The Modular Briefing, Issue 02. Your data, your rules.
Modular Technology Group

Welcome back to the Modular Briefing. Each week: a short, plain-English read on private AI, governance, and owning your infrastructure. No hype, no vendor spin.

From the desk of Cale
Before you can govern an agent, you have to know where the work lives
I've been thinking about how little of this week's AI news was actually about AI.

Most of my own week went into something that looks nothing like it. We stood up SharePoint for a department as its source of truth. One landing pad for that department's artifacts, so the documents and the decisions quit living in six inboxes and a shared drive nobody trusts.

Unglamorous. Also the whole ballgame.

Here's the connection. Every story below is about authority: what an agent can reach, and who answers for it when it reaches too far. You can't settle either question if you don't know where your work lives. The permissions on a real library are the leash. Give a department's artifacts one home with real ownership, and "what's this thing allowed to touch?" turns from philosophy into a list you can read out loud.

That's why I keep calling it a cockpit instead of a document store. A cockpit gives whoever runs the department the instruments to see their own operation. Get that right and the executive dashboard above it is mostly assembly work, because the numbers already have a home and a name against them. Get it wrong and every dashboard is somebody's best guess in a nice font.

We're early in this. But it's the right first mile, and it's the mile I'd want walked before anybody lets an agent near something that matters. Your data, your rules, and that includes the AI working on it. Your AI, your rules.

If you're staring at the same problem in your own department, I'm always open to compare notes.

Cale Hollingsworth is the founder of Modular Technology Group and a fractional CTO. He has been future-proofing organizations since 1993, and he works with teams too small for an enterprise AI program and too serious about their data to wing it.

Almost every story worth reading this week landed on that same question, and it was not what AI can do. It was who decides what it is allowed to do, and who pays when it does it.

This week in private AI

A single link could have built an agent inside your workspace
Researchers showed that one crafted URL was enough to create an assistant in a logged-in account, attach every connected mailbox and file store with approval prompts set to never ask, and put it on an hourly schedule. The flaw was fixed on June 8. The lesson outlives the patch: an agent is an actor with authority, and authority needs a named owner.
The Hacker News
An attacker left an AI agent running unattended inside a finance ministry
Security researchers report an open-source agent used for post-exploitation work at Thailand's Ministry of Finance, running with its approval mode switched off. One security firm is the only public source, and the ministry has confirmed nothing. Treat it as a direction of travel rather than a settled fact.
The Hacker News
Unlimited AI tokens aren't unlimited after all as US Army burns through supply
The Army announced unlimited access in May, then exhausted the pooled allowance behind it by the middle of June and put limits back. Usage-based pricing behaves this way at every size of organization. A fixed, right-sized private deployment has no cliff to walk off in month two.
Ars Technica, reporting from WIRED
'You just hired a million bad employees': how the brief tokenmaxxing era delivered the opposite of what it promised
The argument, and it is an argument rather than a study, is that most AI spend now buys volume instead of judgment, because nobody gave the model the context it needed to be useful. Buying more tokens does not fix a governance problem. It funds it.
Fortune
Ireland stalls a billion-euro cloud tender over digital sovereignty
Ireland's Office of Government Procurement cancelled the competition after an interested party raised concerns. The existing framework is capped at 350 million euro and runs to September 2027; a replacement value of 750 million to 1 billion euro was quoted in the Dáil by an opposition deputy, not by the government. Sovereignty has stopped being a talking point and started being a procurement decision.
The Register

Still true. The Department of Defense pause on CMMC does not pause the obligation underneath it. NIST SP 800-171, required by DFARS 252.204-7012, has been in force for roughly nine years. Phase one self-affirmations were signed under penalty of perjury and still stand, the department is running a 60-day review, and the underlying regulation still carries a November 10 date. Eric Crusius of Hunton Andrews Kurth walked through it on Federal News Network.

Talk through agent governance for your team

Your data, your rules.

Your data, your rules.
Modular Technology Group · 18 Village Plaza, Suite 115, Shelbyville, KY 40065 · 1-888-723-4508 · modtechgroup.com

The Modular Briefing is curated by Arthur, Modular's AI assistant. Please verify anything important before you rely on it.

This is the latest edition of the Modular Briefing. View in browser