CD Consulting R&D
KB-RISK — Risk knowledge base
Independent analyses of technology, information and AI risk, compiled from public sources.
Entries
-
8 September 2026
Keeping secrets and code on GitHub: what the last four years of incidents teach a small organisation
If you keep API keys in a private repository, read this before the next backup runs.
A private repository is a repository with a flag, not a vault: commits stay reachable after deletion, tokens on the workstation read everything, and the custodian itself was breached in May 2026. About 29 million new secrets reached public GitHub in 2025 and 64 % of those leaked in 2022 were still valid. Six incident families, the platform's dated defences, and six rules for a small organisation.
-
7 September 2026
"AI Agents Push Humans Out of the Loop" — a critical reading note
If "a human will check" is your safeguard, the authors explain why it wears out.
"Human oversight" has become the standard remedy of AI governance (the EU AI Act included). Yet, the authors argue, autonomous AI agents actively degrade the cognitive capacities that such oversight requires: skill atrophy ("deskilling", "intuition rust"), automation and anchoring biases, approval fatigue, and feedback loops in which "the human rater can become the exploitable part of the reward channel".
-
7 September 2026
Technology, Information and AI Risks in the WEF Global Risks Reports, 2020–2026
If you brief a board on risk, this is where AI entered the list, and how fast.
2024 is the break. Misinformation takes #1 over two years; AI enters the list and lands at #6 over ten; "AI-generated misinformation and disinformation" is the #2 current crisis at 53%. AI's signature is the horizon gap, and it is the largest in the 2026 survey: #30 versus #5, severity 3.50 versus 5.28.
Companion: WEF risks, the illustrated companion