This website uses cookies

Read our Privacy policy and Terms of use for more information.

In partnership with

Disclaimer: All views presented here, in this newsletter, are my own, or are either sourced from internet or using AI (using LLMs) search and referenced accordingly.

Author or the newsletter are not liable for any actions taken by any individual or any organization / business / entity. The information provided is for information, education and awareness purposes only and is not specific to any business and or situation.

This publication does not constitute legal, regulatory, or professional security advice.

M. Yousuf Faisal

Hi Securing Things family, Hope you are doing well.

As announced in the last newsletter edition (titled Cybersecurity Before and After Mythos), that I’ll be starting 3 awareness campaigns on 3 different topics on my socials.

This edition focuses one 1 of the 3 campaigns as the main theme:

↪️ Part 0 - EU AI Act Awareness Series – What every stakeholder needs to know about Regulation (EU) 2024/1689 + the Best Book on the topic.

Remember to bookmark it as this’ll be updated as I continue the series.

Other 2 i.e. on ACSSA and HKPCICSO; to start sometime soon as well.

In addition, we’ll be also covering the following:

  • 📘 Part 1 - EU AI Act - Accountability and Trust!

  • ‼️Part 2 - Why EU AI Act Changes Everything for Manufacturers (Even If You Never Build AI)?

  • ✍️ Part 3 - What Manufacturing Leaders Should Do Next?

Hop on to the section that interest you more.

But before we begin, do me a favor and make sure you “Subscribe” to let me know that you care and keep me motivated to publish more. Thanks!

Ready? let’s dig in.

Yours truly.

— Yousuf.

♻️if you know someone in your professional circle who will benefit from these resources and interested in learning. Thanks 🌟

Together with (Sponsor):

Your employees are connecting AI to everything. Now what?

ChatGPT and Claude don't just answer questions anymore. Employees are connecting them directly to Notion, Linear, Jira, and the rest of your stack. The AI can read, write, and take actions on company data. Most IT and security teams have no visibility into any of it.

Harmonic Security Connectors changes that. It sits inline with every AI-to-app connection, so you see each call, control what data moves, and block destructive actions before they happen. Employees notice nothing different.

See what's actually running across your business in a live demo.

EU AI ACT - Awareness Series!

Here’s a free awareness training on EU AI ACT:

Part 1Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 2 Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 3 Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 4 Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 5Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 6 Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 7Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 8Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 9 → Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 10Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 11 Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 12 (a) → Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 12 (b)→ Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 13Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 14Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 15Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

Part 16Securing Things for EU AI Act - by M. Yousuf Faisal - an Awareness Series

<several additional parts will be added here over the next few days>

Be sure to bookmark this and come back to this for reference.

♻️Do let me know + reshare if you like & find this helpful in your roles♻️

If you’d like a video explainer to this series, do hit the reply button to let me know. If I get even 25 replies, I’ll turn this into free training.

Best Learning Resource for EU AI Act:

Easy Peasy Guide for EU AI Act by Jamal Ahmed.

Early in July, I was lucky to cross path online with Jamal’s profile and were able to make in the very last lot of the first 100 book launch team.

I was not sure what I was getting into by pre-ordering a book. But I saw his previous GDPR easy peasy guide was a best seller as well and several others posting about it. So, I ordered.

Next thing, I was welcomed with access to the first 100 community portal, digital edition of gamified 14 chapters that gets unlocked, one by one, as you progressed (yes, am yet to finish but soon will), 3 master classes, whatsapp etc. etc.

Thanks Jamal.

Amazon Best seller

Checkout the free chapter → here.

This makes the long legal text, as title suggests → Easy Peasy to get it.

Why buy:

The person who gets the job you wanted might already own this book.

Think about that. While some professionals are saying:

“I’ll learn AI governance when I need it.” Others are learning it now.

They’re building the knowledge. Learning the language.

Preparing for the questions. Becoming the people employers will turn to.

So picture your next interview. Similar experience. Similar qualifications.

Two strong candidates. Then comes the question about AI governance.

One candidate knows. The other wishes they’d prepared.

Which one do you want to be?

That’s why I recommend The Easy Peasy Guide to the EU AI Act by Jamal Ahmed.

It makes one of the world’s most important AI regulations practical, accessible and easy to understand.

And it’s already become an Amazon International Bestseller.

But if you’ve been thinking about buying it, today is the day.

Because today is the LAST day to claim £1,289 worth of launch bonuses:

→ 3 x Live AI Governance Masterclasses
→ 1 year’s membership to the AI Governance Community

Tomorrow, you can still buy the book. But £1,289 of bonuses will be gone.

So you can save the link. You can tell yourself you’ll order it later.

You can wait until AI governance becomes impossible to ignore.

But your competition might not.

Get the book. Claim the bonuses. Start building the knowledge now.

Because you can choose to wait. Just don’t assume the person competing for your next opportunity will.

📖 Get and secure your copy here today. 📌

EU AI Act - Accountability and Trust!

The EU AI Act isn't about AI. It's about accountability and trust.

Why every manufacturer, OEM, automation vendor and CISO should care—even if you've never built an AI model.

"We're only using ChatGPT internally. Surely EU AI Act doesn't apply to us?"

You may have heard some version of this question in several to most executive discussion over the past year.

Sometimes it's from a manufacturing - CIO / Head of Engineering / OT Security Manager.

Occasionally, it's from a machine builder that confidently says,

"We don't build AI. We just buy software from our vendors."

And every time, my answer is almost the same.

You're asking the wrong question.

The EU AI Act isn't trying to regulate whether you use AI.

It's trying to regulate how AI affects people, products and society—and who is accountable when it does.

That distinction changes everything.

Especially for manufacturers.

AI has already arrived in Your Factory! Whether you planned for it or not.

5 years ago, Artificial Intelligence felt like a futuristic roadmap item.

Today, it's quietly becoming part of everyday industrial operations.

Walk through almost any modern manufacturing facility and you'll find AI hiding in places most people don't even think about.

  • It's helping reliability engineers predict equipment failures before they happen.

  • It's inspecting welds, packaging and finished products faster than traditional vision systems.

  • It's helping operators troubleshoot alarms.

  • It's analysing network traffic for cyber threats.

  • It's recommending maintenance activities.

  • It's optimising energy consumption.

  • It's searching engineering documentation in seconds.

And increasingly...

It's becoming the first place engineers turn when they have a problem they don't immediately know how to solve.

The interesting part?

Most organisations don't even think of these systems as "AI."

They're simply new features inside software they've already purchased.

Manufacturing Is Entering Its Next Transformation

We've already lived through several major industrial shifts.

Mechanisation, Electrification, Automation, Digital Transformation.

Industry 4.0, Industrial IoT. Now we're entering another one.

This time, the differentiator is Intelligence and isn't connectivity.

Machines are no longer just connected.

They're beginning tointerpret. Recommend. Predict. Assist.

Sometimes even decide.

That doesn't mean factories are becoming autonomous overnight. Far from it.

But role of AI inside industrial environments is expanding much faster than most governance programs. That's where the challenge begins.

The Biggest Myth About the EU AI Act

Let's clear up one misconception immediately.

Using AI does not automatically make your organisation subject to the EU AI Act's High-Risk requirements.

That's probably the single biggest misunderstanding I've encountered since the legislation was adopted.

Many organisations assume something like this:

Manufacturing + AI = High-Risk AI

It sounds logical. However, it just isn't how the legislation works.

A food manufacturer using machine learning to predict pump failures isn't automatically operating a High-Risk AI system.

Neither is a factory using AI to optimise production schedules.

Nor is an organisation deploying an industrial copilot to help engineers search maintenance manuals.

The law doesn't ask: "Are you using AI?"

It asks something much more specific.

"What is the AI actually doing?"

That difference matters.

Because, answer determines almost every legal obligation that follows.

Here's where many compliance programs go wrong. Most organisations begin with technology.

They create a list of AI tools. Categorise vendors. Review contracts. Maybe even launch an AI policy.

Those are all useful activities. But they're not the starting point.

The first question shouldn't be: "Which AI systems do we have?"

It should be:

"What business problem is this AI solving—and what role does it play?"

That's a subtle difference. But it's an important one.

A predictive maintenance model helping an engineer schedule maintenance has a very different governance profile from AI embedded inside a product's safety function.

Both use AI. Both may use similar machine learning techniques.

But from a regulatory perspective, they are very different systems.

AI Governance Is Becoming a Board-Level Conversation

Not because regulators want more paperwork. Rather, because AI is changing how decisions are made.

Historically, industrial decisions followed a familiar path.

Sensor → PLC → SCADA → Operator → Engineer → Manager.

Today, AI is quietly inserting itself into that chain.

Sometimes it's:

  • making recommendations.

  • identifying anomalies humans would never spot.

  • generating insights in seconds that previously took hours.

That's incredibly powerful. But it also raises new questions.

Who validated the model? What data was it trained on? What assumptions is it making? How should engineers challenge its recommendations? Who is accountable if it's wrong?

Those questions aren't technical. They're governance questions.

And governance is becoming one of the biggest competitive differentiators in industrial AI.

What this means for manufacturers:

You don't need to stop adopting AI. Quite the opposite.

But you do need to understand:

where AI is being used, why it's being used, who owns it, and how much you should trust it.

The organisations that answer those questions early will move much faster than those trying to retrofit governance later.

AI Is Quietly Changing OT Cybersecurity Too

Cybersecurity teams are experiencing exactly the same transformation.

Modern OT security platforms increasingly use AI to:

  • Prioritise threats.

  • Detect unusual network behaviour.

  • Discover unmanaged assets.

  • Correlate alerts.

  • Recommend investigations.

  • Summarise incidents.

  • Accelerate threat hunting.

Five years ago, analysts spent hours manually piecing together these insights. Today, many platforms deliver them in seconds.

That's good news. But it introduces a new challenge.

Security teams now have to evaluate not only whether an alert is accurate — but also whether the AI's reasoning can be trusted.

That's a different skill. And it's one many organisations are only beginning to develop.

The Real Conversation Isn't About AI

It's about trust and accountability.

  • Can you trust the recommendation?

  • Can your engineers explain why the AI reached that conclusion?

  • Can your procurement team evaluate AI suppliers with the same rigour they evaluate cybersecurity suppliers?

  • Can your executives understand where AI is influencing business decisions?

  • who is accountable?

These questions matter far more than whether the underlying model is a large language model, a neural network or a traditional machine learning algorithm.

Because technology changes quickly. Governance lasts much longer.

A Different Way to Think About the EU AI Act

If you've been viewing the EU AI Act as another compliance exercise, I'd encourage you to reframe it. Think of it as a catalyst.

An opportunity to answer questions many organisations should already be asking.

  • Where are we using AI today?

  • Which decisions rely on it?

  • Who is accountable?

  • How do we know it's performing as expected?

  • What happens when it fails?

Those aren't legal questions. They're leadership questions.

And organisations that answer them well won't just become more compliant.

They'll become more resilient.

Next we'll unpack one of the most misunderstood aspects of EU AI Act:

  • Why High-Risk AI is far narrower than most organisations believe.

  • Difference between Providers, Deployers, Importers & System Integrators.

  • Why two manufacturers using the same AI platform can have completely different legal obligations.

  • Real-world manufacturing examples that separate myth from reality.

Because when it comes to the EU AI Act, your technology matters far less than your role in the AI ecosystem.

Next → we’ll discuss:

  • Part 2 — Why EU AI Act Changes Everything for Manufacturers (Even If You Never Build AI).

  • Part 3 — What Manufacturing Leaders Should Do Next.

Subscribe to keep reading

This content is free, but you must be subscribed to Securing Things Newsletter to continue reading.

I consent to receive newsletters via email. Terms of use and Privacy policy.

Already a subscriber?Sign in.Not now

Reply

Avatar

or to participate

Keep Reading