<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Core Purpose Tech Insights</title>
    <link>https://www.corepurpose.tech/insights</link>
    <atom:link href="https://www.corepurpose.tech/insights/rss.xml" rel="self" type="application/rss+xml" />
    <description>Insights on operational AI, systems architecture, integration, and platform engineering for regulated organizations in Denmark and the EU.</description>
    <language>en</language>
    <lastBuildDate>Fri, 07 Aug 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>What the Open Knowledge Format does</title>
      <link>https://www.corepurpose.tech/insights/what-the-open-knowledge-format-does</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/what-the-open-knowledge-format-does</guid>
      <description>A directory of markdown files with YAML frontmatter, published by Google Cloud as an open specification. What OKF requires, what its trust fields record, and which of your problems it leaves untouched.</description>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>Open Knowledge Format</category>
      <category>OKF specification</category>
      <category>Google OKF markdown AI agents</category>
      <category>agent knowledge base format</category>
      <category>OKF vs MCP</category>
    </item>
    <item>
      <title>WebMCP and the dual-mode website: what leadership actually decides</title>
      <link>https://www.corepurpose.tech/insights/webmcp-and-the-dual-mode-website</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/webmcp-and-the-dual-mode-website</guid>
      <description>There is a widely held expectation that web pages end up as a prompt box. WebMCP is the more modest version of that future: the application stays visible, and a prompt is added as a second way to operate it. Two things have to exist for that to work. Only one of them is yours to build, and whether you build the second one as well is the decision about who controls the agent.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>WebMCP</category>
      <category>AI agent on a website</category>
      <category>prompt-driven website</category>
      <category>embedded copilot</category>
      <category>agent-ready web application</category>
    </item>
    <item>
      <title>Forms an agent can fill: what WebMCP changes</title>
      <link>https://www.corepurpose.tech/insights/webmcp-forms-an-agent-can-fill</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/webmcp-forms-an-agent-can-fill</guid>
      <description>An agent filling a form today reads the rendered page and infers. WebMCP lets the page declare the same capability as a named tool with a schema. Two attributes on the form, one per field, and no script. The demonstration below runs in this article.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>WebMCP</category>
      <category>agent-ready forms</category>
      <category>AI agent filling web forms</category>
      <category>declarative WebMCP API</category>
      <category>autocomplete attribute autofill</category>
    </item>
    <item>
      <title>WebMCP security: the backend does not change, but intent does</title>
      <link>https://www.corepurpose.tech/insights/webmcp-security-backend-does-not-change</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/webmcp-security-backend-does-not-change</guid>
      <description>A form completed through WebMCP should run the same authentication, authorization and business rules as one filled in by hand. The security question WebMCP actually raises is not whether the backend needs to change. It is whether the action a valid, authorized agent just took is the action the user meant.</description>
      <pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>WebMCP security</category>
      <category>AI agent authorization</category>
      <category>prompt injection WebMCP</category>
      <category>agent intent versus authorization</category>
      <category>WebMCP audit logging</category>
    </item>
    <item>
      <title>What an AI gateway does, and when you need one</title>
      <link>https://www.corepurpose.tech/insights/what-an-ai-gateway-does</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/what-an-ai-gateway-does</guid>
      <description>One internal interface between your applications and whichever model serves them. What belongs in that layer, and the point at which not having one starts to cost you.</description>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>what is an AI gateway</category>
      <category>LLM gateway</category>
      <category>AI gateway vs API gateway</category>
      <category>LLM routing and cost control</category>
      <category>enterprise LLM governance</category>
    </item>
    <item>
      <title>The AI code trust gap: adoption is settled, ownership is not</title>
      <link>https://www.corepurpose.tech/insights/ai-generated-code-trust-gap</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/ai-generated-code-trust-gap</guid>
      <description>Around 90% of developers use AI daily, more distrust its accuracy than trust it, and its security pass rate has not moved in a year. Read together, the 2025-2026 evidence says the constraint has shifted from writing software to owning it, and that is a specification and accountability problem rather than a tooling one.</description>
      <pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>AI generated code trust</category>
      <category>AI code security evidence</category>
      <category>AI adoption trust gap</category>
      <category>AI prototype to production</category>
      <category>spec-driven development</category>
      <category>AI code review</category>
      <category>software ownership AI</category>
    </item>
    <item>
      <title>The EU AI Act: what it asks of deployers</title>
      <link>https://www.corepurpose.tech/insights/ai-act-deployer-obligations</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/ai-act-deployer-obligations</guid>
      <description>Most organizations buying or building on AI are deployers rather than providers. That distinction decides which obligations land on you, and most of them are architectural.</description>
      <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>EU AI Act deployer obligations</category>
      <category>AI Act requirements for companies</category>
      <category>deployer vs provider AI Act</category>
      <category>high-risk AI system obligations</category>
      <category>EU AI Act compliance for businesses</category>
    </item>
    <item>
      <title>On-premises vs hosted LLM: how to choose</title>
      <link>https://www.corepurpose.tech/insights/on-premises-vs-hosted-llm</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/on-premises-vs-hosted-llm</guid>
      <description>The choice is usually settled by data residency and contracts, not by cost or model quality. Here is what each option costs you in practice.</description>
      <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>on-premises vs hosted LLM</category>
      <category>self-hosted LLM vs API</category>
      <category>when to self-host an LLM</category>
      <category>LLM data residency requirements</category>
      <category>enterprise LLM deployment options</category>
    </item>
    <item>
      <title>What sovereign AI actually means</title>
      <link>https://www.corepurpose.tech/insights/what-sovereign-ai-means</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/what-sovereign-ai-means</guid>
      <description>The term covers four separable properties, and vendors tend to sell the cheapest one. Which of them you actually need depends on what you are protecting against.</description>
      <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>what is sovereign AI</category>
      <category>sovereign AI definition</category>
      <category>data residency vs data sovereignty</category>
      <category>EU cloud sovereignty</category>
      <category>digital sovereignty and AI</category>
    </item>
    <item>
      <title>AI-assisted implementation with frontier models</title>
      <link>https://www.corepurpose.tech/insights/ai-assisted-implementation-frontier-models</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/ai-assisted-implementation-frontier-models</guid>
      <description>Frontier models can accelerate implementation, but only when they are used inside a disciplined delivery method: clear architecture, review, testing, security, and production ownership.</description>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>AI-assisted software development</category>
      <category>frontier models for coding</category>
      <category>AI generated code in production</category>
      <category>LLM assisted software engineering</category>
      <category>AI coding tools for enterprise teams</category>
    </item>
    <item>
      <title>How to turn a business-built AI prototype into production software</title>
      <link>https://www.corepurpose.tech/insights/business-led-prototypes-implementation</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/business-led-prototypes-implementation</guid>
      <description>A business-built prototype proves intent and interaction. It does not prove architecture, security, data integrity or operational readiness. Treat it as an executable specification: preserve intent by default, and preserve generated code only where evidence justifies it.</description>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>vibe coding to production</category>
      <category>AI prototype to production</category>
      <category>prototype to production software</category>
      <category>business-led prototyping</category>
      <category>AI-assisted prototyping</category>
      <category>production-ready software</category>
      <category>spec-driven development</category>
      <category>business prototype implementation</category>
      <category>citizen developer governance</category>
    </item>
    <item>
      <title>Why AI pilots stall before production</title>
      <link>https://www.corepurpose.tech/insights/operational-ai-vs-pilots</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/operational-ai-vs-pilots</guid>
      <description>A working demo is not a working system. The difference between AI that ships and AI that stalls is operational integration, not model quality.</description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>why AI pilots fail</category>
      <category>AI pilot to production</category>
      <category>moving AI from pilot to operations</category>
      <category>enterprise AI adoption barriers</category>
      <category>operational AI in production</category>
    </item>
    <item>
      <title>Sovereign AI in regulated EU enterprises</title>
      <link>https://www.corepurpose.tech/insights/sovereign-ai-regulated-eu</link>
      <guid isPermaLink="true">https://www.corepurpose.tech/insights/sovereign-ai-regulated-eu</guid>
      <description>Data residency and modern AI are not mutually exclusive. A governed model gateway and on-premises deployment let regulated organizations use AI on their terms.</description>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
      <author>Jens Østergaard</author>
      <category>sovereign AI implementation</category>
      <category>AI sovereignty for EU enterprises</category>
      <category>GDPR compliant LLM deployment</category>
      <category>AI in regulated industries EU</category>
      <category>sovereign AI Denmark</category>
    </item>
  </channel>
</rss>
