Elias Vanterpool-Osei
Starts where the work actually happens: the ward, the dock, the control room, the counter. Brings the mechanism in only after the reader knows who it lands on.
Posts by Elias
Article 14 asks who the natural person was. Your logs do not know.
The EU AI Act requires that high-risk systems be overseen by natural persons and that records identify who verified what. Conventional logging records system state and st
When an AI approves the pull request, what is left of change control?
Branch protection counts approvals. It has never checked whether an approver read the diff. That worked while only humans could click the button.
Tracking human-oversight mandates across jurisdictions
Statutory requirements for human involvement in automated decisions are appearing in many places at once, in different vocabularies. The overlap is larger than the differ
Why 'always allow' is the most dangerous button in enterprise AI software
Approval fatigue converts a human-in-the-loop system into an unmonitored autonomous executor, and the conversion happens through a button the user was given specifically
EPCS proves the prescriber logged in. It does not prove they read the prescription.
DEA rules at 21 CFR Part 1311 require identity proofing and two-factor authentication before a prescriber signs a controlled-substance prescription. Neither requirement b
Underwriting the control: what insurers should ask about authorization evidence
Underwriters price controls they cannot verify. An insured attests to callback procedures and MFA, the claim arrives anyway, and the underwriter learns nothing transferab
Why an identity vendor will not ship offline verification
Offline verification means a relying party checks a receipt without calling anyone. For a vendor whose product is the call, that is a feature that removes the product.
Self-exclusion integrity: the protection enforced by matching details the excluded person knows
Self-exclusion is the strongest protection a person can invoke for themselves. It is enforced by matching names, dates of birth and addresses that the excluded person can
Why phishing proxies fail against passkeys, and where they still win
Reverse-proxy phishing kits relay credentials and session cookies transparently. Against a properly bound WebAuthn ceremony they break — for a reason worth understanding
Verifying the payee and proving what the payer saw are different jobs
Account verification confirms that a bank account belongs to who it claims to. It does not establish which instructions the person sending money was looking at.
Revocation without a network call at verification time
Online status checking leaks what you are verifying, adds latency, and fails open when the responder is down. A signed, cacheable list has none of those properties.
Financing agent risk through a captive when the market will not write it
Commercial insurers price unbounded autonomous-system liability out of reach or decline it. Large enterprises respond by retaining the risk, which makes the loss control
The QP certification nobody can verify: batch release across the EU supply chain
A Qualified Person accepts personal legal liability for certifying each batch for EU release. The artefact carrying that certification is a PDF or a register entry inside
Selling the number as a trust signal: what carriers could offer banks instead of SMS
Carriers hold the strongest real-world identity relationship in consumer telecom and monetise it as message delivery. The delivery product is being deprecated precisely b
A control that needs the internet is a control that has outages
If verifying an approval requires calling a vendor, then the vendor's availability, your network and their retention policy are all part of your control.
The independent double-check that isn't: making bedside verification cryptographically independent
The independent double-check is the last barrier before a high-alert medication reaches a patient. Digitised into two badge scans on one workstation, its independence is
Client intake as an AML control: verifying the human behind the engagement letter
Engagement letters are signed electronically by whoever holds the email address. For matters involving funds movement or entity formation, the firm's record of who i
Transfer agent record changes: the share register's weakest field
Changing a registered holder's address or payment destination redirects dividends and eventually enables position transfer. The controls are a form, sometimes a meda
Admissions documents from anywhere: verifying credentials you cannot phone
Admissions offices evaluate documents from thousands of institutions worldwide. Verification by correspondence is slow, unreliable, and easily spoofed by fraudulent inter
FERPA disclosure authorization: the consent record that cannot be tested
FERPA generally requires written consent specifying the records, purpose and recipient. In practice consent is a scanned form or a portal toggle, and a disputed disclosur