Complex Discovery

Complex Discovery ComplexDiscovery provides news and views on data compliance, privacy and security to technology prof

✈️ Flying to the Camino Portugués Coastal Route: 4,700 miles to walk 167 🇵🇹 Houston to Porto is about 4,700 miles in a s...
09/09/2026

✈️ Flying to the Camino Portugués Coastal Route: 4,700 miles to walk 167

🇵🇹 Houston to Porto is about 4,700 miles in a straight line. The walk on the other end is 167.

🛫 The flight leaves this afternoon. Thursday it lands in Porto, and the transfer runs up the coast to Matosinhos. Friday morning three walkers from ComplexDiscovery start north, and 15 days later the route ends in Santiago de Compostela.

🏛️ The route is the Camino Portugués Coastal Route. Up the Portuguese shore to the mouth of the Minho, across into Galicia by boat, then inland at Pontevedra onto the Variante Espiritual, and finally up the Ría de Arousa by water into Padrón.

👣 Posts will follow from the walk, and it is worth saying up front what they will be about, because it is not quite what you would expect from a pilgrimage.

🔎 Almost everything on this route comes with two histories. There is what the record establishes, and there is what tradition has attached to it over a thousand years. The two are usually different. The gap between them is the interesting part.

🖥️ So that is the series. One thing per stage worth looking at, what can actually be documented about it, and what got added later. Some of it sits awkwardly next to the tourist copy. None of it makes the walk smaller.

💻 Working with digital content and records for a living turns out to be reasonable preparation.

🗓️ Next update Friday, from a beach north of Porto where the Roman ruins are partly reproductions, and the museum says so.

📰 Read the route overview from ComplexDiscovery OÜ at https://complexd.blog/4xc91J2.

🇷🇺 How a general's walk across a bridge tested Putin's claim to Svyatohirsk 🔎 Putin told the world on Sept. 1 that Russi...
09/09/2026

🇷🇺 How a general's walk across a bridge tested Putin's claim to Svyatohirsk

🔎 Putin told the world on Sept. 1 that Russian forces had taken Svyatohirsk. Six days later, Brig. Gen. Andriy Biletskyi walked across the town’s bridge on camera, unhelmeted, and told Russia’s leadership to take off their clown noses. Between those moments, four Institute for the Study of War assessments, a Kyiv Post fact check, Reuters reporting from Moscow, and a Conflict Intelligence Team sitrep supplied every step a verifier would run: the claim in the claimant’s words, the doctored evidence offered for it, a Russian milblogger’s admission, an unmoved DeepState map and a bakery that was open.

💡 Cybersecurity, data privacy, compliance and eDiscovery professionals will recognize the sequence as authentication under adversarial conditions. It mattered beyond one town because, Reuters reported, Putin told two U.S. envoys on Sept. 5 that Russia was making “real progress,” and a person close to the Kremlin said his year-end confidence rests on his commanders’ reports.

👀 Watch next for what follows the Sept. 8 Trump-Putin call, whether the three-way format the envoys hoped to revive takes shape, and whether the front-line ceasefire Russia did not accept resurfaces.

📰 Read the complete article from ComplexDiscovery OÜ's geopolitics beat at https://complexd.blog/4xcxcXK.

🔎 Law professors propose a three-part test for what counts as AI slop ⚖️ Two Boston University law professors have given...
08/09/2026

🔎 Law professors propose a three-part test for what counts as AI slop

⚖️ Two Boston University law professors have given policymakers something the AI slop argument has lacked: a test with edges. Jessica Silbey and Woodrow Hartzog provisionally define slop as machine output produced with little exertion that shifts the burden onto recipients and erodes the domain it lands in. The test turns on effort, imposition and domain degradation rather than on quality, and that is what makes it usable. It separates a clumsy first draft, which is fine, from a polished report nobody will stand behind, which is not.

🕛️ The timing sharpens the point. Transparency duties under Article 50 of the EU AI Act and California’s AI Transparency Act both became operative Aug. 2, with three more compliance dates through 2028 and a penalty formula that inverts for smaller firms. Meanwhile, the courts, where the counting has actually been done, are what the paper’s policy catalog never reaches. A public database of decisions involving hallucinated material stood at 2,022 when checked Sept. 7.

👀 Watch two developments next. Whether detection tooling hardens into an enforcement layer, carrying its false-positive problem. And whether governance programs start treating unattributable AI output as a retention and defensibility question rather than an HR one.

📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at https://buff.ly/GZMnf3O.

🇵🇹 Camino Portugués Coastal Route: what the record shows and what tradition added🇪🇸 The Pilgrim's Reception Office in Sa...
07/09/2026

🇵🇹 Camino Portugués Coastal Route: what the record shows and what tradition added

🇪🇸 The Pilgrim's Reception Office in Santiago issued 530,987 Compostelas in 2025, its highest annual figure, and the Portuguese routes accounted for 190,344 of them. ComplexDiscovery walks the coastal one this month, Matosinhos to Santiago, with the Variante Espiritual for the final stages.

⛪️ What the route offers, beyond the Atlantic and the granite, is an unusually clear view of how institutions handle their own histories.

👣 A monastery on this walk publishes its founding legend and labels it a legend. A Spanish national archive supports Baiona's Columbus claim, then states in the next sentence that no testimony of the report behind it survives.

📃 Set against those: a heritage decree credited with a property count it never states, a hillfort population that circulates as a figure and was produced as an estimate, promotional superlatives with no institutional origin, and a World Heritage listing the route does not hold.

🔎 For readers whose work turns on provenance, that contrast is the story. The habits that separate a documented fact from an attached tradition are the habits that separate an established finding from a confidently repeated claim.

💡 This piece opens Camino Month at ComplexDiscovery OÜ.

📰 Read the complete article from ComplexDiscovery OÜ at https://complexd.blog/4xc91J2.

💼 D.C.'s highest court struck a brief over four fake citations and called its own sanctions authority unclear 🏛️ A court...
06/09/2026

💼 D.C.'s highest court struck a brief over four fake citations and called its own sanctions authority unclear

🏛️ A court of last resort struck an institutional litigant’s brief this month over four citations that did not exist. Its most quotable line, that “every firm attorney who signed the brief bears some responsibility,” is real. Senior Judge Stephen H. Glickman wrote separately to urge a narrower reading, and to argue that existing rules appear to leave the court little beyond a published admonishment and the strike itself. Rule 38 in the District reaches frivolous appeals, but not briefs; its Rule 46 covers only bar admission, and inherent authority needs a bad-faith finding this record would not support.

⚖️ Practitioners who stop at that line will miss the qualification, and that gap is where compliance effort can get misdirected. Anyone building AI governance for a regulated function should read what the order leaves unanswered: who reviewed the brief, and how the drafter was trained and supervised.

🔎 Two things to carry. The panel called the full scope of its sanctions authority unclear and sent the question to its Rules Committee, where the answer will come from. And the vendor hallucination figures the order quotes, now in two published decisions, assign the numbers to the wrong products; the Stanford study says the reverse.

📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at https://buff.ly/0cUbNfj.

🗓️ In six days the Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities with...
05/09/2026

🗓️ In six days the Cyber Resilience Act starts requiring manufacturers to report actively exploited vulnerabilities within 24 hours of becoming aware. The platform they must file through has no published web address.

💼 ENISA updated its guidance Sept. 4, and the update is the story. No API at launch, so every filing against the clock is a person and a form. No voluntary reporting through it at launch. If it is down, ENISA says to wait. And ENISA discloses that its 72-hour counter can show a report overdue before 72 hours have run from awareness.

🕛️ A second timing question sits underneath. The regulation’s penalty article is not among the provisions that take effect early, so on the face of the text its fine ceilings apply only from Dec. 11, 2027. No official guidance reviewed addresses enforcement before then.

🔎 Anyone checking whether open-source stewards face fines should read the corrected regulation. A July 2025 correction moved the boundary of the penalty exclusions, and the original text gives the wrong answer.

🔐 For cybersecurity, privacy, compliance, and eDiscovery readers, the operative question is when a manufacturer became aware – a judgment to be evidenced rather than defined. Watch for the address and the counter logic.

📰 Read the complete article from ComplexDiscovery OÜ's cybersecurity beat at https://complexd.blog/4cZL5kE.

📢 A fresh wave of legal-technology launches just hit the market this week — Querious integrated with 8am MyCase and Desc...
05/09/2026

📢 A fresh wave of legal-technology launches just hit the market this week — Querious integrated with 8am MyCase and Descrybe brought its Legal Engine into Microsoft 365 Copilot, both announced on September 3, 2026, following iManage's Gemini Enterprise for Legal rollout in late August.

⚔️ Every one of those launch teams will eventually sit in a room and reach agreement on go-to-market plans, and this analysis argues that the moment everyone nods in unison is exactly the moment to slow down and ask who was not in the room.

📘 Drawing on Clausewitz's center of gravity, Sun Tzu's positioning discipline, Everett Rogers' adopter categories, Geoffrey Moore's chasm and whole-product concepts, Igor Ansoff's growth matrix, Clayton Christensen's innovator's dilemma, and Gary Klein's premortem technique, the piece builds a 15-question "Launch Doctrine" gate for cybersecurity, information governance, eDiscovery, and legal technology launches.

🖥️ Concrete industry examples ground the framework, from antitrust second requests as a demanding beachhead segment to technology-assisted review's long march toward judicial defensibility and generative-AI review tools now facing mainstream evidentiary scrutiny.

🔎 Read the complete analysis from ComplexDiscovery OÜ https://complexd.blog/4eTuVLa.

⚖️ A lawyer fed AI citations to his own regulator, and the tribunal struck him off 🏛️ A disciplinary tribunal in London ...
04/09/2026

⚖️ A lawyer fed AI citations to his own regulator, and the tribunal struck him off

🏛️ A disciplinary tribunal in London has removed a lawyer from the register of foreign lawyers over legal authorities that generative AI invented, and those authorities sat in his defense against the regulator prosecuting him. When the regulator’s counsel flagged the errors, he answered with an email he had also drafted using AI, and that email carried further false material. The Solicitors Disciplinary Tribunal says this is the first time a lawyer’s use of AI in legal proceedings has been litigated before it.

🔎 Professionals in cybersecurity, data privacy, regulatory compliance and eDiscovery should read the culpability findings rather than the headline. The tribunal weighed both how Kumar began using AI and what he did once the errors were identified, and it gave very substantial weight to the repetition. The same distinction runs through incident-response practice, where the handling of a defect is judged separately from the defect.

👀 Watch the referral route. Courts on both sides of the Atlantic have referred AI citation failures to regulators, though no court referred Kumar; the SRA was already prosecuting him. The Solicitors Regulation Authority (SRA) said it received 42 reports of potential AI misuse in the year to July 2026, with investigations underway.

📰 Read the complete article from ComplexDiscovery OÜ's artificial intelligence beat at https://complexd.blog/4yloBTw.

🔍 Who really controls your cloud provider?Europe’s proposed Cloud and AI Development Act could expand cloud audits beyon...
04/09/2026

🔍 Who really controls your cloud provider?

Europe’s proposed Cloud and AI Development Act could expand cloud audits beyond data residency and security, bringing ownership, governance, and control directly into the audit process.

📋 Auditors may be asked to examine:

✅ Ownership structures and cap tables
✅ Ultimate beneficial owners
✅ Strategic decision-making bodies
✅ Voting thresholds and control mechanisms
✅ Shareholders holding 5% or more of ownership or voting rights

🌍 As concerns around digital sovereignty and strategic technology grow, the proposal highlights a critical question for buyers: Is vendor risk only about where data resides, or also about who controls the company behind the service?

💡 Regardless of whether the regulation is adopted, the draft offers a practical framework for stronger vendor due diligence today.

📖 Read the complete article from ComplexDiscovery OÜ's data privacy and protection beat at https://complexd.blog/4qRebbA.

🚨 When the Agent Becomes a Witness🤖 As organizations increasingly rely on AI agents to search, classify, recommend, and ...
03/09/2026

🚨 When the Agent Becomes a Witness

🤖 As organizations increasingly rely on AI agents to search, classify, recommend, and act, a critical question is emerging: Can agent-generated activity be proven, reconstructed, and defended when it becomes relevant to litigation, investigations, audits, or regulatory reviews?

📔 This new Oxford-style tutorial from ComplexDiscovery examines the intersection of AI, evidence, accountability, and discovery. Through 21 contestable propositions, it explores agent logs, privilege, retention, oversight, authentication, proportionality, and testimony in an era where machine actions may become part of the evidentiary record.

Key Questions

✅ Are AI logs evidence or simply telemetry?
✅ Can agent activity be reconstructed months or years after an event?
✅ Who can explain an AI agent's conduct when challenged by regulators, auditors, investigators, or courts?
✅ Are today's governance, procurement, and logging decisions sufficient to answer tomorrow's questions?

⚖️ Capability without accountability may create significant operational, legal, and governance risks. As agentic AI adoption accelerates, organizations should consider not only what systems can do, but also how actions can be verified, explained, and defended when scrutiny arrives.

🔗 Read the full tutorial from ComplexDiscovery OÜ at https://complexd.blog/4cO37pW.

Address

Tallinn

Alerts

Be the first to know and let us send you an email when Complex Discovery posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Complex Discovery:

Shortcuts

Share