><li><strong>Oliver Hsu · a16z</strong> — <a href="https://www.a16z.news/p/the-physical-ai-deployment-gap">The Physical AI Deployment Gap</a><br/>The Physical-AI version of &quot;necessary, not sufficient,&quot; with a number that sticks: a picking robot at 95% lab success still fails around 50 times a day — a plant wants 99.9%. The gap is not one breakthrough away; it is distribution shift, latency, integration, safety certification and maintenance. This is the interface where software meets physical systems, and it is exactly there that the last one percent is the whole job. Demos scale; reliability is earned.</li><li><strong>Eugene Yan</strong> — <a href="https://eugeneyan.com/writing/eval-process/">An LLM-as-Judge Won’t Save the Product; Fixing Your Process Will</a><br/>Older (2025) but foundational — and it travels straight into industry: another eval tool will not save the product; the scientific method and eval-driven development will. In regulated, high-consequence settings, &quot;we cannot tell ahead of time when it is wrong&quot; is the whole problem. The unglamorous process work — error analysis, held-out evals, monitoring — is the moat, not the model.</li><li><strong>McKinsey Technology</strong> — <a href="https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/reimagining-tech-infrastructure-for-and-with-agentic-ai">Reimagining Tech Infrastructure for Agentic AI</a><br/>The boardroom confirmation of Pieter’s view from the plant floor: agents do not run on bolt-ons, they need re-plumbed infrastructure — data, context and governance as first-class citizens. Most enterprises layer agents on legacy processes and wonder why they stall. Same lesson, different altitude: the hard part is the substrate, not the demo.</li><li><strong>McKinsey · QuantumBlack</strong> — <a href="https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai">The State of AI</a><br/>The reality check in numbers: only about a quarter of organisations are scaling agents in even one function; the rest are experimenting or just layering AI on top. The gap between the narrative and the P&amp;L is still wide — and it closes on exactly the unglamorous work this whole list is about: context, evals, infrastructure, trust.</li></ol>]]></description>
    </item>
    <item>
      <title>GTM Engineering, deeper</title>
      <link>https://kaihackbarth.com/reading-2026-07-05</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-07-05</guid>
      <pubDate>Sun, 05 Jul 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on GTM engineering — go-to-market as an engineering discipline, and where it hits the limits of industrial reality. The state of the discipline, the operating system behind it, an enterprise proof point, the hard numbers on AI SDRs, and what the buyer side actually weighs. Curated and commented, not aggregated.</p><ol><li><strong>Maja Voje · GTM Strategist</strong> — <a href="https://knowledge.gtmstrategist.com/p/the-2026-state-of-gtm-engineering">The 2026 State of GTM Engineering</a><br/>The proof that GTM engineering became a budgeted function, not an agency fad: 228 operators across 30-plus countries, US median around $135K, coding adds a $40K premium, 84% run on Clay. The discipline is real and professionalising fast. What the data underplays for my world: it is SaaS and self-serve. In industrial deep-tech, a GTM engineer without buyer-side credibility just builds a faster, cleaner funnel — one that still stalls at procurement and the eighth stakeholder.</li><li><strong>Thomas Euler · Medium</strong> — <a href="https://medium.com/@thomase/a-go-to-market-operating-system-for-the-ai-era-be05f9854b67">A Go-to-Market Operating System for the AI Era</a><br/>The best framework I have read on GTM engineering: not automating existing processes, but rebuilding the motion around signals, agent orchestration and autonomous pods. &quot;Systems beat tactics&quot; — agreed, that is exactly the shift from gut feel to a repeatable system. The part the operating system cannot encode is the trust that carries a tier-1 OEM to signature over months. The system delivers the pipeline; a human wins the deal.</li><li><strong>Kyle Poyar · Growth Unhinged</strong> — <a href="https://www.growthunhinged.com/p/what-ai-native-gtm-looks-like-at-public-company-scale">What AI-native GTM looks like at public company scale</a><br/>The most concrete enterprise proof yet: monday.com runs three agents for inbound qualifying, trial activation and account planning. Demo response from 24 hours to under 2 minutes, trial conversion 2.5x, account research from one to two weeks down to five minutes. And still: the agents augment, they do not replace — the rep gets qualified meetings with the context prepared and keeps strategy and the relationship. Exactly the model I argue for, proven here at public-company scale.</li><li><strong>Digital Applied</strong> — <a href="https://www.digitalapplied.com/blog/ai-sdr-agents-2026-buyers-guide-landscape-pricing">AI SDR Agents in 2026: The Realistic Buyer’s Guide</a><br/>The numbers behind &quot;necessary, not sufficient&quot;: autonomous AI SDRs fall short, hybrid pods make roughly 2.3x the revenue on fewer meetings, and 50 to 70% of AI SDR deployments churn within a year. &quot;Data plumbing beats prompts&quot; — the data foundation decides, not the model. In high-ACV industrial deals the split is settled anyway: AI does volume and research, the human owns judgment. The lesson from 2025’s exposed vendor claims: check post-trial retention, not the demo.</li><li><strong>Kai Waehner</strong> — <a href="https://www.kai-waehner.de/blog/2026/04/06/enterprise-agentic-ai-landscape-2026-trust-flexibility-and-vendor-lock-in/">Enterprise Agentic AI: Trust, Flexibility, and Vendor Lock-in</a><br/>A clean map of what my buyers actually weigh: buying agentic AI is not software procurement — trust and vendor lock-in compound because the model shapes autonomous decisions. Waehner argues for open standards, multi-model and MCP to stay interoperable. For GTM that means: selling into industrial enterprises requires speaking trust and no-lock-in, or the engineered funnel never reaches procurement. It is exactly why I advise vendor-neutral — the edge is sitting on the buyer’s side of the table.</li></ol>]]></description>
    </item>
    <item>
      <title>AI-native services: sell the outcome</title>
      <link>https://kaihackbarth.com/reading-2026-06-28</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-06-28</guid>
      <pubDate>Sun, 28 Jun 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on the shift everyone is arguing about: AI-native services, selling the outcome instead of the tool. The thesis, an operator’s playbook, the GTM craft, a framework for which markets, and the strongest counterargument. Curated, commented, not aggregated.</p><ol><li><strong>Julien Bek · Sequoia</strong> — <a href="https://sequoiacap.com/article/services-the-new-software/">Services: The New Software</a><br/>The thesis everyone now cites: the next giant won’t sell software, it will sell the outcome, because services dwarf software roughly six to one. The distinction that earns its keep is intelligence versus judgment, AI is racing up the first, the second still rests on taste, experience and accountability. That is exactly where senior operators stay valuable rather than getting commoditised. What it underplays for my world: in regulated industry, trust and liability slow the handover from intelligence to autonomy.</li><li><strong>Nikola Lazarov · Eilla</strong> — <a href="https://www.linkedin.com/pulse/ai-native-services-playbook-operators-guide-nikola-lazarov-ahmve/">The AI-Native Services Playbook: An Operator’s Guide</a><br/>The sharpest case yet for where AI value really accrues: sell the completed work, not the tool, because the services budget dwarfs the software budget. The team is the product; AI is internal leverage. It reads like a description of my own practice, senior judgment and relationships up front, AI doing the heavy lifting underneath. His critical test is the right one: does your service get stronger as the models improve, or do they commoditise you? My addition from regulated industry: the real bottleneck is trust and accountability, exactly the part no model closes for you.</li><li><strong>Kyle Duffy · Gradient Ventures</strong> — <a href="https://www.gradient.com/blog/posts/the-rise-of-the-gtm-engineer/">The Rise of the GTM Engineer</a><br/>The new GTM playbook: prospecting and the funnel as an engineering discipline, where the moat is how you find and engage buyers, not which tools you own. Right for self-serve and mid-market. My caveat from the industrial side: enterprise deep-tech deals are still won on trust and navigating the buyer’s org, procurement, security, the eighth stakeholder, exactly the part that does not automate. GTM engineering is necessary, not sufficient.</li><li><strong>Julian Teicke · The Delta</strong> — <a href="https://www.thedelta.io/blog/the-ai-native-economy-from-software-to-services-with-the-3h-model">The AI-Native Economy: From Software to Services (the 3H Model)</a><br/>The most useful filter in this debate: which service markets are actually ready for autonomous disruption, scored on Hands (physical work), Hearts (trust and empathy) and Handcuffs (regulation and liability). Handcuffs is exactly the friction I keep flagging in industrial and regulated sectors, the reason the playbook lands faster in some markets than others. Read it as a screen: the fewer the H’s, the faster autonomy wins; the more, the longer a human-plus-AI service stays the right answer. The 44x gap between Europe’s legal-services and software markets shows how much value sits in the service layer.</li><li><strong>Immerman &amp; Rodriguez · a16z</strong> — <a href="https://a16z.com/good-news-ai-will-eat-application-software/">Good News: AI Will Eat Application Software</a><br/>The necessary counterweight to the services-eat-software narrative: a16z argues AI expands the application layer rather than gutting it, and that classic moats, switching costs, process, distribution, still hold. The line worth keeping: better models make the application layer more capable, not thinner, because the hard part was never raw intelligence, it was knowing what to do with it. Read against Sequoia and Lazarov, the truth is not either/or: the winners wrap judgment, workflow and accountability around the intelligence, whether you call the wrapper software or a service.</li></ol>]]></description>
    </item>
    <item>
      <title>AI sovereignty from all sides</title>
      <link>https://kaihackbarth.com/reading-2026-06-21</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-06-21</guid>
      <pubDate>Sun, 21 Jun 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces on the debate of the moment: AI sovereignty, read from every side. Policy, a hyperscaler, the open-source camp, and two skeptics. Curated, commented, not aggregated.</p><ol><li><strong>European Commission</strong> — <a href="https://commission.europa.eu/news-and-media/news/strengthening-europes-tech-sovereignty-2026-06-03_en">Strengthening Europe’s Tech Sovereignty (CADA, Chips Act 2.0, Open Source Strategy)</a><br/>What Brussels is actually doing, beyond the slogans: the Cloud and AI Development Act, the SEAL sovereignty scale, and ‘Union added value’ as a procurement criterion. If you talk sovereignty, read the instrument, not just the headlines.</li><li><strong>Google Cloud</strong> — <a href="https://cloud.google.com/blog/products/identity-security/choice-compliance-and-collaboration-europes-path-to-open-digital-sovereignty">Choice, compliance, and collaboration: Europe’s path to open digital sovereignty</a><br/>The hyperscaler’s reply to the EU package. Serious engineering (customer-held encryption keys, EU-operated partner clouds), not marketing. But read closely for what it does not answer: US extraterritorial reach (the CLOUD Act). Data residency is not the same as control.</li><li><strong>SUSE</strong> — <a href="https://www.suse.com/eu-tech-sovereignty-letter/">EU Tech Sovereignty Letter: Open Source First</a><br/>The bottom-up lever: over 100 European open-source firms calling for a binding ‘Open Source First’ rule in public procurement. Their core line lands: the public sector is the single biggest driver of proprietary lock-in in Europe.</li><li><strong>Pieter Garicano &amp; Simon Grimm · Silicon Continent</strong> — <a href="https://www.siliconcontinent.com/p/nineteen-thoughts-on-ai-and-europe">Nineteen thoughts on AI and Europe</a><br/>The strongest case against my own line: do not substitute at all, dependency is historically normal, a sovereign frontier champion is economically irrational. On most layers Garicano and Grimm are right. On one I push back, continuity and the kill-switch risk. Required reading for both sides.</li><li><strong>David Linthicum · InfoWorld</strong> — <a href="https://www.infoworld.com/article/4187944/europes-cloud-sovereignty-push-may-backfire.html">Europe’s cloud sovereignty push may backfire</a><br/>The cloud-economics skeptic: scale wins, sovereign-cloud champions will consolidate, often bought by the very US hyperscalers they meant to escape. Right about the fortress version, in my view wrong about the goal: sovereignty means substitutability and continuity, not a European AWS.</li></ol>]]></description>
    </item>
    <item>
      <title>The AI economy and sovereignty</title>
      <link>https://kaihackbarth.com/reading-2026-06-14</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-06-14</guid>
      <pubDate>Sun, 14 Jun 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces that sharpened the view on the AI economy this week — from the solo founder to Europe’s strategic position. Curated, commented, not aggregated.</p><ol><li><strong>Anthropic</strong> — <a href="https://www.anthropic.com/news/fable-mythos-access">Statement on the US government directive to suspend access to Fable 5 and Mythos 5</a><br/>The live case behind my sovereignty argument — and the must-read of the week. An export-control directive forced Anthropic to disable its two most capable models for every customer worldwide, eleven days after filing to go public. The lesson in one line: control follows the provider’s jurisdiction, not where the data sits — Frankfurt hosting wouldn’t have changed a thing.</li><li><strong>Europe 2031</strong> — <a href="https://europe2031.ai/europe-2031.pdf">Europe 2031: What getting AI wrong means for us</a><br/>The sharpest read of the week: a scenario-novella on Europe’s possible slide into AI irrelevance, grounded in real data. Its brutal number — 17.3 GW of US compute against Europe’s 1.4 GW, a 12.4× gap. Its core line could be mine: sovereignty is easier to announce than to build.</li><li><strong>Satya Nadella · sn scratchpad</strong> — <a href="https://snscratchpad.com/posts/frontier-ecosystem/">A frontier without an ecosystem is not stable</a><br/>Satya Nadella’s thesis, the one I kept building on this week: a “frontier model” alone is unstable — value has to flow through an ecosystem, not condense into a few models. Every organisation needs its own learning loop as IP. This is the company-level version of my sovereignty argument: build, don’t just buy models.</li><li><strong>World Economic Forum</strong> — <a href="https://www.weforum.org/stories/2026/05/agentic-ai-reshaping-what-it-means-to-be-a-founder/">How agentic AI could reshape what it means to be a founder</a><br/>The “super-individual” founder is no longer theory — one senior plus a swarm of agentic AI colleagues now does what used to need a team. I lived exactly this building SchulHeld. My operator’s footnote: what gets scarce is no longer execution capacity, but judgement, taste and distribution.</li><li><strong>Harvard Business Review</strong> — <a href="https://hbr.org/2026/06/how-people-are-really-using-ai-in-2026">How People Are Really Using AI in 2026</a><br/>Marc Zao-Sanders’s annual reality check, third edition. The 2026 surprise: the fastest-rising uses aren’t productive but playful — fake reality TV, robot tarot, fan fiction. My take for industrial buyers: real adoption follows what people find useful or delightful, not the strategy deck.</li></ol>]]></description>
    </item>
    <item>
      <title>An early set from the desk</title>
      <link>https://kaihackbarth.com/reading-2026-06-07</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-06-07</guid>
      <pubDate>Sun, 07 Jun 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Five pieces from the industrial IoT and AI world worth the five minutes this week — curated, commented, not aggregated.</p><ol><li><strong>MIT Technology Review</strong> — <a href="https://www.technologyreview.com/2026/04/16/1135554/treating-enterprise-ai-as-an-operating-layer/">Treating enterprise AI as an operating layer</a><br/>My point exactly, cleanly put: the edge in enterprise AI doesn’t come from the best foundation model but from the “operating layer” — AI embedded in operations, where proprietary data, domain experts and feedback loops become the real moat. Pilot-to-P&amp;L, rendered as architecture.</li><li><strong>Ulrich Homann · LinkedIn</strong> — <a href="https://www.linkedin.com/pulse/future-software-engineering-product-engineer-ulrich-homann-zro9e/">The Future of Software Engineering: Product Engineer</a><br/>Ulrich Homann (Microsoft) on the shift from coder to “Product Engineer”: as AI cheapens implementation, value moves to architecture and problem understanding. My addition from building things myself — the tool lowers the barrier to building, not the barrier to building well.</li><li><strong>Anthropic</strong> — <a href="https://www.anthropic.com/institute/recursive-self-improvement">Recursive self-improvement</a><br/>Anthropic’s own data: engineers ship 8× more code per quarter, over 80 % authored by Claude. The view on the trajectory behind “vibe coding” — and why Industrial AI readiness is not a someday-luxury but a today-necessity.</li><li><strong>World Economic Forum</strong> — <a href="https://www.weforum.org/publications/shaping-the-future-of-learning-education-readiness-for-the-age-of-ai/">Shaping the Future of Learning: Education Readiness for the Age of AI</a><br/>AI readiness isn’t only a question for schools. The WEF framework reads as a blueprint for organisations too: taking AI seriously means designing for people’s ability to learn and adapt — not just the models.</li><li><strong>Handelsblatt</strong> — <a href="https://www.handelsblatt.com/unternehmen/industrie/hannover-messe-2026-ki-veraendert-fabriken-schneller-als-erwartet/100216807.html">Hannover Messe 2026: KI verändert Fabriken schneller als erwartet</a><br/>Wermke, Bomke and Kerkmann deliver the update to last year’s “decisive year” framing: twelve months on, Physical AI is no longer a slogan but a production reality. The Pilot-to-P&amp;L question stays open.</li></ol>]]></description>
    </item>
    <item>
      <title>The first list</title>
      <link>https://kaihackbarth.com/reading-2026-05-24</link>
      <guid isPermaLink="true">https://kaihackbarth.com/reading-2026-05-24</guid>
      <pubDate>Sun, 24 May 2026 06:00:00 GMT</pubDate>
      <description><![CDATA[<p>Four pieces from the industrial IoT and AI world worth the five minutes this week — curated, commented, not aggregated.</p><ol><li><strong>VDI Nachrichten</strong> — <a href="https://www.vdi-nachrichten.com/technik/produktion/maschinenbau-und-der-ai-act/">Warum der Maschinenbau die KI-Ausnahme nutzen muss</a><br/>The EU AI Omnibus gives German machinery makers an 18-month window — and that is exactly the point: don’t wait, move Industrial AI into series operations now. Whoever misses this window loses both the regulatory reprieve and the competitive edge.</li><li><strong>Handelsblatt</strong> — <a href="https://www.handelsblatt.com/unternehmen/industrie/hannover-messe-2026-ki-veraendert-fabriken-schneller-als-erwartet/100216807.html">Hannover Messe 2026: KI verändert Fabriken schneller als erwartet</a><br/>Wermke, Bomke and Kerkmann deliver the update to last year’s “decisive year” framing: twelve months on, Physical AI is no longer a slogan but a production reality. The Pilot-to-P&amp;L question stays open — and a follow-up from the same authors would be exactly the right venue.</li><li><strong>Heise online</strong> — <a href="https://www.heise.de/en/news/Eclipse-hawkBit-1-0-Backend-for-IoT-updates-reaches-production-readiness-11250173.html">Eclipse hawkBit 1.0: Backend for IoT updates reaches production readiness</a><br/>84 contributors, 4,000 commits, 20 releases — and now 1.0. hawkBit is one of the few open-source projects I’ve recommended for years: anyone building FOTA mandates in a UNECE R156 context without locking into a single vendor now has a serious production-ready alternative.</li><li><strong>Dataiku</strong> — <a href="https://www.dataiku.com/stories/blog/manufacturing-ai-trends-2026">Manufacturing's 2026 Mandate: From AI Pilot to Agentic Profit</a><br/>Vendor perspective, but the data backs the thesis: 45 percent of industrial AI pilots remain stuck in pilot status 18 months after launch. That is precisely the gap boards need to understand in 2026 — adoption rate is not the same as P&amp;L realisation.</li></ol>]]></description>
    </item>
  </channel>
</rss>
