Skip to content

Last updated

Engineering

  • Printed export inventory on a desk, permission lists beside a schema diagram, a catalog table and a network trust diagram
    Data Act cloud switching requirements

    Article 30 of the EU Data Act splits a switching duty by capability, not by service-model label, and Article 2(37) defines functional equivalence in law while no published standard operationalises it into a threshold. This article works through the exemption gate, the export inventory beyond raw data and the escrow-and-rebuild record that stands in for the missing standard, including the correction most coverage misses: 12 January 2027 zeroes switching charges, not multi-cloud egress.

  • Two records of the same fund holdings compared side by side, a printed ledger listing and a bound shareholder register
    Tokenized fund register reconciliation

    A tokenized fund runs two books, the ledger the token moves on and the shareholder register a transfer agent maintains, and three published regimes now say which one wins when they disagree, in two opposite directions. None of them says how anyone learns the two diverged, at what cadence or where the investor stands between a bad entry and its reversal.

  • Two bound hardcover incident logbooks lying open side by side on one desk with visibly different column rulings and a separate pen resting in each, the two independent classification passes a financial entity runs under the AI Act and DORA
    AI Act and DORA Overlap

    How the EU AI Act and DORA land on the same financial entity without either text citing the other, why Article 74(6) puts the AI file on the financial supervisor's desk, and what Articles 26(5), 26(6), 72(4) and 73(9) actually change.

  • A bank compliance officer reading from an open supplier manual while a colleague fills a single row on a wide ruled sheet whose other rows stay empty, the deployer side fundamental rights impact assessment owed by banks and insurers under the AI Act
    AI Act Fundamental Rights Impact Assessment

    Article 27 of the AI Act puts the fundamental rights impact assessment on the deployer, names creditworthiness and life and health insurance pricing explicitly, and since July 2026 lets it cross-reference an existing data protection impact assessment.

  • An on-duty engineer standing at a desk with a phone handset lifted off its cradle and starting the first entry on a blank printed incident record form, the moment one of the AI Act reporting clocks starts running
    AI Act Serious Incident Reporting

    The AI Act defines a serious incident in four alternative limbs and attaches three different reporting deadlines to them, and since 27 July 2026 the recipient of the report depends on who supervises the provider.

  • A hand-ruled monitoring plan draft on plain paper beside a printed list of logging fields on a working desk, the Article 72 plan a team has to design itself because the mandatory template never issued
    AI Act Post-Market Monitoring Plan

    What Article 72 of the EU AI Act requires of a post-market monitoring system and plan, why the mandatory Commission template was repealed before it ever appeared, and what telemetry, logging and retention an engineering team has to build to make the plan real.

  • A provider's own staff signing the declaration page on a thick conformity file in a small office with no external assessor present, the Annex VI internal control route for credit scoring and insurance pricing under the AI Act
    AI Act Conformity Assessment

    Which conformity assessment procedure applies to a high-risk AI system under Article 43, why Annex III point 5 credit and insurance systems take the Annex VI internal control route with no notified body involved, and what evidence a self-assessment has to produce and keep.

  • Two clipped printed legislative texts on a payments engineering desk under a magnetic wall planner strip whose first slot sits empty, PSD3 and PSR planning without a publication date
    PSD3 Compliance Requirements

    PSD3 and PSR compliance is an offset from an unset anchor, not a calendar date. The 21 and 27 month tiers, sourced from the Council's April 2026 compromise texts, and what a build has to have ready before either clock starts.

  • Macro of a printed source document marked with cut lines at its section breaks and one exception clause bracketed back to the rule above it.
    RAG Data Pipeline

    A RAG corpus is a live system with state, not a build artifact. This piece traces one document through arrival, change, duplication, deletion and embedding model migration, and shows where five major vector stores document contradictory answers to the same event.

  • An accessibility testing bench laid out with a refreshable braille display, a keyboard with the mouse set aside, a switch access pad and headphones.
    European Accessibility Act Compliance

    The European Accessibility Act never names WCAG or EN 301 549. This piece sorts a software company into the role that actually carries liability, and states plainly why the standard everyone cites carries no legal presumption here.

  • Duty analysts at a public sector security operations desk during a shift handover with a wall clock and a paper incident log between them.
    NIS2 Compliance Software Requirements

    NIS2 never names a software company as a regulated type. This piece sorts a software vendor into the route that actually applies, then lists the artifacts each route asks it to keep on a shelf.

  • Hardware test bench with a small connected device opened on an anti static mat beside a clipped printed dependency list and an archive box.
    CRA Vulnerability Handling Requirements

    Annex I Part II of the Cyber Resilience Act sets eight standing vulnerability handling duties, and Article 13 layers two further clocks on top: a support period of at least five years, unless the product's expected use is genuinely shorter, and a ten year availability window on every security update issued during it. Which conformity route a product takes then depends on its Annex III or Annex IV class.

  • Two colleagues in a documentation and print room, one lifting a printed checklist from an office printer while the other types into a plain web form on a laptop.
    CRA Single Reporting Platform Integration

    The CRA's Single Reporting Platform is a web form and case management system that ENISA runs, not an API, with no published roadmap for one. Registration runs through named individual Assigned Representatives, and one notification record moves through three stages that lock for good once the final report is submitted.

  • Hands and shoulders of two colleagues comparing clauses across three thick ring binders opened flat in a small meeting booth.
    CRA NIS2 and DORA Reporting Overlap

    A company that is at once a CRA manufacturer, a NIS2 essential or important entity and a DORA financial entity keeps three separate reporting duties on three separate filings, even where two of them reach the same national CSIRT. The CRA's Single Reporting Platform consolidates filings within the CRA itself and does not fold NIS2 or DORA into that filing.

  • Close up of a printed two column triage sheet and a fanned stack of index cards on a security operations desk with wall monitors behind.
    CRA Severe Incident Classification

    The Cyber Resilience Act never defines severe as a standalone term. The threshold sits in Article 14(5), narrowing the general incident definition to sensitive or important data or functions, or to malicious code, while Article 3(42) sets a separate evidentiary bar for actively exploited that a high severity score alone does not meet.

  • Top down view of two printed reporting timelines, a desk clock and a marked regulation extract on an incident war room table.
    CRA Incident Reporting Deadlines

    The EU Cyber Resilience Act's Article 14 sets up two separate reporting duties, not one sequence: an actively exploited vulnerability and a severe incident share the same 24-hour and 72-hour stages but diverge at the final report deadline. Filing there does not satisfy the separate duty to inform affected users.

  • Five vendor pricing sheets fanned in a row on a desk beside a handwritten notepad of measured trace usage, the working papers behind an LLM observability cost comparison
    LLM Observability Cost

    A real LLM observability cost model built from verified vendor pricing retrieved 2026-08-08, showing why Langfuse, LangSmith, Braintrust and Arize cannot be compared on list price alone and how the OpenTelemetry GenAI conventions' Development status quietly breaks naive cost attribution.

  • Two developers scoping a build against a handwritten enumerated list on paper with the keyboard pushed aside, the planning stage of Model Context Protocol server development
    MCP Server Development

    A spec-current guide to MCP server development after the 2026-07-28 revision, covering the stateless protocol change, the modern-vs-legacy split, server primitives, transports, authorization and the named security failure modes, plus what a server actually costs to build and maintain.

  • An auditor's reserve file open at a tabbed valuation section on a desk beside a sealed filing envelope and a desk calendar, the six-monthly attestation evidence behind electronic money token issuance
    Electronic Money Token Issuance

    MiCA describes an accounting outcome for an e-money token and almost never a mechanism. This follows one euro through the licence gate, the mint, placement, circulation, the redemption request, burn and attestation, states which of those steps the Regulation actually specifies and names the two places where it specifies nothing at all.

  • Two finance operations colleagues at adjacent desks matching a customer balance figure on an internal ledger printout against a bank statement drawn from a separate system, the daily reconciliation an e-money safeguarding team has to prove
    E-Money Safeguarding Reconciliation

    An EMI or PI CTO has to prove on any business day that customer balances in the ledger equal the safeguarding accounts. No EU instrument in force names how often that comparison runs. This walks the invariants that do exist, the way each one breaks and the control that catches the break, ordered by how fast the control fires.

  • Three analysts at a shared hit review desk working down a queue of flagged transfers, one clearing an item and setting the sheet aside, the review work the EU Instant Payments Regulation reshapes
    Instant Payments Sanctions Screening

    Article 5d did not ban sanctions screening on the instant rail. It moved the object of the screening from the transaction to the customer base, prohibited one specific check in one specific window between two specific parties and carved out three categories expressly. This walks the pre-2025 screening stack component by component and states, for each one, what replaces it and which control it was carrying.

  • Printed routing directory pages spread across a table with one entry tabbed and a magnifier resting on it beside a mechanical stopwatch, the lookup and the fixed clock in a Verification of Payee build
    Verification of Payee Implementation

    Verification of Payee is two jobs in one build, and the scheme treats them very differently. The requesting side is a specified round trip with a five second envelope and a discard rule. The responding side is a specified message shape wrapped around a decision the scheme declines to make, in a guidance document that says it is not part of the Rulebook and that the responder is free to ignore. This walks the message lifecycle position by position, states each one twice and closes each one on the contract both sides owe.

  • A payments operations analyst standing at her desk checking a printed batch of customer payment records against a screen in a bank operations room before the ISO 20022 address deadline.
    ISO 20022 Structured Address Migration: What Breaks on 15 November 2026

    The EPC's 15 November 2026 inter-PSP settlement date and Swift's 14 November 2026 SR 2026 go-live are two different events on one cutover weekend. This walks an address population through seven gates, from scope to the inter-PSP double rejection duty, and states at each gate which records die and what the remedy is.

  • An operations team signing off a frozen balance snapshot beside a printed seven phase wind down sequence with the earlier phases struck through by hand, the sequence a MiCA Article 74 wind-down plan sets in motion
    CASP Wind Down Plan

    A CASP wind down plan is required by MiCA Article 74 and defined by almost nothing else in the act: no paragraph numbering, no recital, no technical standard, no filing duty and no deadline. What MiCA does supply is two conflicting destinations for client assets, a transfer to a successor provider under Article 64(8) and a return to the client under Article 75(6), and it never says which one runs. This article walks the wind-down in execution order, from the duties that have to be standing before any exit decision through trigger, freeze, client instruction, execution, sub-custody unwind and register closeout, and it is honest about the three different timing formulas MiCA writes for cessation, none of which is a number.

  • Four printouts of the same balance from four different systems laid in a row with one figure circled in pen, the reconciliation evidence behind omnibus versus segregated crypto wallet structures
    Omnibus vs Segregated Crypto Wallets

    Omnibus vs segregated crypto wallets is an architecture decision with a statutory edge: MiCA Article 75(7) limb one requires that on the distributed ledger, clients' crypto-assets are held separately from the CASP's own. This article reads that sentence closely, shows where per-client granularity actually lives, walks the cost of each branch on UTXO and account-model chains and treats reconciliation between the on-ledger position and the Article 75(2) register as the evidence artefact a supervisor will ask for.

  • A bound evidence pack passed across a meeting room desk to a supervisor who is already opening it at the first divider, the supervisory evidence view of smart contract risk in crypto custody
    Smart Contract Risk in Crypto Custody

    Smart contract risk in crypto custody is the one ESMA Common Supervisory Action scope item with no settled evidence practice behind it. This article treats each claim a CASP makes about its contracts as a claim under test, and names the artefact that proves or falsifies it: how upgrade privilege is proven on chain and revoked, what a proxy admin key does to an Article 75(7) segregation argument, what a staking contract does to the register of positions and what 130 audits say about where the critical findings actually cluster.

  • A thick ring binder with archive tabs beside a slim saddle stitched booklet on a table, each with its own addressed envelope, the split between the two audiences a general-purpose AI model provider must write for
    GPAI Model Obligations

    What a general-purpose AI model provider owes regulators under Annex XI versus downstream integrators under Annex XII, where the open-source carve-out stops and why GPAI penalties sit in Article 101, not Article 99.

  • Someone pulling dated records out of open archive boxes and spreading them across a table to reconstruct technical documentation after the fact, why retrospective assembly fails under the AI Act
    AI Act Technical Documentation

    Annex IV of the EU AI Act translated point by point into engineering deliverables, plus the logging and retention duties in Article 12, Article 19 and Article 26 and the unconfirmed SME simplified-documentation route.

  • A printed product feature list annotated down a five step sequence with index tabs and two small product photographs clipped beside it, the high-risk classification test under the EU AI Act
    AI Act High Risk Classification

    How to classify an AI system as high-risk under Article 6 and Annex III of the EU AI Act after the Digital Omnibus, with the new 1a to 1c carve-outs, a decision tree and worked examples.

  • Two reviewers checking printed disclosure icon proofs against printed video frame stills on a long review bench, the marking check required by AI Act Article 50
    AI Act Article 50

    What Article 50 of the EU AI Act actually requires for marking AI-generated content, the two mandatory layers, the transitional date hidden in Article 111(4) and the failure modes the Code of Practice admits marking cannot survive.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? hello@pharosproduction.com

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day