Wednesday, September 02, 2026

 

Malta jury clears suspect mastermind businessman in Daphne Caruana Galizia murder case

This April 4, 2016 file photo shows Maltese investigative journalist Daphne Caruana Galizia, who was killed by a car bomb in Malta on Oct. 16, 2017.
Copyright Jon Borg/AP


By Greta Ruffino
Published on

His arrest in 2019, as he was sailing away from Malta on his yacht, sparked a series of mass protests in the country that culminated with Prime Minster Muscat’s resignation.

A jury in Malta on Wednesday found Maltese businessman Yorgen Fenech not guilty of charges related to the 2017 car bomb killing of investigative journalist Daphne Caruana Galizia.

Caruana Galizia's killing shocked Europe, sparked protests that led to the resignation of a prime minister and exposed a culture of impunity in Malta, the European Union's smallest member state.

Fenech, a prominent Maltese businessman, was indicted in 2021 on charges of complicity and criminal conspiracy. He was involved in a consortium that won a controversial contract with the Maltese government to build a power station.

Prosecutors accused Fenech of masterminding the killing and of ordering and paying for it.

Fenech pleaded not guilty, and the jury on Wednesday found him not guilty on both counts. He was the last of a half-dozen people charged over the plot to be prosecuted.

Following the verdicit, he walked out of the Valletta courtroom to a chaotic scene outside, with hecklers yelling as he walked into a waiting car. He made no comment.

Yorgen Fenech leaves court in Valletta, Malta, on 29 November 2019.
Yorgen Fenech leaves court in Valletta, Malta, on 29 November 2019. Martin Agius/AP/str

Targeted over her anti-corruption investigations

Caruana Galizia, 53, was killed on 16 October 2017 when a car bomb exploded as she was driving near her home.

She had reported extensively on suspected corruption involving political and business figures in Malta.

Her investigations included members of then-Prime Minister Joseph Muscat's inner circle, whom she accused of having offshore companies in tax havens revealed by the Panama Papers. Her reporting also scrutinised opposition figures and Maltese business leaders.

At the time of her death, Caruana Galizia was facing more than 40 libel lawsuits.

An independent inquiry into her killing, published in 2021, concluded that the Maltese state “has to bear responsibility” for the assassination due to a culture of impunity that emanated from the highest levels of government.

Protesters in Valletta call for Prime Minister Joseph Muscat's resignation following developments in the Daphne Caruana Galizia murder case, 29 November 2019.
Protesters in Valletta call for Prime Minister Joseph Muscat's resignation following developments in the Daphne Caruana Galizia murder case, 29 November 2019. Image Rene Rossignaud/AP

Others prosecuted over the killing

In 2022, George Degiorgio and his brother Alfred Degiorgio pleaded guilty to carrying out the killing and were each sentenced to 40 years in prison.

In 2025, Jamie Vella and Robert Agius were sentenced to life in prison, the maximum possible penalty, after being convicted of complicity in the murder. The two men were accused of supplying the bomb that killed Caruana Galizia.

Another man, Vincent Muscat, pleaded guilty in 2021 for his role in the slaying, and was sentenced to 15 years in prison.

Melvin Theuma, a taxi driver who admitted acting as a middleman, was granted a presidential pardon in 2019 in exchange for his testimony.

'Our country failed to protect Daphne'

Caruana Galizia's children were at the forefront in demanding accountability and justice for her death. Her sons were in the courtroom when the verdict was read out but left without commenting.

In a statement later posted to Facebook, the family said the verdict denied Caruana Galizia the “justice she deserves."

“Nine years after Daphne’s brutal assassination, the institutional failures that enabled her murder remain unaddressed and unreformed. Lasting justice means no person should ever face the same risks again," the statement said. "Our country failed to protect Daphne. It owes it to her to prevent other lives being lost.”

No cameras were allowed in the courtroom, as is customary in Maltese criminal trials.

 

'Climate policy must survive, because we want to survive in Europe,' EU Commission says

Wind turbines operate near Aschersleben, Germany, Tuesday, Sept. 1, 2026.
Copyright AP Photo / Matthias Schrader

By Marta Pacheco
Published on

Europe cannot afford to choose between climate policy and competitiveness or security, a senior EU official said.

The European Union's worsening exposure to extreme weather and imported fossil fuels makes decarbonisation as much a matter of economic and security policy as climate policy, a senior European Commission official said.

Russia’s war against Ukraine and the disruption around the Strait of Hormuz have raised successive warnings about Europe’s dependence on imported oil and gas, Jan Dusik, director general at the Commission's climate department, said on the sidelines of the think tank Bruegel Annual Meetings on Wednesday.

“Climate policy must survive, because we want to survive in Europe,” Dusik said, arguing that abandoning or weakening the agenda would ignore its links to energy security, resilience and affordability.

The EU's premise is faster electrification of its economy and the development of domestic energy sources to reduce its vulnerability to volatile fossil-fuel markets, Dusik said, which have raised energy bills and are threatening the bloc's industrial competitiveness.

At a time when climate policy is being contested as too onerous for industry competitiveness vis-a-vis China and the United States, the Commission is rolling out its next climate measures in stages, with the end goal of reaching net-neutrality by 2050, even if many critics argue the climate targets are becoming unrealistic and can become counterproductive if the market stops believing in it.

"Most people will tell you we're not going to be in net zero in 2050. That's what I hear. And so it creates some cognitive dissonance, because by pretending we are going there, but having a lot of people believing we're not going there, you lose the credibility of the instruments,” Wunsh told the Bruegel audience on Wednesday.

But the EU executive remains focused on pursuing climate neutrality. The first step came in July with the proposed review of the EU carbon market, the Emissions Trading System (ETS).

Next month, the Commission plans to present a climate resilience framework to help Europe better cope with heatwaves, floods and other climate impacts. By the end of 2026, it plans to unveil the rest of its post-2030 climate package, setting out how the EU intends to deliver its 2040 emissions-cutting target.

ETS: defending the credibility of the 2040 pathway

On the ETS, Dusik rejected suggestions that the EU executive is effectively “playing with numbers” by allowing flexibilities, existing carbon allowances and future carbon removals while simultaneously targeting a 90% reduction in net greenhouse-gas emissions by 2040.

The Czech EU politician said the ETS and the wider post-2030 climate package were designed as a single system and will ultimately have to add up to the EU’s overall carbon budget.

"There are moments where we look at how the legislation is implemented, and we are doing adjustments as we have done for the market stability reserve, as we are doing for the benchmarks in the ETS, which does not jeopardise that total carbon budget that we should have in 2040 or 2050. It needs to add up and this is designed to add up," Dusik said.

The key mechanism, Dusík suggested, will increasingly be price rather than simply the quantity of carbon allowances. As the number of allowances declines through the 2030s, prices are expected to rise, creating a stronger financial incentive for companies to invest in cutting emissions rather than continue paying for carbon.

The Commission is also preparing to introduce additional flexibility through carbon removals and international carbon credits.

But the official stressed that these should complement, rather than replace, European investment.

International credits could help lower the overall cost of meeting targets, but Brussels does not want a system in which European companies simply buy reductions abroad instead of investing in clean technologies at home.

"This needs to be done in a very smart way, knowing what the amount of credit is available, how it complements rather than replaces domestic investments. Because after all, we are also interested in investing in Europe, rather than purchasing investments abroad. So it needs to be the right mix," the Commission official said.

Climate adaptation is becoming unavoidable

The official also acknowledged that the EU is increasingly having to deal with climate impacts that cannot be prevented by mitigation alone.

Following a summer marked by extreme weather, the Commission plans to put forward a climate resilience framework, arguing that Europe needs to prepare for a world in which climate impacts become increasingly severe.

Even if the world fails to stay within the Paris Agreement's 1.5°C goal, the official argued, every fraction of additional warming still matters because it translates into higher economic and social costs.

“This doesn't mean that we will give up on the Paris targets. It means that we have to recognise that the challenge is going beyond being able to stay under the one and half degree target," Dusik said.

"At the same time, we know that every fraction of a degree is a massive impact, a massive cost for the whole society, and the longer and the further we get into the overshoot, the more of the problem it will be.”

ETS revenues: Brussels wants more money going back into industry

One of the sharper criticisms focused on how governments use the revenues generated by the ETS. The Commission's analysis, according to the EU official, found that only around 5% of ETS revenues are actually being returned to industry for decarbonisation.

Since its inception in 2005, the ETS was not supposed to function simply as a source of government revenue. With a growing climate finance gap, Brussels wants more of the money generated by carbon pricing to finance the transition itself, including hydrogen, batteries, carbon capture and storage and other industrial technologies.

The proposed 'ETS investment booster', the industrial decarbonisation bank and the Innovation Fund are intended to turn carbon pricing into an investment mechanism rather than simply another cost for companies, the EU official said.

From infrastructure to military drills, China deepens footprint in Egypt as Xi visits Cairo

Chinese President Xi Jinping is welcomed by Egyptian President Abdel-Fattah el-Sisi upon his arrival at Cairo International Airport for an official visit to Egypt,
Copyright Mohamed Abd El Ghany/Pool Photo via AP


By Mohamed Elashi
Published on

Chinese President Xi Jinping’s return to Cairo comes as Egypt and China push their relationship beyond infrastructure and trade into technology, defence and a broader strategic partnership with regional implications.

Chinese President Xi Jinping arrived in Egypt on Tuesday for his first visit since 2016, as the two countries mark 70 years of diplomatic ties and push their relationship into new areas in what Beijing has described as a "comprehensive strategic partnership".

Since his last visit, some of Beijing's megaprojects have become part of Egypt’s landscape.

Chinese companies have helped build the central business district of Egypt’s New Administrative Capital. Built by China State Construction Engineering Corporation, it consists of 20 skyscrapers.

At its centre stands the 385.8-metre Iconic Tower, Africa's tallest building.

A light rail system built with Chinese involvement connects Cairo’s eastern outskirts with new urban centres, and a China-Egypt industrial zone near the Suez Canal now hosts more than 200 companies.

The industrial zone created more than 10,000 direct jobs, according to Chinese figures. Chinese reporting puts total investment at more than $4.7 billion (€4.05bn).

The scope is now widening.

AI, advanced manufacturing and technology transfer are increasingly part of the economic agenda, while Chinese and Egyptian fighter aircraft have been training together in the second joint air force exercise between the two countries.

Trade grows, but so does the imbalance

Bilateral trade reached $11.3 billion (€9.75bn) in the first six months of 2026, up 21.5% year on year, according to Egypt's Central Agency for Public Mobilisation and Statistics.

Egyptian exports to China almost tripled to $840.8 million (€725.4m), driven by fuel, mineral oil, fruit, vegetables and cotton.

But imports from China reached $10.4 billion (€8.97bn) over the same period — machinery and electrical equipment alone accounting for $4.1 billion (€3.5bn), followed by vehicles, iron and steel, plastics and chemicals.

The China-Egypt TEDA industrial zone in Ain Sokhna has attracted more than 200 companies.
The China-Egypt TEDA industrial zone in Ain Sokhna has attracted more than 200 companies. TEDA Investment Holding/Handout via Xinhua

Egypt wants Chinese investment and technology, but also wants more Chinese companies to manufacture inside Egypt and greater access for Egyptian goods to the Chinese market.

A five-year programme agreed for 2024-2028 calls for local production and technology transfer in electric vehicles, electronics, solar panels, chemicals and modern agricultural technology, with artificial intelligence also listed as a priority.

El-Sisi said ahead of the visit that Egypt wanted to attract Chinese investment in EVs, battery storage, renewable energy and shipbuilding, while expanding technology transfer in telecommunications, AI and space sciences.

Military ties move into view

Defence links are also becoming more visible. China and Egypt are holding the second edition of their Eagles of Civilisation joint air force exercise, running from mid-August into early September at Egyptian air bases. The first was held only last year.

Chinese officials said the 2026 drills would include air combat tactics, air superiority operations, combat search and rescue and joint force deployment.

The US remains Cairo's key longstanding security partner, providing large-scale military assistance and supplying a significant part of Egypt's diversely sourced military equipment.

Washington has not publicly commented on the Chinese exercises. The Pentagon has previously flagged concerns about Chinese military engagement with US partners across the Middle East and Africa.

The exercises fit Egypt's wider policy of diversifying its defence partnerships, a deliberate balancing act that also encompasses its involvement in BRICS, the New Development Bank and the Shanghai Cooperation Organisation alongside continued reliance on Western economic and security support.

Next phase of relations crucial

Ahead of the visit, Xi described the country as an important link between the Arab world and Africa and called for deeper China-Arab and China-Africa cooperation through Egypt.

For China, Egypt combines a market of more than 100 million people with a strategic position on the Suez Canal and political weight across the Arab world and Africa.

The two governments have also taken similar positions on several regional issues, including support for a Palestinian state, while Egypt maintains its One China policy.

Fireworks light up the Chinese-built Iconic Tower in Egypt's New Administrative Capital during New Year celebrations.
Fireworks light up the Chinese-built Iconic Tower in Egypt's New Administrative Capital during New Year celebrations. AP Photo

Egypt was the first Arab and African country to establish diplomatic relations with the People's Republic of China in 1956.

El-Sisi has travelled to China eight times since taking office in 2014, most recently in May 2024.

The agreements announced during Xi's visit are expected to provide more detail on newer areas of cooperation, particularly technology transfer and advanced manufacturing, where Egypt has pushed hardest to move beyond the construction and infrastructure model that defined the relationship's first decade.

 

X's new payments app X Money hit by mass hacking attempt

Workers install lighting on an "X" sign atop the company headquarters, formerly known as Twitter, in downtown San Francisco, on Friday, July 28, 2023.
Copyright AP Photo/Noah Berger

By Indrabati Lahiri
Published on

Unsolicited password reset emails have hit X users after the launch of X Money, with the platform warning that hackers could be behind a wider phishing attempt.

X has revealed that hackers could be trying to attack users after the launch of X Money.

This follows several X users receiving surprise password reset emails. Although the social media giant has been looking into the issue, there is no evidence so far that these attack attempts were successful.

It is believed that attackers could be mass-triggering the form for password resets using public usernames

An X user discussing the recent breach attempt

X Money, the platform's payments service, launched on an invite-only basis in July before expanding to all Premium and Premium+ subscribers on 31 August.

It allows users to hold money, make and receive payments, as well as carry out peer-to-peer transfers, all on the X platform.

As such, any access that attackers may get to these users' accounts could have significant financial implications.

The company's general counsel, James Burnham, highlighted that "the legal and security teams @X will stop at nothing to identify, locate, and hold criminally accountable any person anywhere on or off earth who attempts to victimize our platform's users."

This has led to a flood of users taking to the platform to both spread awareness that this is happening and also remind others to use two-factor authentication, if they aren't already, for an added layer of protection.

Glen Bradley urges users to enable two-factor authentication to prevent attacks

The social media platform's Grok chatbot has also chimed in, replying to some posts with practical measures users can take to do so.

Could this be hiding a more dangerous phishing attack?

Although receiving an email for a supposed password change request doesn't automatically mean your account has been breached, especially if you have multi-factor authentication, some users are concerned that this latest incident could be hiding a wider phishing attempt.

Several users have also claimed that follow-up phishing emails have been sent out, along with these password reset confirmation emails. These have been framed as legitimate emails coming from X, which has added to the confusion and fear.

An X user warning about the potential of a wider phishing attack

These emails have been urging users to change their passwords, which is an expected follow-up after a security breach. However, they include a fake X link for users to do so, which can trick them into providing their login credentials to attackers.

As such, this is more likely to be an elaborate multi-step hacking and phishing attempt than previously expected.

X Money has already faced scrutiny for its reliance on partner banks like Cross River Bank, due to past regulatory enforcement actions against the bank, as well as the underlying reasoning behind the promotional 6% yield on deposits, compared to federal benchmarks.

 


How Taiwan's AI stock boom has ordinary people borrowing to invest

FILE - People walk past an electronic stock board at Taipei Exchange in Taipei, Taiwan, Monday, Jan. 30, 2023.
Copyright AP Photo/(AP Photo/Chiang Ying-ying)

By Una Hajdari with AFP
Published on

People across Taiwan are taking out loans and even remortgaging their homes to chase gains in an AI-fuelled stock boom — and not everyone is coming out ahead.

Taiwan is in the grip of a borrowing frenzy — but not for houses or cars. This year, people are taking out loans to buy stocks.

As Taiwan's stock market soared this year, real-estate worker Lucas Chen borrowed NT$5 million (€136,000) to buy tech shares, and within six months he had quadrupled his money.

Chen is one of a growing number of people using debt to buy into the island's stock market, which soared 59% in the first half of the year thanks to booming demand for AI hardware made by chip giant Taiwan Semiconductor Manufacturing Co (TSMC) and others.

But while the prospect of vast returns has lured and repaid many handsomely, others have suffered hefty losses or been tricked by scammers, prompting authorities to issue warnings about the risks.

"The first half of the year was really crazy. It was absolutely wild," said Chen, who makes a base salary of up to NT$50,000 (about €1,360) from his job.

The 34-year-old began trading in the stock market 10 years ago, saving up his bonuses to buy chip titan TSMC, which accounted for about 45% of the Taiwan Stock Exchange at the end of 2025.

At the start of this year, Chen saw "a good opportunity" to increase his investments and took out three bank loans worth NT$5 million, using his new Tesla as collateral for two of them.

The bet paid off.

Chen's tech investments, half of them in TSMC, surged nearly 70%, pumping up his holdings by about NT$20 million (€544,000) by late June.

"The older generation would say borrowing money isn't a good thing," Chen told AFP, adding that if you did the maths carefully, the risks were "controllable".

Financial influencer Yeh Yu-shuo has enjoyed the fruits of the market but has also seen the downside of the stock-buying frenzy in his Facebook group, where hundreds of thousands of members trade investment advice.

"I've reviewed posts saying they want to jump off a building," Yeh said.

One anonymous poster said in early August he had invested NT$10 million (about €272,000), including a NT$6 million (about €163,000) mortgage, in recent months and had lost nearly half of it.

"Since last month I've been waking up in the middle of the night in a panic," the poster said.

"I've already sought treatment from a psychiatrist, and I even went to Zinan Temple, but none of it has helped at all. Right now, all I want is to get my money back as quickly as possible."

'Buying stocks like crazy'

Global stock markets have surged this year to record highs as tech firms ramped up spending on AI data centres, hardware and software.

However, the rally hit a wall in July, hammering the tech sector on concerns over when that cash will see a return and warnings that company valuations had gone too far.

Anticipation of a US interest rate hike has also weighed on sentiment and could curb demand for stocks, particularly tech firms, which rely on borrowing to fuel their investments.

While some people in Taiwan have used their savings or borrowed from family to invest, many have relied on banks or brokers to fund their stock purchases.

Norman Yin, a professor of money and banking at National Chengchi University, said young people have been "buying stocks like crazy".

Taiwanese banks are sitting on "unprecedented" levels of deposits, partly due to stagnant property prices, and are very willing to lend.

"If I borrow money from a bank to buy stocks, I could make more in one day than I earn from my salary in a month," Yin said, noting fresh graduates often made around NT$40,000 (about €1,090) per month.

"It's faster and easier than sitting in an office and working hard."

Meanwhile, margin trading — in which investors use funds borrowed from a broker to buy securities — rose nearly 20% in the first half from the previous six months, Taiwan Stock Exchange data show.

Taiwan's Financial Supervisory Commission told AFP that overall "credit risk remains under control".

The stock exchange has started publishing videos on social media warning young investors of the risks of defaulting on their loans.

'Windfall for our generation'

Social media platforms in Taiwan are rife with posts about people making huge sums and quitting their jobs to trade full time.

Marketing specialist Jerry Lee, 30, said he has watched with some envy as friends post about their gains in their group chat.

"When you see someone make two or three months' salary in two days, oof, that's really painful," said Lee, who describes himself as a conservative investor.

Social media gives the impression that "everyone is making money," he said.

"When it's dropping they won't tell you about it."

Taiwan's stock index fell about 16% from its record high on 22 June to 30 July, while South Korea's market — the poster child of the global tech-led surge this year — plunged about 40%.

Still, Yeh said he had confidence in Taiwan's stock market "as long as TSMC remains stable". The Taiex has recovered almost all the losses sustained in the summer sell-off.

Chen said the opportunity to make money would keep him investing.

"This is a windfall for our generation," he said.




Industrial AI Needs An Authority Test Before It Touches The Physical World – Analysis


Image: ChatGPT


September 2, 2026

By Burak Oktenli

Key Takeaways:

Once industrial AI can write setpoints or isolate kit—not just recommend—the test is authority, not average accuracy: what it may change, on what evidence, for how long, who interrupts, and when it must abstain.

Give every acting system a documented authority envelope that narrows as consequence or sensor quality worsens; use twins and “ugly data” (drift, stale values, comms loss) to measure scope, abstention, reversion time, and a log of why permission existed—not only the command issued.

Five Eyes agentic-AI guidance, NIST OT/smart-manufacturing work, and the EU AI Act’s high-risk calendar (2027–28) already point that way: put envelopes in procurement and revalidate after model or plant changes, so the plant knows where the AI stops.


A model can be accurate and still be unsafe if its permissions, evidence thresholds, fallback logic or audit trail are wrong. Before AI writes to a plant, grid or industrial process, operators should test what it is allowed to do – not only how well it predicts.

Industrial artificial intelligence is crossing an important boundary. For years, most deployments predicted failures, forecast demand, optimized schedules or recommended process changes while a human or conventional control system remained responsible for execution. Increasingly, AI is being connected to tools that can write settings, isolate equipment, change operating parameters or trigger workflows that reach the physical process.

At that point, accuracy stops being the only validation question.


A model can be highly accurate on average and still be given permissions that are too broad. It can keep acting after sensor quality deteriorates. It can make a defensible recommendation under one operating state and continue using the same authority after the evidence supporting that state has gone stale. It can leave a perfect log of what command was issued while failing to preserve why the system was allowed to issue it.

The additional question is authority: What may the system change? On what evidence? For how long? Who can interrupt it? What forces it to abstain? And what happens when control has to return to a person?
Cyber Agencies Are Already Warning About Permission, Not Just Performance

A useful signal came in May, when six national cybersecurity agencies across the Five Eyes published joint guidance on the careful adoption of agentic AI services. The document is aimed primarily at tool-using software agents rather than industrial controllers, so the two should not be conflated. But its governance logic is directly relevant wherever AI can act instead of merely advise.


The guidance tells operators to limit privileges, define trigger-action protocols that automatically restrict permissions when unexpected behavior appears, separate duties, record delegation chains, use explicit expiry for delegated authority and require stronger approval for higher-stakes actions.

That is a different security vocabulary from conventional model validation. It treats the dangerous object not simply as a prediction but as a prediction coupled to permission.

Operational technology makes that coupling more consequential because software outputs can become pressure, temperature, flow, voltage, speed, valve position, chemical concentration or physical movement.

NIST’s Guide to Operational Technology Security emphasizes that OT systems interact directly with the physical environment and must be secured while preserving their distinctive performance, reliability and safety requirements. Its 2026 smart-manufacturing AI roadmap likewise places autonomous systems and digital twins among the technologies reshaping manufacturing while stressing the need for trustworthy, explainable and reliable operation in high-stakes industrial environments.

The implication is simple: when AI gains write access to a physical process, model assurance and authority assurance become separate test problems.
Accuracy Answers the Wrong Question Once AI Can Act

Suppose an optimization model predicts an energy-saving setpoint correctly 97 percent of the time. That number says nothing about whether the system should be allowed to write the setpoint during a sensor disagreement, after a communication delay, while a maintenance override is active, or when one of the variables feeding the model has not refreshed for ten minutes.


A plant can therefore have an accurate model inside an unsafe permission architecture.

The same distinction applies outside manufacturing. An AI system in a power network may forecast load accurately but still need narrow authority over switching actions. A building-management system may predict thermal demand well while requiring hard limits on which zones, valves or emergency systems it may change. An autonomous warehouse optimizer may make good routing decisions but still need an immediate reversion path when people enter a restricted movement area.

The engineering question is no longer merely, “Does the AI make the right prediction?” It becomes, “Can the AI be wrong safely?”
Give the System an Authority Envelope

Before live deployment, every AI system capable of changing an industrial process should have a documented authority envelope: the set of actions it may initiate, the assets and variables it may write to, the evidence required for each class of action, the duration of each permission, and the conditions that force abstention, escalation or human approval.

The envelope should narrow as consequence rises. A system may be allowed to adjust a low-consequence scheduling variable autonomously while only recommending a change to a safety-relevant setpoint. A permission that is safe for ten minutes during stable operations may be unsafe after a sensor fault, alarm, maintenance intervention or major configuration change.

Expiration matters because industrial authority is often contextual. Permissions should not silently survive the evidence that justified them.

This is the same underlying control principle I have described in the context of AI agents as an authority envelope: define what the system is allowed to reach and do, and enforce that boundary technically rather than treating it as a behavioral preference. In a plant, the envelope is physical as well as digital.
Use the Digital Twin to Test Authority, Not Just Performance

Digital twins, operator-training simulators, hardware-in-the-loop rigs and isolated process testbeds create an obvious place to test that envelope before the AI touches live equipment.

The test environment must be fit for purpose. It should match the relevant plant configuration closely enough to represent the hazards being exercised, remain isolated from live control, and be synchronized often enough that operators are not certifying yesterday’s plant. A weak or outdated twin can create false confidence.


Simulation should therefore complement rather than replace hazard analysis, factory and site acceptance testing, independent protection layers and production monitoring.

But a validated twin can expose a class of failure that ordinary historical backtesting often misses: an AI system whose model performance looks acceptable while its operational authority is not.
Four Measurements Matter

Scope. Did the system attempt or retain access beyond the functions approved for the scenario? A safe result is not enough if the system used an unsafe path to reach it.

Abstention. When evidence quality fell below the acceptance threshold, did the system stop, downgrade to advisory mode, narrow its permitted actions or request human review?

Reversion. How long did it take to restore effective human control and an accurate operating picture? The acceptable time should come from the process hazard analysis, not from a universal AI benchmark.

Traceability. Can the event record reconstruct who or what held authority, which evidence triggered the action, what changed, why it changed, when the permission expired and how control returned to a person?

These measurements turn an abstract governance principle into an acceptance test.
Test the Ugly Data

Clean historical data are not enough. The authority test should deliberately create the conditions in which a plausible AI system is most likely to become overconfident.

Introduce slow sensor drift. Feed stale but believable values. Create disagreement between instruments. Delay communications. Remove context that is normally present. Inject manipulated readings that stay inside normal-looking ranges. Simulate maintenance modes, partial network loss and an operator who does not acknowledge a handoff immediately.

Then ask two separate questions.

Did the model’s output degrade appropriately?

And did the system’s permission to act contract as confidence in the evidence declined?

The second question is the one conventional accuracy testing tends to miss.

The International Rules Are Moving in the Same Direction

Regulators are also moving toward lifecycle controls for high-consequence AI. The European Union’s AI Act implementation framework now has enforcement in place for the provisions already applicable, while high-risk rules for certain critical-infrastructure uses are scheduled for December 2027 and high-risk AI embedded in regulated products for August 2028.

The details of those regimes will matter, but operators do not need to wait for a regulation to discover that a permission boundary is an engineering property.

The Five Eyes guidance, NIST’s OT security work and Europe’s high-risk approach differ in legal form and scope. Yet they converge on a practical point: systems that can take consequential action need bounded access, human oversight, monitoring, traceability and tested fallback behavior.

Industrial AI programs should convert that convergence into procurement language now.
Put Authority in the Acceptance Criteria

A vendor supplying AI that can influence a physical process should be required to state and demonstrate more than model accuracy.

The acceptance package should specify the approved action set, evidence thresholds, permission expiration, escalation path, safe-state behavior, maximum reversion time, logging and provenance requirements, and the conditions under which the system must fall back from autonomous execution to recommendation only.

Material changes to the model, sensors, thresholds, process configuration or connected tools should trigger targeted revalidation of the authority envelope, not merely a fresh accuracy report.

That does not mean freezing industrial AI. It means treating permissions as part of the controlled configuration.
The Plant Should Know Where the AI Stops

Industrial automation already has a mature culture of commissioning, acceptance testing, hazard analysis and independent protection. AI should extend that discipline rather than bypass it.


The temptation will be to focus on the exciting metrics: prediction accuracy, optimization gains, reduced downtime and faster response. Those numbers matter. They are not enough once the model can act.

Before an AI system touches pressure, temperature, flow, voltage or movement, make it prove not only that it understands the process well enough to help operate it.

Make it prove that it knows where its authority ends.


About Burak Oktenli

Burak Oktenli holds an MBA and a Master of Professional Studies in Applied Intelligence from Georgetown University. His research addresses the governance of authority in autonomous and AI-enabled systems, and his writing has appeared at the Modern War Institute at West Point, RUSI, RealClearDefense, RealClearMarkets, and Geopolitical Monitor. He is the author of Authority Architectures for Autonomous Systems, a ten-volume series on how authority in autonomous systems is delegated, monitored and recovered, at authority-architecture.me.

View all posts by Burak Oktenli →