August 2026 Summaries
9 posts from Duality
Filter
Month:
Year:
Post Summaries
Back to Blog
Responsible AI is presented as an operational approach to designing, deploying, and monitoring AI systems that incorporates fairness, transparency, accountability, privacy, safety, explainability, and human oversight throughout the AI lifecycle, particularly in high-stakes sectors such as healthcare, finance, and government. The discussion emphasizes that failures in these areas can lead to biased decisions, privacy violations, legal exposure, regulatory penalties, and loss of public trust, while frameworks including the NIST AI Risk Management Framework, the EU AI Act, GDPR, and ISO/IEC 42001 provide overlapping guidance or requirements for governance and risk management. Because sensitive data is essential but difficult to share safely, regulated organizations are encouraged to use controls such as data minimization, role-based access, bias monitoring, audit logs, encryption, and human review. It also highlights privacy-enhancing technologies, including federated learning, fully homomorphic encryption, and confidential computing, as methods for training or operating AI on protected data without centralizing or exposing raw records, and promotes Duality Technologies as a provider of tools implementing these approaches.
Aug 26, 2026
3,333 words in the original blog post.
IBM Sovereign Core and Duality Technologies are positioned as a combined approach for developing sovereign AI systems that can analyze sensitive, distributed data without centralizing or exposing it. IBM Sovereign Core provides customer-operated controls for identity, access, keys, logging, compliance evidence, and governance within a sovereign boundary, while Duality uses privacy-enhancing technologies to support protected analytics and AI collaboration across organizations, jurisdictions, and cloud environments. The approach is intended for sectors such as government, defense, healthcare, finance, and research, where data-sharing restrictions can limit collaborative work on issues including intelligence, fraud, and medical research. Proposed uses include federated workloads across agencies and sovereign clouds, secure access to public cloud computing capacity, and confidential queries against external data providers. The companies argue that this model enables organizations to retain data custody, enforce consistent policies, protect sensitive queries and outputs, and generate shared insights without creating centralized copies of protected information.
Aug 20, 2026
1,100 words in the original blog post.
GDPR generally treats any access to or movement of EEA personal data from outside the EEA as a cross-border transfer, including remote support access, foreign cloud storage, and analytics workflows, and permits it only through an adequacy decision, appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules, or limited Article 49 derogations. Following the Schrems II ruling, organizations using contractual mechanisms must also conduct transfer impact assessments and implement supplementary protections where foreign laws could undermine equivalent EU-level protection, with violations potentially resulting in substantial penalties such as the Dutch authority’s €290 million fine against Uber. The EU-US Data Privacy Framework remains a valid basis for transfers to certified US organizations in 2026, but its long-term stability is uncertain because it faces further legal review and follows two invalidated predecessor arrangements. Highly regulated sectors including healthcare, finance, and government face additional sensitivity, sovereignty, and security concerns, increasing the importance of controls such as encryption with EEA-controlled keys, pseudonymization, anonymization, and differential privacy. The text also highlights privacy-enhancing technologies, including federated learning, secure multi-party computation, confidential computing, and fully homomorphic encryption, as methods for enabling cross-border analysis while limiting exposure of readable personal data, and recommends that organizations map all external access paths, maintain legal transfer bases, and design systems resilient to changing legal frameworks.
Aug 20, 2026
2,844 words in the original blog post.
Protecting personally identifiable information in regulated industries requires layered controls such as encryption at rest and in transit, role-based access, data minimization, monitoring, and employee training, but these measures often leave data vulnerable while it is actively processed for analytics, applications, partner collaboration, or AI. GDPR, HIPAA, and CCPA impose differing obligations and penalties, with organizations frequently falling short through inadequate risk assessments, unclear legal bases, weak opt-out processes, and insufficient documentation. The discussion emphasizes privacy-enhancing technologies, including fully homomorphic encryption, secure multi-party computation, federated learning, and trusted execution environments, as methods for analyzing or training models on sensitive data without exposing raw records. It also identifies AI and unsanctioned “shadow AI” use as growing PII risks and recommends measures such as input redaction, AI-specific governance, access controls, privacy-preserving inference, and federated fine-tuning. For cross-organizational data use, the text advocates keeping information with its original owner while enabling encrypted or distributed computation, presenting Duality Technologies’ platform as one implementation of these approaches.
Aug 14, 2026
2,900 words in the original blog post.
Privacy-Enhancing Technologies (PETs), traditionally associated with protecting personal data, are increasingly being framed as tools for digital sovereignty because they can help individuals, enterprises, and nations retain control over sensitive assets while using infrastructure they do not own. As organizations rely more heavily on public clouds, SaaS platforms, external AI models, global providers, and cross-border collaboration, sovereignty concerns now extend beyond data location to include control of models, intellectual property, cryptographic keys, policies, and workload access. The text argues that cryptographic protections such as confidential computing and fully homomorphic encryption can shift control from infrastructure owners to the workloads themselves, allowing organizations to use external compute and AI capabilities without granting providers access to sensitive data or models. This approach, described as “sovereignty without isolation,” treats sovereignty as a manageable spectrum rather than an absolute goal and proposes the broader term Sovereignty-Enabling Technologies (SETs) to reflect these technologies’ role in supporting control, resilience, and operational flexibility across interconnected digital ecosystems.
Aug 11, 2026
1,561 words in the original blog post.
Zero trust data security replaces perimeter-based defenses with continuous authentication, authorization, least-privilege access, segmentation, encryption, and monitoring across five CISA pillars: identity, devices, networks, applications and workloads, and data, supported by analytics, automation, and governance. It is particularly relevant to healthcare, financial services, and government organizations, where stolen credentials, regulatory obligations, and sensitive data-sharing needs make traditional network trust inadequate. While zero trust can protect data at rest and in transit and limit lateral movement after a breach, the text argues that it leaves a significant gap when data must be decrypted for processing, especially in collaboration between organizations that cannot fully trust one another. Privacy-enhancing technologies such as fully homomorphic encryption, trusted execution environments, secure multi-party computation, federated learning, and differential privacy are presented as complementary tools that can protect data during use, although they differ in performance, trust assumptions, and suitable workloads. The text positions Duality’s platform as one approach for combining these technologies with governance and auditability to enable secure cross-organizational analytics and AI without exposing raw data.
Aug 11, 2026
4,258 words in the original blog post.
Data security protects information against unauthorized access, alteration, loss, and theft through measures such as encryption, authentication, access controls, monitoring, and incident response, while data privacy governs whether personal data may be collected, used, retained, shared, or transferred under lawful and clearly defined purposes. The distinction is central to GDPR, which addresses security primarily through Article 32 and privacy through Articles 5 and 25, requiring lawful processing, data minimization, purpose limitation, and privacy by design in addition to risk-appropriate safeguards. An organization can therefore maintain strong technical protections yet still violate privacy rules by collecting data without a lawful basis, retaining it too long, or using it beyond the agreed purpose. Regulated sectors such as healthcare, financial services, and government commonly manage security and privacy through separate but coordinated controls, owners, and compliance frameworks. The discussion also highlights privacy-enhancing technologies—including confidential computing, federated learning, secure multi-party computation, and fully homomorphic encryption—as approaches intended to enable analytics and AI collaboration while reducing exposure of sensitive data during processing.
Aug 11, 2026
3,149 words in the original blog post.
Data localization refers to legal requirements that certain data be stored, and sometimes processed, within a country’s borders, driven by privacy, security, law-enforcement access, digital sovereignty, and economic policy goals. It differs from data residency, which is a voluntary choice about physical storage location, and data sovereignty, which concerns the laws governing data regardless of location. Restrictions have expanded globally, with Russia, China, and India among the countries enforcing particularly strict rules, while many others apply sector-specific mandates to payment, health, telecom, or government data. GDPR does not require EU data to remain in Europe but instead regulates international transfers through adequacy decisions and safeguards. The discussion argues that building separate local infrastructure for every jurisdiction can create costly data silos that limit analytics, fraud detection, research, and AI development. It presents compute-to-data approaches and privacy-enhancing technologies, including federated learning, homomorphic encryption, secure multi-party computation, and confidential computing, as ways to keep raw data in required locations while allowing protected insights or model updates to be shared. As localization rules are expected to extend further into AI training and governance, organizations are encouraged to design systems in which sensitive data remains local while authorized, non-identifying outputs can move across borders.
Aug 10, 2026
2,953 words in the original blog post.
Sovereign cloud is presented as a model that aims to keep data, infrastructure, and operations under the exclusive legal and operational control of one jurisdiction, distinguishing it from simple data residency, which only determines where servers are located. The discussion argues that many offerings remain vulnerable to foreign legal demands because laws such as the US CLOUD Act can compel US-controlled providers to disclose data held abroad, while European initiatives and locally controlled subsidiaries seek to reduce this exposure without necessarily eliminating it. It identifies data residency, locally controlled operations, and technical sovereignty as three required layers, with the last relying on customer-held encryption keys and privacy-enhancing technologies to prevent providers from accessing readable data even during computation. Technologies including confidential computing, fully homomorphic encryption, and secure multi-party computation are described as ways to enable protected cloud processing and cross-border collaboration. Organizations with especially sensitive government, defense, health, or critical-infrastructure workloads may build their own sovereign clouds, although this entails substantial cost and operational tradeoffs; other organizations are encouraged to assess providers’ jurisdictional exposure, access to plaintext, key control, operational independence, and audit evidence.
Aug 10, 2026
2,804 words in the original blog post.