The Illusion of Control: What the Second Line Gets Wrong—and What Regulators and Failures Reveal

By Jeremy Swenson

Thirty-one. That is how many unaddressed safety-and-soundness supervisory warnings Silicon Valley Bank was sitting on when it collapsed in March 2023—roughly triple the number carried by comparable banks. The warnings existed. Examiners had written them down. Committees had reviewed them. And the bank failed anyway, in 36 hours, taking $209 billion in assets down with it.[1]

This figure isn’t really just about Silicon Valley Bank; it’s a broader story about how governance can falter right when it was meant to prevent failure. Across modern sectors like finance, healthcare, insurance, and tech—especially under heavy regulation—the structure is quite similar: a First Line managing risks, a Third Line (Internal Audit) independently evaluating effectiveness, and a Second Line acting as an oversight layer to challenge and ensure risk remains within boundaries before issues arise.

The uncomfortable pattern across nearly every major governance failure of the last fifteen years is not that the second line was absent. It was there, busy, and documented—and it still didn’t work.

That is the uncomfortable pattern across nearly every major governance failure of the last fifteen years: the second line of defense (2LOD) was rarely absent. It was there, it was busy, and it was thoroughly documented. JPMorgan’s Chief Investment Office had risk managers. Credit Suisse’s Prime Services division had a dedicated risk team. Wells Fargo had a corporate risk function, a legal department, and an audit group that all reviewed the Community Bank. Danske Bank’s Estonian branch had internal audit and a chief risk officer. In each case, the paperwork existed. The risk did not go away.

This raises the question at the center of this piece, and one that boards, regulators, and chief risk officers are increasingly asking out loud: is the modern second line of defense actually reducing risk—or is it primarily producing evidence that governance activities occurred? The two are not the same thing, and the gap between them is where some of the costliest failures in recent corporate history have lived.

What the Second Line Is Supposed to Do

The three-lines model that underpins risk governance at virtually every large regulated institution was formalized by the Institute of Internal Auditors in 2013 and substantially updated in 2020. The first line is operational management—the traders, lenders, engineers, and business unit leaders who own risk because they create it in the course of doing their jobs. The third line is internal audit, an independent function that reports to the board and periodically tests whether the first two lines are actually working. The second line sits in the middle: risk management, compliance, information security, and similar functions that provide, in the Institute’s own language, “complementary expertise, support, monitoring, and challenge” to the business.[2]

In U.S. banking specifically, this structure is not just best practice—it is regulatory expectation with teeth. The Office of the Comptroller of the Currency’s (OCC) 2014 heightened standards for large national banks explicitly require an independent risk management function, organizationally and financially separate from the business lines it oversees. The Federal Reserve’s 2011 guidance on model risk management, SR 11-7, assigns the second line an independent validation role specifically because business lines have an inherent incentive to trust their own models.[3]

Notably, when the Institute of Internal Auditors rewrote its guidance in 2020, it deliberately dropped the word “defense” from the model’s name, worried that the martial framing had encouraged organizations to treat risk management as purely defensive—blocking and reviewing—rather than as a function that helps an organization take the right risks well. That single word change is a useful preview of this piece’s argument: a second line built entirely around defense metrics—how many reviews were completed, how many policies exist, how many attestations were signed—can satisfy every requirement on paper while missing the actual point.[4]

Where the Model Breaks Down

Strip away the acronyms, and the recurring failure modes of the second line reduce to a short, uncomfortable list. Each one, on its own, sounds like a minor process gap. Together, and when combined with real money and real institutions, they have produced some of the largest corporate governance failures on record.

Documentation Instead of Risk Reduction

The clearest symptom is a second line that measures itself by volume: reviews completed, policies published, attestations collected, meetings held. Every one of those activities can be running at full capacity while the underlying risk grows untouched, because none of them require anyone to verify that a control actually works—only that someone said it does.

Self-Attestation Over Independent Verification

Much of traditional second-line practice depends on the first line telling the second line the truth: attestations, self-assessments, and point-in-time control tests that sample a narrow window and assume it represents the whole. When Danske Bank’s Estonian branch was later examined, the bank’s own lawyers conceded that “major deficiencies in controls and governance made it possible to use Danske Bank’s branch in Estonia for criminal activities such as money laundering,” and that internal reporting simply never reached the people positioned to stop it.[5]

Individual Exceptions Over Systemic Patterns

Second lines are often organized to catch one broken control at a time—a missed reconciliation, a late report, an expired certificate—rather than to notice that dozens of small, individually explainable exceptions are actually one large, systemic problem wearing different clothes.

Compliance Treated as a Proxy for Safety

Perhaps the most persistent conflation in second-line practice is the assumption that a control environment which satisfies a regulation is therefore a control environment that manages the underlying risk. The two frequently travel together. They are not the same claim, and treating them as interchangeable is exactly how organizations end up technically compliant and substantively exposed at once.

A Challenge Function That Doesn’t Actually Challenge

Effective second-line challenge requires two things that are hard to combine: enough independence to say no to a profitable business line, and enough technical and commercial fluency to know when “no” is actually warranted. Many second lines have one without the other—independent enough to be disliked, but not fluent enough in the actual business to be heeded, or so embedded in the business that independence quietly erodes.

Struggling to Govern What It Doesn’t Understand

Every one of the weaknesses above compounds sharply the moment the underlying risk is technical: artificial intelligence models, cloud migrations, third-party data pipelines, or novel cyber threats. A second line built to review loan files and sales scripts is not automatically equipped to evaluate a machine learning model’s training data lineage or a cloud vendor’s shared-responsibility boundary—and regulators are now saying so explicitly. NIST’s AI Risk Management Framework (RMF) and the broader push toward AI-specific governance exist precisely because traditional control catalogs were not written with adaptive, probabilistic systems in mind.[6]

Five Failures, One Pattern

These are not abstractions. They are the documented findings of regulators, board-appointed investigators, and congressional committees—and read together, they describe the same failure recurring in different industries, different countries, and different decades.

1. JPMorgan’s “London Whale” (2012)—When Risk Managers Don’t Know What the Business Is Doing

In 2012, JPMorgan Chase’s Chief Investment Office lost more than $6.2 billion on a series of synthetic credit derivative trades that came to be known as the “London Whale.” The U.S. Senate Permanent Subcommittee on Investigations spent nine months and reviewed more than 90,000 documents before concluding that the unit had mismarked its trading book to hide losses, disregarded multiple indicators of increasing risk, manipulated its own risk models, and evaded regulatory oversight.[7]

The Subcommittee’s report found that JPMorgan’s firm-wide risk managers—the second line—“knew little about” the trading strategy and had no role in approving the positions that produced the loss, even as the bank’s own public statements insisted the trades were consistent with firm-wide risk management. This was a second line that existed on the org chart and was functionally absent from the transaction that mattered most.[8]

2. Wells Fargo’s Sales Practices Scandal (2011–2016)—When Egos and Tenure Silence the Second Line

Between 2011 and 2016, Wells Fargo employees opened millions of unauthorized accounts to meet aggressive sales quotas, ultimately leading to the termination of roughly 5,300 employees and $185 million in regulatory penalties. When the bank’s independent directors released their own 110-page investigation in 2017, the findings went well beyond a rogue sales culture.[9]

The report found that Carrie Tolstedt, the long-tenured head of the Community Bank, and other Community Bank leaders “resisted and impeded scrutiny or oversight from corporate risk management and the Board,” and “minimized the scale and nature of problems” when they were forced to report them. Then-CEO John Stumpf, the report found, relied on “the Bank’s decades of success” and was “too slow to investigate or critically challenge” the sales model—a textbook description of tenure-driven bias, where years of past success become evidence against present-day concerns rather than a reason to look harder.[10]

Just as tellingly, the report found that Wells Fargo’s control functions were structurally weakened by internal politics: risk, legal, HR, and audit were “decentralized” and had “parallel units” embedded inside the Community Bank itself, reporting up through business-aligned structures that deferred to the business rather than challenging it. Audit reviewed the relevant controls and largely found them effective—but, the report notes pointedly, “it did not view its role to include analyzing more broadly the root cause of the improper conduct.” That is the governance-activity trap in a single sentence: the review happened, the box was checked, and the actual problem sailed through untouched.[11]

3. Credit Suisse and Archegos (2021)—When the Second Line Is Afraid to Say No

In March 2021, the collapse of Archegos Capital Management, a lightly regulated family office, cost Credit Suisse $5.5 billion—more than any other bank exposed to the same client. The board-commissioned investigation by Paul, Weiss found no fraud and no missing risk architecture. The controls existed. What failed was the willingness to use them.[12]

The investigation found a “persistent failure” to manage and remediate known risks connected to Archegos, and, more specifically, that Credit Suisse’s risk managers had intended to demand additional margin from Archegos to reflect its mounting credit risk—but were prevented from doing so because the business “deemed” it not to be in the bank’s commercial interest to upset the relationship. One outside review summarized the underlying dynamic bluntly: this was “a business more scared of losing a client than addressing the risks that client was bringing to the bank.” The report also found the Prime Services risk team itself was understaffed, had failed to replace departing senior risk staff, and lacked leadership experience—the second line, quite literally, hollowed out from within.[13]

4. Danske Bank Estonia (2007–2018)—When the Second Line Covers Its Own Mistakes

Danske Bank’s Estonian branch moved an estimated $230 billion in suspicious transactions, much of it linked to Russia, between 2007 and 2015—one of the largest money-laundering cases in European history. It might never have come to light if not for Howard Wilkinson, a British trader who filed four internal whistleblower reports to the bank’s audit unit and Copenhagen management between 2013 and 2014.[14]

Wilkinson later testified before the Danish and European Parliaments that the bank had “deliberately ignored” his warnings and that an Estonia branch executive told him the bank was “not the police.” An internal Danske audit team eventually validated the substance of his concerns, yet the bank still failed to take meaningful action until the money-laundering scandal became public in 2018—four years later. As Wilkinson departed the bank, he was reportedly presented with a nondisclosure agreement. This is the sharpest version of the pattern this piece was asked to examine directly: not a second line that failed to notice a problem, but one that noticed, confirmed it internally, and chose containment over correction—protecting the institution’s narrative rather than fixing the underlying failure.[15]

5. Silicon Valley Bank (2023)—When Periodic Reviews Can’t Keep Up With Real-Time Risk

SVB failed in 36 hours following a bank run, but the vulnerabilities behind it built for years. The Federal Reserve’s own review, led by Vice Chair for Supervision Michael Barr, is remarkable for how directly a regulator indicted its own supervisory process: SVB’s board and management “failed to manage their risks,” Federal Reserve supervisors “did not fully appreciate the extent of the vulnerabilities” as the bank grew, and—critically—even when supervisors did identify problems, they “did not take sufficient steps to ensure that Silicon Valley Bank fixed those problems quickly enough.”[16]

The report also found that SVB itself had changed its own risk-management assumptions specifically to reduce how its interest rate risk was measured, rather than managing the underlying exposure—a second-line control quietly redefined until it stopped producing uncomfortable answers. Barr’s report is also a rare admission that periodic, point-in-time supervisory cycles are structurally too slow for a risk that can move at deposit-run speed; a regulator reaching the same conclusion this piece reaches about the second line more broadly.[17]

What Regulators Learned—And Where Their Own Findings Converge

The most useful evidence that this is a systemic problem, not a string of unrelated scandals, comes from the regulators themselves. On April 28, 2023, the Federal Reserve and the Federal Deposit Insurance Corporation (FDIC) each released their own self-critical report on the same weekend of bank failures—an unusually candid coincidence that let the two reports be read side by side.

The Fed’s report on SVB, discussed above, found that supervisors identified real vulnerabilities but did not escalate forcefully enough once they had. The FDIC’s own report on Signature Bank reached a strikingly similar structural conclusion through a completely separate investigation: the bank’s failure was rooted in poor management, but the report also found that FDIC examiners had downgraded Signature’s liquidity rating as early as 2017 while its overall composite rating stayed at a healthy “2-Satisfactory” for six more years—a gap between what examiners were seeing and what the supervisory rating actually communicated.[18]

The U.S. Government Accountability Office (GAO) took a further step by reviewing both agencies together rather than separately. It concluded that this supports the main argument of this piece concerning federal banking regulation: the Federal Reserve and FDIC “identified numerous concerns at the banks as early as 2018, but did not issue enforcement actions.” Additionally, the GAO pointed out that the Federal Reserve’s “procedures for moving from a lower-level concern to an enforcement action often weren’t clear or specific.” This indicates that a regulator, assessing itself, independently recognizes the same core idea discussed here: identifying a risk is not the same as forcing a change. An institution can recognize risks on a large scale for years without reliably enforcing change.[19]

Read together with the NIST AI Risk Management Framework’s push for governance built around measurable, continuous risk assessment rather than static control catalogs, and the IIA’s 2020 shift away from purely defensive framing, a consistent regulatory direction emerges across otherwise unrelated bodies: less faith in point-in-time review, more emphasis on forcing identified risk into actual remediation, and explicit skepticism that documentation volume is a reliable proxy for safety. None of these bodies coordinated with each other. They arrived at overlapping conclusions anyway, because they were all looking at the same underlying failure pattern from different angles.[20],[21]

Figure 1. Most second-line functions do not lack activity—they sit in the high-activity, low-reduction quadrant, producing evidence of governance without changing risk outcomes.

The 2LOD governance trap and its four related boxes.

The Part Nobody Puts in the Org Chart: Tenure, Ego, and Internal Turf Wars

Every case above shares a dynamic that rarely appears in a governance framework diagram but shows up in nearly every post-mortem: the people closest to a mistake are often the ones best positioned to prevent its discovery, and organizational tenure tends to make that worse rather than better.

Long-tenured leaders accumulate something more dangerous than complacency—they accumulate authorship. A risk model, a sales program, a client relationship built over a decade is not just a business asset to the person who built it; it is proof of their own judgment. Wells Fargo’s Board Report describes exactly this pattern in Carrie Tolstedt, who had run the Community Bank for years and treated challenges to the sales model as challenges to her track record, not as useful information. John Stumpf’s decades at the company produced the same effect at the top: reliance on “decades of success” became a reason to discount new evidence rather than investigate it.[22]

Ego compounds this in a specific and predictable way inside the second line itself: once a risk function has signed off on something—approved a model, cleared a client, blessed a control—reversing that judgment later means admitting the earlier review was wrong. The Credit Suisse-Archegos investigation found that risk staff who wanted to tighten margin requirements were overruled by colleagues managing the client relationship, who prioritized the commercial relationship over the escalation. That is not a hypothetical about incentives; it is a documented instance of one part of the organization protecting a prior decision instead of correcting course.[23]

The most direct evidence of internal fighting to cover mistakes is Danske Bank. Wilkinson’s own account describes a bank that did not simply fail to notice a problem—it received internal confirmation that the problem was real, from its own audit function, and chose a non-disclosure agreement and years of silence over disclosure and remediation. That is not a control gap. It is a second line, or the executives who supervise it, actively managing the appearance of the problem rather than the problem itself—the containment instinct that shows up whenever an admission of error threatens a career, a bonus cycle, or a carefully maintained reputation.[24]

A second line that cannot survive telling the truth about its own prior mistakes will eventually stop looking for them.

None of this requires malice to be dangerous. Most of the people in these stories were not villains; they were professionals whose incentives, tenure, and self-image quietly bent the direction of ambiguous judgment calls toward “this is probably fine.” A modern second line has to be designed with the explicit assumption that this bending will happen—through rotation of long-tenured reviewers, external validation of internally cleared decisions, and protected channels for escalation that do not depend on the goodwill of the person whose earlier judgment is being questioned.

Governance Activity Is Not the Same as Risk Reduction

Every case study mentioned earlier successfully passed a compliance test before turning into a scandal. This is the key point repeatedly emphasized here: governance that merely shows evidence of compliance is different from governance that genuinely reduces risk. An organization can generate a lot of documentation proving compliance but still fall short in actually altering risk outcomes.

Evidence-of-compliance governance is legible, defensible in an exam, and relatively cheap to produce: a signed attestation, a completed checklist, a policy that has been “reviewed and approved.” Outcome-based governance is harder and more expensive: independently tested controls, risk metrics tied to actual loss experience, escalation paths that get used even when the news is bad. The first kind of governance protects the organization in an audit. The second kind protects the organization in a crisis. Wells Fargo, Credit Suisse, and Danske Bank all had abundant supplies of the first and a critical shortage of the second.

Figure 2. Modernizing the second line means shifting the underlying operating model, not just increasing the volume of existing activity.

Two columns showing the legacy model of checkbox compliance and the new model of continuous risk governance.

What a Modern Second Line Actually Looks Like

None of this argues for a weaker second line—every case study here shows the cost of that. It argues for a fundamentally different operating model, one that a growing body of regulatory guidance and industry practice is already pointing toward.

Risk-Based, Not Checklist-Based

Oversight intensity should scale with actual risk and complexity, not with how many items happen to be on a standard control list. A stable, well-understood process and a novel AI model deployed into a regulated decision workflow should never receive the same depth of review simply because both appear as line items on the same checklist.

Continuous Monitoring, Not Periodic Snapshots

The Barr report on SVB is itself an argument for this shift: point-in-time exams cannot keep pace with risks—interest rate exposure, deposit concentration, model drift—that can move materially between review cycles. Where technology allows it, continuous, automated monitoring should replace calendar-driven review as the default, with periodic deep-dives reserved for the risks continuous monitoring cannot yet see.

Evidence Over Attestation

Self-reported control effectiveness should be treated as a starting hypothesis, not a conclusion. Independent data validation—sampling actual transactions, actual model outputs, actual system logs—is more expensive than collecting a signature, and it is the only version of assurance that would have caught what self-attestation missed at Danske Bank.

Genuine Business and Technology Fluency

A second line cannot challenge what it does not understand. This means recruiting and developing risk professionals with real technical depth—in derivatives, in cloud architecture, in machine learning—rather than treating the second line as a generalist compliance career track. JPMorgan’s risk managers not knowing what the CIO’s synthetic credit portfolio actually did is the clearest cautionary tale on this point.

Escalation That Survives Internal Politics

Escalation paths need to be structurally protected from the relationship dynamics that killed escalation at Credit Suisse and Danske Bank—which means routing serious concerns to a level of the organization with no commercial stake in the outcome, and protecting the people who raise them, not just on paper but in how the organization actually treats them afterward.

Outcome-Based Metrics

A second line’s effectiveness should be measured by risk events avoided, losses prevented, and issues resolved before they compound—not by the number of reviews completed, policies published, or meetings held. Volume metrics are easy to game and easy to satisfy without changing anything; outcome metrics are harder to fake.

Real Oversight of AI, Cloud, and Third Parties

Emerging-technology governance needs its own competency track within the second line, built around frameworks purpose-designed for these risks—NIST’s AI Risk Management Framework, cloud shared-responsibility models, and structured third-party risk programs—rather than an attempt to stretch legacy control catalogs over technology they were never built to evaluate.[25]

Clear Accountability Between the First and Second Lines

Wells Fargo’s decentralized risk structure, with control functions embedded inside and reporting up through the business they were meant to oversee, shows what happens when the line between “owns the risk” and “challenges the risk” blurs. Modern governance requires those roles to remain organizationally and, where possible, financially distinct—precisely what the OCC’s heightened standards were written to enforce.[26]

Constructive Challenge, Not a Permanent Bottleneck

None of the above is a case for more friction everywhere. A second line that slows every decision equally will be resented, routed around, and eventually ignored—which is its own form of failure. The goal is targeted friction: fast, low-touch review for well-understood, lower-risk activity, and genuinely rigorous, well-resourced challenge concentrated on the decisions that could actually sink the institution.

Conclusion: Measuring the Right Thing

Return to Silicon Valley Bank’s 31 unaddressed supervisory warnings. Every one of them was, in a narrow sense, evidence that governance was happening: someone had identified a risk, written it down, and tracked it. And every one of them failed to change what actually happened to the bank. That is the second line’s central modern challenge, in miniature.

None of this is solvable by better metrics alone. Every case study in this piece also involved someone for whom the honest answer was personally expensive—a bonus, a reputation, a decade of authorship over a program now under question. A second line rebuilt around outcome-based measurement but layered on top of the same career incentives that rewarded Carrie Tolstedt’s silence and cost Howard Wilkinson his job will simply produce more sophisticated versions of the same evasions. The measurement has to change. So does the price of telling the truth.

It is also worth taking seriously what the regulators’ own convergence implies about where this is heading. The Federal Reserve, the FDIC, the GAO, NIST, and the IIA did not coordinate their findings—they arrived at the same conclusion independently, from different mandates, within the same few years. Convergence without coordination is usually a sign that a standard is hardening, not that a moment is passing. Institutions that treat this argument as a post-SVB overreaction, rather than the new baseline expectation, are likely to be rereading their own supervisory letters in a few years and wondering how they missed it.

The stakes of getting this right are also rising, not leveling off. Every failure examined here involved a risk that a sufficiently empowered reviewer could, in principle, still understand—a trading book, a sales incentive, a margin call. The AI models now moving into underwriting, claims, and credit decisions will not extend that same courtesy; their behavior can shift with a single retraining cycle in ways no annual attestation was ever built to catch. A second line that could not reliably catch a mismarked trading book will not reliably catch a model that has quietly drifted—not without first becoming the kind of second line this piece has been describing.

The organizations in this piece did not fail because nobody was watching. They failed because watching, on its own, was mistaken for managing. A modern second line has to be judged by a harder, more honest standard than whether the reviews got done: whether the risks that mattered actually got smaller. Everything else—the frameworks, the dashboards, the attestations—is only useful to the extent it serves that one outcome. Where it doesn’t, it is not governance. It is just paperwork with better branding.

Endnotes


[1]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank (Washington, DC: Federal Reserve, April 28, 2023), https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf; “Fed’s Barr: ‘Weaknesses in Supervision and Regulation Must Be Fixed,’” American Banker, April 28, 2023, https://www.americanbanker.com/news/feds-barr-weaknesses-in-supervision-and-regulation-must-be-fixed.

[2] The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[3]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards for Certain Large Insured National Banks, Insured Federal Savings Associations, and Insured Federal Branches, 12 C.F.R. Part 30, Appendix D (2014); Board of Governors of the Federal Reserve System, “Supervisory Guidance on Model Risk Management,” SR Letter 11-7 (Washington, DC: Federal Reserve, April 4, 2011).

[4]  “IIA Unveils New Three Lines Model,” Radical Compliance, July 22, 2020, https://www.radicalcompliance.com/2020/07/22/iia-unveils-new-three-lines-model/.

[5]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/.

[6]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[7]  U.S. Senate Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs, JPMorgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses (Washington, DC: U.S. Senate, March 15, 2013), https://www.hsgac.senate.gov/subcommittees/investigations/library/files/report-jpmorgan-chase-whale-trades-a-case-history-of-derivatives-risks-and-abuses-march-15-2013/.

[8]  JP Morgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses, summarized in Demos, https://www.demos.org/research/jp-morgan-chase-whale-trades-case-history-derivatives-risks-and-abuses.

[9]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report (San Francisco: Wells Fargo & Company, April 10, 2017), https://lowellmilkeninstitute.law.ucla.edu/wp-content/uploads/2018/01/WF-Board-Report.pdf.

[10]  Wells Fargo Newsroom, “Wells Fargo Board Releases Findings of Independent Investigation of Retail Banking Sales Practices and Related Matters,” press release, April 10, 2017, https://newsroom.wf.com/news-releases/news-details/2017/Wells-Fargo-Board-Releases-Findings-of-Independent-Investigation-of-Retail-Banking-Sales-Practices-and-Related-Matters/default.aspx.

[11]  “Summary of the Report of the Independent Directors of Wells Fargo & Company into Sales Practices,” Lexology, October 11, 2017, https://www.lexology.com/library/detail.aspx?g=9b82dbcc-146d-4921-847c-526ccbf505a2; Brad S. Karp, Roberto J. Gonzalez, and Vikas Desai, “Lessons Learned from the Wells Fargo Sales Practices Investigation Report,” Harvard Law School Forum on Corporate Governance, April 22, 2017, https://corpgov.law.harvard.edu/2017/04/22/lessons-learned-from-the-wells-fargo-sales-practices-investigation-report/.

[12]  Credit Suisse Group AG, Report of the Special Committee of the Board of Directors of Credit Suisse Group Regarding Archegos Capital Management, prepared by Paul, Weiss, Rifkind, Wharton & Garrison LLP (July 29, 2021), as reported in “Credit Suisse Publishes Independent Review of Archegos Losses,” Paul, Weiss news release, July 29, 2021, https://www.paulweiss.com/practices/litigation/internal-investigations/news/credit-suisse-publishes-independent-review-of-archegos-losses.

[13]  “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney, July 29, 2021, https://www.euromoney.com/article/28usrfe6tdwq9fkpayosg/capital-markets/unpacking-the-report-on-credit-suisses-archegos-disaster/; “Credit Suisse and the Archegos Collapse – Lessons in Risk Management and Governance for All,” BDO, February 21, 2025, https://www.bdo.co.uk/en-gb/insights/industries/financial-services/credit-suisse-and-the-archegos-collapse-lessons-in-risk-management-and-governance.

[14]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Associated Press via Seattle Times, November 19, 2018, https://www.seattletimes.com/business/whistleblower-in-danish-banking-scandal-bank-ignored-me/; “Danske Bank Money Laundering Scandal – Tip of the Icebergs,” National Law Review, accessed August 2026, https://natlawreview.com/article/danske-bank-money-laundering-scandal-tip-icebergs.

[15]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/; “Thanks to Danske Bank Whistleblower, SEC Sets Aside $178 Million for Harmed Investors,” Whistleblower Blog, April 4, 2023, https://whistleblowersblog.org/corporate-whistleblowers/sec-whistleblowers/thanks-to-danske-bank-whistleblower-sec-sets-aside-178-million-for-harmed-investors/.

[16]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, i-iii; “Federal Reserve Board Announces the Results from the Review of the Supervision and Regulation of Silicon Valley Bank,” press release, April 28, 2023, https://www.federalreserve.gov/newsevents/pressreleases/bcreg20230428a.htm.

[17]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, 3.

[18]  Federal Deposit Insurance Corporation, FDIC’s Supervision of Signature Bank (Washington, DC: FDIC, April 28, 2023), https://www.fdic.gov/news/press-releases/2023/pr23033a.pdf; “FDIC Signature Bank Report Summary,” prepared for the U.S. House Committee on Financial Services, May 2, 2023, https://financialservices.house.gov/uploadedfiles/2023.05.02_-_fdic_signature_bank_report_summary_final.pdf.

[19]  U.S. Government Accountability Office, Bank Supervision: More Timely Escalation of Supervisory Action Needed, GAO-24-106974 (Washington, DC: GAO, 2024), https://www.gao.gov/products/gao-24-106974.

[20]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[21]  The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[22]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

[23]  “Credit Suisse and the Archegos Collapse,” BDO; “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney.

[24]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Seattle Times; “Howard Wilkinson,” Kohn, Kohn & Colapinto.

[25]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0).

[26]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards, 12 C.F.R. Part 30, Appendix D; Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

What the rise, fall, and rapid rebirth of eXch tells us about the real shape of crypto crime in 2026

Every few months, a crypto exchange gets “shut down.” Headlines run. LinkedIn fills with hot takes. And then, quietly, the money keeps moving. That’s the pattern I want to walk through here—not as a hypothetical, but as a documented case, built on the work of the two firms that actually trace this money for a living: TRM Labs and Chainalysis.

Across my career in technology governance, cyber risk, enterprise transformation, and technology leadership, this particular case study has become one of the clearest illustrations of a lesson every risk leader eventually learns the hard way: shutting down a bad actor is not the same as dismantling the capability behind it. The organization goes away. The infrastructure, the liquidity, and the operators very often do not.

The Exchange That Wouldn’t Stay Dead:

eXch was a no-questions-asked crypto swap service. No identity verification, no meaningful compliance program—and it marketed that absence as a feature, branding itself a “privacy project” rather than what regulators would call it: a gap in the system, wide open and waiting to be used.

That gap became national news in February 2025, when North Korea’s Lazarus Group pulled off the largest crypto theft in history, stealing roughly $1.4 to $1.5 billion in Ethereum from the Bybit exchange.1 Bybit and independent investigators—including Elliptic, TRM Labs, and researcher ZachXBT—all pointed to the same off-ramp: eXch allegedly helped launder more than $90 million of the stolen funds.2

eXch’s owner, publicly known only as “Johann Roberts,” denied it, then partially admitted it, then blamed a slow compliance data feed. For what it’s worth, I went looking for a verified identity behind that name while researching this piece. I couldn’t find one. Treat it as an alias until proven otherwise.

In April 2025, eXch announced it was shutting down—citing, of all things, a DOJ whistleblower and a “transatlantic law enforcement operation.” Here’s the part almost nobody covered: it didn’t actually stop. TRM Labs found that eXch pulled its public-facing website but kept serving business partners through an API, with the same laundering fingerprints continuing right past its own announced shutdown date.3

This Isn’t One Bad Exchange—It’s a Lineage:

If eXch feels like an isolated case, look at what happened to Garantex, the Russian exchange first sanctioned in 2022 for laundering funds tied to darknet markets and ransomware groups like Conti and Hydra. Law enforcement finally seized its infrastructure in March 2025, after the platform had processed an estimated $96 billion in transactions since 2019, a substantial share of it tied to ransomware, darknet-market, and other criminal activity.4

What happened next is the whole point of this article. Garantex didn’t disappear. It became Grinex—same liquidity, same users, same money, new name. Chainalysis and TRM then traced the same pattern into ABCeX and its rebrand AEXBit, which share identical backend infrastructure and hot wallets with their predecessors; into the A7/A7A5 ruble-backed payment network, which has moved more than $93.3 billion in on-chain volume and counting; and into Heleket, a “new” service that received its opening liquidity directly from Garantex’s own wallets.5

TRM’s own assessment, stated plainly in its 2026 crypto crime report, is that this wave of rebrands is likely coordinated—a deliberate attempt to keep Russia’s crypto liquidity flowing while insulating the actual operators from further sanctions.6 For what it’s worth, Grinex itself went dark in April 2026 after a $13.7 million cyberattack it blamed, without evidence, on Western intelligence agencies.7 I’d bet money there’s already a successor standing by.

The Bigger Story Nobody’s Talking About Enough:

Here’s what I think most crypto-crime coverage still misses: individual rogue exchanges, however dramatic the headline, are no longer the main event.

Both TRM and Chainalysis now point to something structurally different—Chinese-language money laundering networks, or CMLNs. In 2025 alone, these networks moved an estimated $16.1 billion, roughly $44 million a day, across nearly 1,800 active wallets. That’s not a typo: Chainalysis measured CMLN growth at roughly 7,325 times the growth rate of illicit inflows to centralized exchanges since 2020.8

The anchor of this ecosystem is Huione Group, a Cambodia-based conglomerate that processed more than $98 billion in total crypto inflows between August 2021 and January 2025, over $4 billion of it confirmed illicit. In October 2025, the U.S. Treasury’s FinCEN designated Huione under Section 311 of the USA PATRIOT Act as a primary money laundering concern. Huione is also directly tied to Prince Group, the Cambodia-based criminal network behind a sprawling web of scam compounds across Southeast Asia.9

Why does this matter more than another exchange takedown? Because CMLNs aren’t one company you can seize. They’re a marketplace—fragmentation services, OTC desks, and “guarantee” platforms like Huione and Xinbi that connect buyers and sellers of laundering capacity, often without the platform operators ever directly touching the illicit funds themselves. Sanction one vendor, and the rest of the marketplace barely notices.10

Ransomware Isn’t Slowing Down—It’s Diversifying:

Data-leak-site-claimed ransomware incidents grew 50 percent year-over-year in 2025, reaching an all-time high even as enforcement activity intensified.11 The Ransomware-as-a-Service market has also fragmented, with some trackers counting as many as 85 active independent extortion groups—a more decentralized field that’s harder to monitor collectively, even as individual groups’ laundering patterns become easier to fingerprint on-chain.12

Separately, broader Chainalysis research on illicit crypto flows (not specific to ransomware) points to a shift in final-stage laundering toward exchanges with little to no know your customer (KYC) verification, with no-KYC exchange usage up 82 percent and usage of “guarantee” aggregators such as Tudou Danbao up 87 percent.13 Whether North Korean state actors rely on these no-KYC exchanges less than independent cybercriminals do—running a more specialized pipeline through Chinese money-laundering networks and bridge protocols instead—is a plausible pattern given DPRK’s well-documented use of dedicated laundering infrastructure. But it isn’t a claim I found directly confirmed in the sources reviewed for this piece, so I’m flagging it as a reasonable hypothesis rather than an established fact.

Enforcement has also started targeting the infrastructure layer itself, not just individual exchanges. In February 2025, the U.S., U.K., and Australia jointly sanctioned Zservers, a Russian bulletproof-hosting provider tied to ransomware operations including LockBit; Chainalysis data shows Zservers funneled at least $5.2 million through high-risk channels, including the sanctioned exchange Garantex.14 OFAC separately sanctioned Aeza Group, another Russian bulletproof host, in July 2025—though, notably, that action does not appear to have included the U.K. and Australia as co-sanctioning parties.15

What This Actually Means:

If you take one thing from this, let it be this: the “shut it down” model of enforcement works—temporarily. eXch kept running through its own back door. Garantex became Grinex became ABCeX became AEXBit. The harder, more consequential fight is against the marketplace model itself—the CMLNs, the guarantee platforms, and the hosting infrastructure underneath all of it—which doesn’t have one throat to choke.

The good news, and it’s a real one, is that blockchain transparency remains investigators’ structural advantage. The same on-chain fingerprinting—shared wallets, co-spending patterns, infrastructure overlap—that unmasked ABCeX as a Garantex clone will eventually do the same to whatever comes after Grinex, and whatever comes after that.

This case study reflects the kind of governance-under-adversarial-pressure challenge I spend a lot of time researching and writing about: how do we design governance, oversight, and risk management frameworks for ecosystems that are deliberately engineered to evade them? Answering that will take a coordinated, multi-layered response—end-to-end mapping of cryptocurrency transaction chains, stronger Know Your Customer and Anti-Money Laundering controls, deeper multinational cooperation among regulators and law enforcement, more rigorous misuse-case modeling to anticipate adversarial behavior, and broader, faster identification and blacklisting of the high-risk exchanges, wallets, and tokens that keep facilitating illicit finance long after their predecessors are supposedly gone.

Endnotes:

1. TRM Labs, “2026 Crypto Crime Report” (TRM Labs, 2026), https://www.trmlabs.com/reports-and-whitepapers/2026-crypto-crime-report.

2. Decrypt, The Block, and CryptoRank.io, contemporaneous news coverage of the Bybit hack and eXch’s role in laundering stolen funds, February–March 2025.

3. TRM Labs, “eXch Remains Active Despite Shutdown: How the Bybit Hack-Linked Exchange Continues to Enable Laundering of CSAM Funds” (TRM Labs Blog, May 2, 2025), https://www.trmlabs.com/resources/blog.

4. Chainalysis, “OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime” (Chainalysis Blog), https://www.chainalysis.com/blog/ofac-sanctions/.

5. TRM Labs, “2026 Crypto Crime Report.”

6. TRM Labs, “2026 Crypto Crime Report.”

7. TRM Labs, “2026 Crypto Crime Report.”

8. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem” (Chainalysis Blog, January 27, 2026), https://www.chainalysis.com/blog/2026-crypto-money-laundering/.

9. Chainalysis, “Crypto Sanctions: 2026 Crypto Crime Report” (Chainalysis Blog, 2026), https://www.chainalysis.com/blog/crypto-sanctions-2026/.

10. Chainalysis, “The Chinese-Language Underground Crypto Money Laundering Ecosystem.”

11. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report” (Chainalysis Blog, March 4, 2026), https://www.chainalysis.com/blog/crypto-ransomware-2026/.

12. Chainalysis, “Crypto Ransomware: 2026 Crypto Crime Report.”

13. Chainalysis, “2025 Crypto Theft Reaches $3.4 Billion” (Chainalysis Blog, December 18, 2025), https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2026/.

14. Chainalysis, “OFAC Sanctions Tracker.”

15. Chainalysis, “OFAC Sanctions Tracker.”

From Mythos to Fable: What Business Leaders Must Learn from the New AI Governance Crisis

Anthropic Claud Mythos InfoSec Infographic, generic rights-free, 2026.

The Mythos Moment Just Got Bigger

A few weeks ago, Anthropic’s Mythos model was being celebrated as a breakthrough in AI-enabled cybersecurity. Reports suggested it could identify software vulnerabilities at unprecedented speed, accelerate remediation efforts, and potentially transform how organizations secure critical infrastructure. Some observers described it as one of the most capable cyber-focused AI systems ever developed.¹

Today, the conversation looks very different. The White House has ordered Anthropic to suspend access to Mythos 5 and Fable 5 for foreign nationals, citing national security concerns. Reports indicate that government officials were concerned not only about potential jailbreak vulnerabilities but also about the possibility that a China-linked group may have accessed the models.² The administration reportedly fears that advanced frontier models could be reverse-engineered through model distillation techniques, allowing strategic competitors to replicate key capabilities.³

Whether those concerns ultimately prove justified is almost beside the point. For business leaders, the real lesson is not about Anthropic. It is about the future of AI itself. The Mythos controversy signals that AI governance is rapidly evolving from a technology management issue into a business resilience, geopolitical risk, and digital supply chain challenge.⁴

The New Reality: AI Is Becoming Strategic Infrastructure

For years, organizations treated cloud computing as utility infrastructure. Access was largely assumed. The same cloud services were available whether you were in Minneapolis, Mumbai, London, or Singapore. Artificial intelligence appeared to be following a similar trajectory.

That assumption may no longer hold. The government’s restrictions on Mythos and Fable represent one of the first major examples of an advanced AI model being treated more like sensitive defense technology than commercial software.⁵ In effect, policymakers are beginning to ask whether some AI systems should be governed similarly to advanced semiconductors, encryption technologies, or military capabilities.

If that trend continues, organizations may find that access to critical AI capabilities can be restricted, delayed, licensed, monitored, or even revoked based on national security considerations.⁶ That should concern every executive currently building long-term business strategies around AI-enabled operations.

Why Business Leaders Should Care

Many executives may be tempted to dismiss the Mythos controversy as a dispute between Anthropic and the federal government. That would be a mistake. The more important story is not whether Anthropic’s safeguards were sufficiently robust or whether a jailbreak vulnerability actually existed. The real story is that organizations are rapidly becoming dependent on AI systems they do not own, cannot fully inspect, and may not always be able to access.

Imagine investing millions of dollars to integrate a frontier AI model into cybersecurity operations, software development, customer service, fraud detection, or enterprise decision-making, only to discover that access has been restricted due to a government directive, geopolitical concerns, export controls, or actions taken by the model provider itself. What appeared to be a stable technology platform can quickly become a strategic dependency.⁷

This is precisely why the Mythos situation deserves attention from boards, executives, and risk leaders. The disruption was not caused by a system outage, ransomware attack, or cloud failure. Instead, it emerged from a combination of national security concerns, policy decisions, and uncertainty surrounding advanced AI capabilities. These are risks that many organizations have not yet incorporated into their enterprise risk management programs.⁸

Historically, leaders worried about disruptions involving suppliers, cloud providers, telecommunications carriers, or critical software vendors. Frontier AI models now belong in that same category. Organizations increasingly depend upon a relatively small number of providers for advanced AI capabilities, creating concentration risks that may become more significant as AI becomes embedded in core business processes.⁹

Endnotes

  1. Anthropic, Project Glasswing Technical Findings, June 2026.
  2. Terrence O’Brien, “China May Have Accessed Mythos,” The Verge, June 14, 2026.
  3. Ibid.
  4. Kristian McCann, “Why the US Restricted Anthropic’s Mythos and Fable and What It Means for AI Access,” June 15, 2026.
  5. Hadas Gold, “Anthropic Suspends All Access to Mythos Model After US Government Bans Foreign Nationals Use,” CNN, June 13, 2026.
  6. McCann, “Why the US Restricted Anthropic’s Mythos and Fable.”
  7. Gold, “Anthropic Suspends All Access to Mythos Model.”
  8. O’Brien, “China May Have Accessed Mythos”; Gold, “Anthropic Suspends All Access to Mythos Model.”
  9. McCann, “Why the US Restricted Anthropic’s Mythos and Fable.”

Russia’s Sanctions-Busting Cryptocurrency Empire: Architecture, Actors, and the Future of Financial Conflict

Fig. 1. Russia’s Sanctions-busting Cryptocurrency Empire Infographic, Jeremy Swenson via ChatGPT, 2026.


I. Origins of a Parallel Financial System
:

The roots of Russia’s sanctions-busting cryptocurrency ecosystem can be traced to the intersection of geopolitical pressure and technological opportunity. While Russia experimented with cryptocurrency policy ambiguity throughout the 2010s, it was the aftermath of the 2022 invasion of Ukraine—and the subsequent exclusion from key parts of the global financial system, including SWIFT—that triggered a structural change. Lacking dollar liquidity and limited by Western banking restrictions, Russian policymakers and aligned financial actors started rapidly developing alternative methods for cross-border settlement (1).

Early efforts were fragmented, consisting of informal networks of exchanges, darknet markets, and capital flight channels. Platforms such as Garantex, founded in 2019, became foundational nodes in this system, allowing users to convert rubles into stablecoins and move funds internationally while avoiding traditional compliance mechanisms (6). Despite sanctions imposed by the U.S. Treasury in 2022, these platforms adapted rapidly, shifting wallets, rebranding, and integrating with crypto mixers to obscure transaction flows (1).

By 2024, Russia had formally embraced cryptocurrency for international trade, legalizing its use in cross-border transactions while maintaining domestic restrictions. This dual posture—restrict internally, exploit externally—laid the groundwork for a state-tolerated, if not state-enabled, shadow financial architecture that would mature rapidly in the years that followed (9).

II. The Rise of A7A5 and the Industrialization of Evasion:

The emergence of the ruble-backed stablecoin A7A5 marked a turning point from opportunistic evasion to industrial-scale financial engineering. Developed through networks linked to sanctioned Russian financial institutions and offshore intermediaries, A7A5 was designed explicitly to bypass Western oversight by enabling direct conversion from rubles into crypto assets and then into globally usable currencies (6).

Unlike decentralized cryptocurrencies such as Bitcoin, A7A5 represents a hybrid model: centralized issuance combined with decentralized transaction pathways. This design allows Russian actors to maintain monetary control while leveraging blockchain’s opacity and global reach. Within its first year, the token processed tens of billions of dollars in transactions, with some estimates approaching $100 billion in cumulative volume—evidence of rapid adoption across trade networks and sanctions-affected industries (4).

Crucially, this system extended beyond simple financial transfers. It became embedded in supply chain logistics, enabling the procurement of dual-use goods—technology with both civilian and military applications—through intermediaries in regions such as Central Asia and the Middle East. Crypto-enabled payments allowed these transactions to bypass traditional banking scrutiny, effectively creating a parallel trade infrastructure insulated from Western enforcement mechanisms (3).

III. Decentralization as Strategy, Not Ideology:

In Western culture, decentralization is often seen as a libertarian ideal—an escape from centralized power. However, in the Russian sanctions-evasion model, decentralization is not about ideology but strategy. It is used selectively to reduce visibility, make enforcement harder, and spread operational risk.

This system operates as a layered network rather than a single platform. Exchanges such as Bitpapa and others flagged by blockchain intelligence firms function alongside mixers, peer-to-peer marketplaces, and offshore entities, creating a fluid ecosystem in which assets can be rapidly converted, transferred, and obfuscated (7).

Moreover, decentralization enhances resilience. When Western authorities sanction one node—such as Garantex—activity shifts to successor platforms or newly created entities, often staffed by the same personnel. This phenomenon mirrors adaptive systems: disruption leads not to collapse but to evolution. The result is a sanctions-resistant architecture that thrives on redundancy and ambiguity.

Academic research supports this point by showing that sanctions enforcement in crypto is structurally reactive, while illicit actors are fast and adaptive. Studies find that once wallets or platforms are sanctioned, actors quickly shift funds to new addresses, exchanges, or networks—often within hours—well before regulators can complete attribution and enforcement cycles (12). Because blockchain systems allow unlimited address creation and operate across jurisdictions, enforcement actions tend to disrupt specific nodes rather than the broader network. As a result, the research consistently demonstrates that sanctions evasion persists not despite enforcement, but because the system’s design enables rapid migration and continuity.

IV. The Ransomware Nexus: Criminal Infrastructure and State Alignment

At the heart of Russia’s crypto ecosystem lies a symbiotic relationship between cybercriminal groups and financial infrastructure. Ransomware organizations such as REvil and Ryuk-linked networks have long relied on cryptocurrency to receive and launder payments, targeting Western corporations, critical infrastructure, and supply chains (2).

The connection between these groups and sanctioned exchanges is well-documented. Platforms like Garantex have been identified as facilitating transactions tied to ransomware proceeds, effectively serving as financial clearinghouses for cybercrime (5). This relationship extends beyond mere tolerance. Investigations such as Operation Destabilise have uncovered networks in which cryptocurrency exchanges, money laundering operations, and state-linked actors intersect. In some cases, these networks have been used not only for financial gain but also to support espionage activities and strategic objectives aligned with Russian interests (11).

The implication is clear: ransomware is not simply criminal activity but a component of a broader hybrid warfare strategy. By targeting Western institutions and funneling proceeds through crypto networks, these groups generate revenue, disrupt adversaries, and reinforce Russia’s alternative financial ecosystem.

V. Extraction from the West: Mechanisms of Digital Theft:

The Russian crypto-sanctions ecosystem extracts value from the West through multiple channels, blending cybercrime, financial engineering, and trade manipulation. Ransomware attacks represent the most visible vector, with payments often demanded in cryptocurrency and subsequently laundered through exchanges and mixers (2).

However, a less visible but equally significant mechanism is trade-based money laundering facilitated by crypto. Russian entities purchase restricted goods through intermediaries, paying in stablecoins that are difficult to trace. These goods are then re-exported into Russia, effectively bypassing export controls (3).

Additionally, capital flight and asset concealment play a major role. Wealthy individuals and sanctioned entities move funds into crypto assets to protect them from seizure, leveraging decentralized wallets and offshore exchanges. The cumulative effect is a steady outflow of value from regulated Western systems into a shadow economy that operates beyond their reach.

By 2025, illicit cryptocurrency flows had surged dramatically, with tens of billions of dollars linked to sanctions evasion and state-aligned networks (10).

VII. Conclusion: The Future of Financial Warfare:

Russia’s sanctions-busting cryptocurrency empire represents a new phase in the evolution of financial conflict—not simply a workaround, but a scalable model for a decentralized, state-influenced financial system operating beyond traditional controls. What began as a reaction to Western sanctions has matured into a resilient ecosystem that blends state policy, criminal enterprise, and technological innovation. Its strength lies in its hybridity: centralized where control is necessary, decentralized where opacity provides advantage.

For the West, this presents a fundamental challenge. Traditional tools—sanctions, asset freezes, and banking restrictions—are increasingly limited in a world where adversaries can operate outside the formal financial system. Countering this shift requires more than incremental reform; it demands a transition from static enforcement to dynamic, intelligence-driven financial defense.

A central component of this approach is the expansion of blockchain analytics and real-time monitoring. On-chain intelligence has proven effective in tracing illicit flows and identifying high-risk actors, but its true value emerges when integrated into coordinated international enforcement frameworks. Moving beyond periodic sanctions designations toward continuously updated, intelligence-led responses will be critical to keeping pace with adaptive networks (7).

Equally important is targeting the infrastructure that enables liquidity. Cryptocurrency ecosystems depend on exchanges, stablecoin issuers, and fiat on-ramps and off-ramps to function. Coordinated regulation and enforcement against these access points—particularly across jurisdictions that facilitate intermediary flows—can significantly constrain the usability of sanctions-evading assets. While measures such as wallet blacklisting and exchange sanctions have had impact, they must evolve from reactive tools into part of a broader, proactive strategy (1).

At the same time, deterrence must be redefined. Financial penalties alone are insufficient against actors who operate in decentralized and jurisdictionally fragmented environments. Effective deterrence will require a combination of cyber operations, asset seizures, and coordinated disruption of ransomware and illicit financial infrastructure. Public-private collaboration will be essential, as much of the expertise and visibility into these networks resides within the private sector.

Beyond enforcement, the West must also compete. Developing secure, efficient, and transparent alternatives—such as regulated digital payment systems, central bank digital currencies, and compliant stablecoin frameworks—can reduce the relative attractiveness of shadow financial networks. If legitimate systems offer greater speed, cost efficiency, and accessibility, the incentive to rely on illicit alternatives diminishes.

Finally, this issue must be understood in its broader geopolitical context. Russia’s crypto ecosystem is not an isolated case but part of a wider movement toward financial fragmentation, in which states seek parallel systems to reduce dependence on Western institutions. Addressing this trend will require sustained international coordination, including strategic engagement with non-Western jurisdictions that play intermediary roles in these networks (4).

In this evolving landscape, success will not be measured by the elimination of illicit systems, but by the ability to constrain, outpace, and adapt to them. The future of financial warfare will belong to those who can align technological capability with strategic coherence—building financial architectures that are not only secure, but resilient against continuous disruption.

Bibliography:

  1. U.S. Department of the Treasury. “Treasury Sanctions Cryptocurrency Exchange and Network.” https://home.treasury.gov/news/press-releases/sb0225
  2. Chainalysis. Crypto Crime Report 2026. https://www.chainalysis.com
  3. Royal United Services Institute (RUSI). “The Shadow Crypto Economy Feeding Russia’s War Machine.” https://www.rusi.org
  4. Center for European Policy Analysis (CEPA). “A Crypto River Runs Through Russia.” https://cepa.org
  5. BankInfoSecurity. “U.S. Sanctions Crypto Exchange Tied to Russian Ransomware.” https://www.bankinfosecurity.com
  6. TRM Labs. “Garantex, Grinex, and the A7A5 Token.” https://www.trmlabs.com
  7. Elliptic. “Russia-Linked Crypto Platforms’ Ongoing Sanctions Evasion.” https://www.elliptic.co
  8. Reuters. “Sanctioned Russian Crypto Exchange Suspends Services.” https://www.reuters.com
  9. Business Insider. “Russia’s Crypto Shadow Economy.” https://www.businessinsider.com
  10. Financial Times. “Illicit Crypto Flows Surge to Record Levels.” https://www.ft.com
  11. National Crime Agency. “Operation Destabilise.” https://www.nationalcrimeagency.gov.uk
  12. Zola, Francesco et al. “Assessing the Impact of Sanctions in the Crypto Ecosystem.” https://arxiv.org/abs/2409.10031

Apple’s Carrier-Level Location Privacy: Strategy, Law, and the Future of Data Control

Fig. 1. Apple’s Carrier-Level Location Privacy Infographic. Jeremy Swenson and Open AI Chat GPT. 2026.

In January 2026, Apple quietly introduced a new privacy control in iOS 26.3 that allows users to limit the precision of location data shared with cellular carriers. While the feature’s initial rollout was narrow—restricted to select devices and carriers—it represents a significant shift in how location data is governed at the network level, with implications for legal investigations, platform competition, and data marketing strategies.1

Unlike app-level location permissions, which have been a focal point of mobile privacy debates for more than a decade, this control targets a less visible layer of the data stack: the information that cellular networks inherently collect as devices connect to towers. By allowing users to reduce carrier access to neighborhood-level rather than precise location data, Apple is challenging long-standing assumptions about the inevitability of carrier-side surveillance.

How the Feature Works—and Why It Matters

The new “Limit Precise Location” setting is found within Cellular Data Options on supported devices running iOS 26.3. When enabled, it reduces the granularity of location data available to participating carriers without degrading network performance or interfering with emergency services.2 Apple has emphasized that precise location data remains available to emergency responders and to apps that users have explicitly authorized, underscoring that the control is designed to limit passive collection rather than eliminate functionality.

At launch, the feature applies only to devices equipped with Apple’s newer C-series modems and is supported by a limited number of carriers, including Boost Mobile in the United States and select providers in Europe and Asia.2 This constrained availability reflects Apple’s vertically integrated approach to privacy: by controlling hardware, operating system, and key software layers, Apple can implement privacy protections that are difficult to standardize across more fragmented ecosystems.

Legal Investigation and Carrier Data: A Shifting Boundary

Carrier-level location data has long been a cornerstone of law-enforcement investigations. Historical cell-tower records can be used to infer a person’s movements, corroborate timelines, or establish proximity to crime scenes. As a result, carriers are frequent recipients of subpoenas and lawful data requests.

By limiting the precision of location data available at the carrier level, Apple’s new feature introduces friction into this investigative model. While it does not prevent lawful access to available data, it may reduce the specificity of records in cases where users have enabled the setting. This development raises important legal questions: if a platform offers a user-controlled mechanism that technically limits data collection, what obligations do carriers retain to preserve or disclose information that no longer exists in high-resolution form?

Security researchers and privacy advocates have framed the feature as a defensive response to the growing misuse of carrier data, including cases where location information has been sold, leaked, or exploited by criminal actors.3 From this perspective, the control is less about obstructing legitimate investigations and more about narrowing the attack surface of sensitive personal data.

Platform Strategy: Apple Versus Android

The contrast with Android is instructive. Android has made substantial progress in recent years with fine-grained app permissions, background location alerts, and transparency dashboards. However, it does not currently offer a system-level control that restricts the precision of location data shared directly with carriers.

This difference reflects deeper architectural realities. Android’s ecosystem spans multiple hardware manufacturers, modem vendors, and carrier customizations, making uniform carrier-level privacy controls difficult to deploy. Apple’s ability to design proprietary modems and tightly integrate them with iOS enables a level of privacy enforcement that is harder to replicate in a more open, modular platform.

From a strategic standpoint, this gives Apple a competitive narrative advantage: privacy not merely as policy, but as product design. While Android remains dominant globally in market share, Apple’s approach positions privacy as a premium feature tied to hardware, reinforcing brand trust among users who are increasingly sensitive to data misuse.

Privacy, Data Marketing, and Consumer Trust

Location data is among the most valuable assets in the data economy. It fuels targeted advertising, behavioral analytics, and predictive modeling across industries. Limiting carrier-level access does not eliminate these practices, but it does alter where and how data is collected.

Apple has been careful to frame this feature as part of a broader philosophy of data minimization rather than an absolute shield. App-level data collection, Wi-Fi triangulation, Bluetooth beacons, and other signals can still reveal detailed location information when users grant permission. The new control instead constrains a historically opaque channel of data flow that users rarely considered or understood.1

For consumers, this reinforces a key reality of modern privacy: meaningful control requires layered defenses. Carrier-level protections, app permissions, and informed usage patterns must work together. For data marketers and brokers, the shift signals a gradual tightening of default access to passive location data, encouraging greater reliance on consent-driven and aggregated sources.

Conclusion: Implications and Best Practices

Apple’s decision to limit precise location data shared with carriers marks an incremental but meaningful evolution in mobile privacy architecture. It highlights the growing tension between user autonomy, lawful access, and commercial data practices, while underscoring the strategic power of vertically integrated platforms.

Looking ahead, several implications stand out:

  1. Legal frameworks may need to adapt to scenarios where high-resolution location data is no longer uniformly available at the carrier level.
  2. Platform competition will increasingly hinge on architectural control, not just policy promises.
  3. Data markets will continue shifting toward explicit consent and diversified data sources as passive collection channels narrow.

Best practices for consumers remain straightforward but essential:

  • Regularly review system-level and app-level privacy settings.
  • Understand the scope and limits of each control.
  • Grant precise location access only when it is necessary for functionality.
  • Stay informed about how platforms and carriers handle personal data.

Ultimately, Apple’s new feature does not end location tracking, nor does it resolve every privacy concern. What it does accomplish is more subtle—and more consequential: it redraws the boundary of what is considered acceptable default data collection in the mobile ecosystem, setting a precedent that others will be pressured to follow.


Endnotes

  1. Apple Inc., “Limit precise location from cellular networks,” Apple Support, accessed January 2026, https://support.apple.com/en-euro/126101.
  2. Chance Miller, “iOS 26.3 Adds New Feature to Limit Location Data Shared With Your Carrier,” 9to5Mac, January 26, 2026, https://9to5mac.com/2026/01/26/ios-26-3-adds-new-feature-to-limit-location-data-shared-with-your-carrier/.
  3. Suzanne Smalley, “New Apple Feature Will Block Cell Networks From Capturing Precise Location Data,” The Record from Recorded Future News, January 29, 2026, https://therecord.media/new-apple-feature-block-location-data-cell-networks.

Digital vs. Physical Heists: Does Crypto Theft Impact Cryptocurrency Value?

Fig. 1. Digital vs. Physical Financial Theft Graphic, Jeremy Swenson, 2025.

Minneapolis—

Cryptocurrencies have revolutionized the financial landscape, offering decentralized and borderless transactions. However, the rise of crypto fraud and theft poses significant challenges to the stability and perception of digital currencies. With large-scale hacks and scams frequently making headlines, the question arises: do these fraudulent activities ultimately raise or lower the value of cryptocurrencies? This article examines the immediate and long-term effects of crypto theft on digital asset valuation, comparing these incidents with traditional cash heists and analyzing market reactions, investor psychology, and regulatory responses.

High-Profile Crypto Thefts and Their Immediate Impact:

One of the most significant incidents in recent history is the Bybit exchange hack in February 2025, where approximately $1.5 billion worth of Ethereum was stolen during a routine transfer from a cold wallet to a warm wallet. The breach led to a temporary decline in Ethereum’s value and prompted over 350,000 withdrawal requests from concerned users. Bybit’s CEO, Ben Zhou, assured clients of the company’s solvency and commitment to reimbursing affected users, highlighting the exchange’s $20 billion in assets to cover the losses.[1] Yet this is hard to believe considering the firm’s newer status. This event underscores the immediate negative impact such breaches can have on cryptocurrency values and investor confidence.

Similarly, the 2016 Bitfinex hack resulted in the theft of 119,756 Bitcoins, causing a sharp decline in Bitcoin’s price by 20%. The exchange managed to recover and reimburse affected users over time, but the incident highlighted vulnerabilities in crypto security and the potential for significant market disruptions.[2] Other major breaches, such as the infamous Mt. Gox collapse in 2014 and the Ronin Network hack of 2022, further illustrate how large-scale thefts can shake the market.[3]

Digital Heists vs. Traditional Bank Robberies:

The magnitude of the Bybit crypto heist becomes more striking when compared to traditional bank robberies. Stealing $1.5 billion in cash presents substantial logistical challenges. For instance, $1 billion in $100 bills weighs approximately 10,000 kilograms (22,046 pounds) and would occupy significant physical space.[4] Transporting such a massive amount would require meticulous planning, heavy machinery, and considerable risk of detection.

In contrast, the largest cash robbery in U.S. history, the Dunbar Armored robbery in 1997, involved the theft of $18.9 million.[5] This amount, while substantial, pales in comparison to the $1.5 billion stolen digitally from Bybit. The largest known cash heist globally was the 2005 Banco Central burglary in Brazil, where thieves stole approximately $70 million by tunneling underground to access the vault.[6] Even this record-setting crime is dwarfed by the scale and ease of execution of digital heists, which require no physical transport or direct confrontation with law enforcement.

Statistical Trends in Crypto Fraud and Theft:

The prevalence of crypto-related fraud and theft has seen a marked increase over the years. In 2022, the FBI reported that Americans lost over $2.57 billion to cryptocurrency investment fraud, a staggering 183% increase from the previous year.[7] This figure represented more than two-thirds of all internet investment scam losses reported that year. By 2023, losses had escalated to over $5.6 billion, indicating a 45% surge from 2022.[8] These statistics reflect a growing trend of illicit activities within the crypto space, which can erode investor trust and negatively impact cryptocurrency values.

Long-Term Effects on Cryptocurrency Value:

While immediate reactions to fraud and theft often result in sharp declines in cryptocurrency values, the long-term effects can vary. In some cases, the market demonstrates resilience, with values rebounding as security measures are enhanced and regulatory frameworks are strengthened. For instance, despite the significant losses from various hacks and scams, the overall market capitalization of cryptocurrencies has continued to grow over the past decade.[9]

However, persistent incidents of fraud and theft can lead to increased volatility and deter potential investors, hindering mainstream adoption. The perception of cryptocurrencies as high-risk assets may be reinforced, leading to more cautious investment approaches and potentially suppressing value growth. Large institutional investors, who could provide market stability, may hesitate to enter the crypto space due to security concerns.[10]

Regulatory Responses and Market Confidence:

Regulatory bodies worldwide are becoming increasingly vigilant in addressing crypto-related fraud and theft. Enhanced regulations aim to protect investors and ensure the integrity of the financial system. While some argue that increased regulation may stifle innovation, others believe it is essential for building trust and stability in the crypto market.[11]

For example, the U.S. government’s recovery of funds from the Bitfinex hack and the subsequent legal actions against the perpetrators demonstrate a commitment to combating crypto-related crimes. Such actions can bolster investor confidence, potentially leading to a positive impact on cryptocurrency values over time.[12] Similarly, stricter Know Your Customer (KYC) and Anti-Money Laundering (AML) requirements for crypto exchanges have been implemented to deter illicit activities and restore trust in the industry.

Conclusion:

Crypto fraud and theft present significant challenges to the stability and perception of cryptocurrencies. While the immediate consequences often include sharp value declines and shaken investor confidence, the long-term impact hinges on the industry’s ability to strengthen security, implement effective regulations, and promote transparency. For crypto thieves and threat actors, the profitability of theft can incentivize further attacks, potentially driving up cryptocurrency values. The real question is: how much theft and insecurity can the system withstand before it collapses, or will its architects continue propping it up just long enough to cash out? As the crypto ecosystem evolves, addressing these vulnerabilities is essential for sustaining growth and maintaining public trust.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant. Over 17 years, he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even government entities. Organizations appreciate his talent for bridging gaps, uncovering hidden risk management solutions, and simultaneously enhancing processes. He is a frequent speaker, podcaster, and a published writer – CISA Magazine and the ISSA Journal, among others. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MBA from Saint Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Cyber Security Summit Think Tank , the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy. He also has certifications from Intel and the Department of Homeland Security.

References:

  1. “Hackers steal $1.5bn from crypto exchange in ‘biggest digital heist ever,'” The Guardian, February 23, 2025.
  2. “Bitcoin Exchange Bitfinex Hacked, Loses $72 Million,” Reuters, August 3, 2016.
  3. “The Mt. Gox Bankruptcy and Its Lasting Impact on Crypto,” CoinDesk, March 2022.
  4. “Money Weight Calculator,” Good Calculators.
  5. “Dunbar Armored robbery,” Wikipedia.
  6. “The Biggest Bank Robbery in History,” Guinness World Records.
  7. “Fact Sheet: Crypto Harms by the Numbers,” Americans for Financial Reform, May 2024.
  8. “Americans lost $5.6 billion last year in cryptocurrency fraud scams,” AP News, September 2024.
  9. “Cryptocurrency Market Capitalization Hits New High Despite Scams,” Bloomberg, January 2025.
  10. “How Institutional Investors Approach Cryptocurrency,” Financial Times, November 2024.
  11. “How Global Regulators Are Cracking Down on Cryptocurrency Fraud,” Financial Times, December 2024.
  12. “US Recovers $3.6B Stolen in Bitfinex Hack, Arrests Two,” CNBC, February 8, 2022.

DeepSeek R1: A New Chapter in Global AI Realignment

Fig. 1. DeepSeek and Global AI Change Infographic, Jeremy Swenson, 2025.

Minneapolis—

DeepSeek, the Chinese artificial intelligence company founded by Liang Wenfeng and backed by High-Flyer, has continued to redefine the AI landscape since the explosive launch of its R1 model in late January 2025. Emerging from a background in quantitative trading and rapidly evolving into a pioneer in open-source LLMs, DeepSeek now stands as a formidable competitor to established systems like OpenAI’s ChatGPT and Microsoft’s proprietary models available on Azure AI. This article provides an expanded analysis of DeepSeek R1’s technical innovations, detailed comparisons with ChatGPT and Microsoft Azure AI offerings, and the broader economic, cybersecurity, and geopolitical implications of its emergence.


Technical Innovations and Architectural Advances:

Novel Training Methodologies DeepSeek R1 leverages a cutting-edge combination of pure reinforcement learning and chain-of-thought prompting to achieve human-like reasoning in tasks such as advanced mathematics and code generation. Unlike traditional LLMs that rely heavily on supervised fine-tuning, DeepSeek’s R1 is engineered to autonomously refine its reasoning steps, resulting in greater clarity and efficiency. In early benchmarking tests, R1 demonstrated the ability to solve multi-step arithmetic problems in approximately three minutes—substantially faster than ChatGPT’s o1 model, which typically required five minutes (Sayegh, 2025).

Cloud Integration and Open-Source Deployment One of R1’s key strengths lies in its open-source availability under an MIT license, a stark contrast to the closed ecosystems of its Western counterparts. Major cloud platforms have rapidly integrated R1: Amazon has deployed it via the Bedrock Marketplace and SageMaker, and Microsoft has incorporated it into its Azure AI Foundry and GitHub model catalog. This wide accessibility not only allows for extensive external scrutiny and customization but also enables enterprises to deploy the model locally, ensuring that sensitive data remains under domestic control (Yun, 2025; Sharma, 2025).


Detailed Comparison with ChatGPT:

Performance and Reasoning Clarity ChatGPT’s o1 model has been widely recognized for its robust reasoning capabilities; however, its closed-source nature limits transparency. In direct comparisons, DeepSeek R1 has shown parity—and in some cases superiority—with respect to reasoning clarity. Independent tests by developers indicate that R1’s intermediate reasoning steps are more comprehensible, facilitating easier debugging and iterative query refinement. For example, in complex multi-step problem-solving scenarios, R1 not only delivered correct solutions more rapidly but also provided detailed, human-like explanations of its thought process (Sayegh, 2025).

Cost Efficiency and Accessibility While premium access to ChatGPT’s capabilities can cost users upwards of $200 per month, DeepSeek R1 offers its advanced functionalities free of charge. This dramatic reduction in cost is achieved through efficient use of computational resources. DeepSeek reportedly trained R1 using only 2,048 Nvidia H800 GPUs at an estimated cost of $5.6 million—an expenditure that is a fraction of the resources typically required by U.S. competitors (Waters, 2025). Such cost efficiency democratizes access to high-performance AI, providing significant advantages for startups, academic institutions, and small businesses.


Detailed Comparison with Microsoft Azure AI:

Integration with Enterprise Platforms Microsoft has long been a leader in providing enterprise-grade AI solutions via Azure AI. Recently, Microsoft integrated DeepSeek R1 into its Azure AI Foundry, offering customers an additional open-source option that complements its proprietary models. This integration allows organizations to leverage R1’s powerful reasoning capabilities while enjoying the benefits of Azure’s robust security, compliance, and scalability. Unlike some closed-source models that require extensive licensing fees, R1’s open-access nature under Azure enables organizations to tailor the model to their specific needs, maintaining data sovereignty and reducing operational costs (Sharma, 2025).

Performance in Real-World Applications In practical applications, users on Azure have reported that DeepSeek R1 not only matches but sometimes exceeds the performance of traditional models in complex reasoning and mathematical problem-solving tasks. By deploying R1 locally via Azure, enterprises can ensure that sensitive computations are performed in-house, thereby addressing critical data privacy concerns. This localized approach is particularly valuable in regulated industries, where strict data governance is paramount (FT, 2025).


Market Reactions and Economic Implications:

Immediate Market Response and Stock Volatility The initial launch of DeepSeek R1 triggered a significant market reaction, most notably an 18% plunge in Nvidia’s stock as investors reassessed the cost structures underlying AI development. The disruption led to a combined market value wipeout of nearly $1 trillion across tech stocks, reflecting widespread concern over the implications of achieving top-tier AI performance with significantly lower computational expenditure (Waters, 2025).

Long-Term Investment Perspectives Despite the short-term volatility, many analysts view the current market corrections as a temporary disruption and a potential buying opportunity. The cost-efficient and open-source nature of R1 is expected to drive broader adoption of advanced AI technologies across various industries, ultimately spurring innovation and generating new revenue streams. Major U.S. technology firms, in response, are accelerating initiatives like the Stargate Project to bolster domestic AI infrastructure and maintain global competitiveness (FT, 2025).


Cybersecurity, Data Privacy, and Regulatory Reactions:

Governmental Bans and Regulatory Scrutiny DeepSeek’s practice of storing user data on servers in China and its adherence to local censorship policies have raised significant cybersecurity and privacy concerns. In response, U.S. lawmakers have proposed bipartisan legislation to ban DeepSeek’s software on government devices. Similar regulatory actions have been taken in Australia, South Korea, and Canada, reflecting a global trend of caution toward technologies with potential national security risks (Scroxton, 2025).

Security Vulnerabilities and Red-Teaming Results Independent cybersecurity tests have revealed that R1 is more prone to generating insecure code and harmful outputs compared to some Western models. These findings have prompted calls for more rigorous red-teaming and continuous monitoring to ensure that the model can be safely deployed at scale. The vulnerabilities underscore the necessity for both DeepSeek and its adopters to implement robust safety protocols to mitigate potential misuse (Agarwal, 2025).


Geopolitical and Strategic Implications:

Challenging U.S. AI Dominance DeepSeek R1’s emergence is a clear signal that high-performance AI can be developed without the massive resource investments traditionally associated with U.S. models. This development challenges the long-standing assumption of American technological supremacy and has prompted a strategic reevaluation among U.S. policymakers and industry leaders. In response, initiatives such as Microsoft’s Stargate Project are being accelerated to ensure that the U.S. maintains its competitive edge in the global AI arena (Karaian & Rennison, 2025).

Localized AI Ecosystems and Data Sovereignty To mitigate cybersecurity risks, several U.S. companies are now repackaging R1 for localized deployment. By ensuring that sensitive data remains on domestic servers, these firms are not only addressing privacy concerns but also paving the way for the creation of robust, localized AI ecosystems. This trend could ultimately reshape global data governance practices and alter the balance of technological power between the U.S. and China (von Werra, 2025).


Conclusion and Future Outlook:

DeepSeek R1 represents a watershed moment in the global AI race. Its technical innovations, cost efficiency, and open-source approach challenge entrenched assumptions about the necessity of massive compute power and proprietary control. In direct comparisons with systems like ChatGPT’s o1 and Microsoft’s Azure AI offerings, R1 demonstrates superior transparency and operational speed, while also offering unprecedented accessibility. Despite ongoing cybersecurity and regulatory challenges, the disruptive impact of R1 is catalyzing a broader realignment in AI development strategies. As both U.S. and Chinese technology ecosystems adapt to these shifts, the future of AI appears poised for a more democratized, competitively diverse, and strategically complex evolution.


About The Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.


References:

  1. Yun, C. (2025, January 30). DeepSeek-R1 models now available on AWS. Amazon Web Services Blog. Retrieved February 8, 2025, from https://aws.amazon.com/blogs/aws/deepseek-r1-models-now-available-on-aws/
  2. Sharma, A. (2025, January 29). DeepSeek R1 is now available on Azure AI Foundry and GitHub. Microsoft Azure Blog. Retrieved February 8, 2025, from https://azure.microsoft.com/en-us/blog/deepseek-r1-is-now-available-on-azure-ai-foundry-and-github/
  3. Waters, J. K. (2025, January 28). Nvidia plunges 18% and tech stocks slide as China’s DeepSeek spooks investors. Business Insider Markets. Retrieved February 8, 2025, from https://markets.businessinsider.com/news/stocks/nvidia-tech-stocks-deepseek-ai-race-nasdaq-2025-1
  4. Scroxton, A. (2025, February 7). US lawmakers move to ban DeepSeek AI tool. ComputerWeekly. Retrieved February 8, 2025, from https://www.computerweekly.com/news/366619153/US-lawmakers-move-to-ban-DeepSeek-AI-tool
  5. FT. (2025, January 28). The global AI race: Is China catching up to the US? Financial Times. Retrieved February 8, 2025, from https://www.ft.com/content/0e8d6f24-6d45-4de0-b209-8f2130341bae
  6. Agarwal, S. (2025, January 31). DeepSeek-R1 AI Model 11x more likely to generate harmful content, security research finds. Globe Newswire. Retrieved February 8, 2025, from https://www.globenewswire.com/news-release/2025/01/31/3018811/0/en/DeepSeek-R1-AI-Model-11x-More-Likely-to-Generate-Harmful-Content-Security-Research-Finds.html
  7. Karaian, J., & Rennison, J. (2025, January 28). The day DeepSeek turned tech and Wall Street upside down. The Wall Street Journal. Retrieved February 8, 2025, from https://www.wsj.com/finance/stocks/the-day-deepseek-turned-tech-and-wall-street-upside-down-f2a70b69
  8. von Werra, L. (2025, January 31). The race to reproduce DeepSeek’s market-breaking AI has begun. Business Insider. Retrieved February 8, 2025, from https://www.businessinsider.com/deepseek-r1-open-source-replicate-ai-west-china-hugging-face-2025-1
  9. Sayegh, E. (2025, January 27). DeepSeek is bad for Silicon Valley. But it might be great for you. Vox. Retrieved February 8, 2025, from https://www.vox.com/technology/397330/deepseek-openai-chatgpt-gemini-nvidia-china

Digital Horizons: 8 Transformative Trends Reshaping AI, Cybersecurity, Strategy, and Crypto for a Smarter 2025

Fig. 1. Digital Horizons Infographic, Jeremy Swenson, 2025.

Minneapolis—

The rapid technological developments of 2024 have established a foundation for significant shifts in artificial intelligence (AI), cybersecurity, digital strategy, and cryptocurrency. Business executives, policy leaders, and tech enthusiasts must pay attention to these key learnings and trends as they navigate the opportunities and challenges of 2025 and beyond. Here are eight insights to keep in mind.

1. AI Alignment with Business Goals:

2024 underscored the importance of aligning AI initiatives with overarching business strategies. Companies that successfully integrated AI into their workflows—particularly in areas like customer service automation, predictive analytics, tech orchestration, and supply chain optimization—reported not only significant productivity gains but also enhanced customer satisfaction. For instance, AI-powered tools allowed firms to anticipate customer needs with remarkable accuracy, leading to a 35% improvement in retention rates. However, misalignment of AI projects often resulted in wasted resources, showcasing the need for thorough planning. To succeed in 2025, organizations must create cross-functional AI task forces and establish KPIs tailored to their unique business objectives.[1]

2. The Rise of Responsible AI:

As AI adoption grows, so does scrutiny over its ethical implications. 2024 saw regulatory frameworks such as the EU’s AI Act and similar policies in Asia gain traction, emphasizing transparency, accountability, and fairness in AI deployments. Companies that proactively implemented explainable AI models—capable of detailing how decisions are made—not only avoided legal risks but also gained consumer trust. Moreover, organizations adopting responsible AI practices observed better team morale, as employees felt more confident about using ethically sound tools. The NIST AI Risk Management Framework is a good start. Leaders in 2025 must view responsible AI as a strategic advantage, embedding ethical considerations into every stage of AI development.[2]

3. Cyber Resilience Becomes Non-Negotiable:

The escalation of sophisticated cyber threats—including AI-driven malware and deepfake fraud—led to a dramatic increase in cybersecurity investments. Many businesses adopted zero-trust models, ensuring that no user or device is trusted by default, even within corporate networks. Product owners must build products with a DevSecOps mindset and must think out misuse cases from many angles. Additionally, the integration of machine learning for anomaly detection enabled real-time identification of threats, reducing breach response times by over 50%. As the cost of cybercrime is projected to exceed $10 trillion globally by 2025, organizations must prioritize cyber resilience through advanced threat intelligence, employee training, and frequent vulnerability assessments. Cyber resilience is no longer a luxury but a fundamental pillar of operational stability.[3]

4. Quantum Readiness Emerges as a Critical Strategy:

Quantum computing made significant strides in 2024, with breakthroughs in error correction and hardware scalability bringing the technology closer to mainstream use. While practical quantum computers remain years away, their potential to break traditional encryption methods has already prompted a cybersecurity rethink. Forward-looking organizations have begun transitioning to quantum-safe cryptographic algorithms, ensuring that their sensitive data remains secure against future quantum attacks. Industries like finance and healthcare—where data sensitivity is paramount—are leading the charge. By adopting a proactive quantum readiness strategy, businesses can mitigate long-term risks and position themselves as leaders in a post-quantum era.[4]

5. The Blockchain Renaissance:

Blockchain technology continued to evolve beyond its cryptocurrency roots in 2024, finding innovative applications in sectors such as logistics, healthcare, and real estate. For example, blockchain’s immutable ledger capabilities enabled unprecedented transparency in supply chains, reducing fraud and enhancing consumer trust. Meanwhile, the tokenization of physical assets, such as real estate and fine art, democratized access to investment opportunities, attracting a broader range of participants. Organizations leveraging blockchain reported reduced operational costs and faster transaction times, proving that the technology’s value extends far beyond speculation. In 2025, businesses must explore blockchain’s potential as a tool for enhancing efficiency and fostering trust.[5]

6. Employee Upskilling for Digital Transformation:

The digital skills gap emerged as a critical bottleneck in 2024, prompting organizations to invest heavily in workforce development. Comprehensive upskilling programs focused on AI literacy, cybersecurity awareness, and digital strategy were launched across industries. Employees equipped with these skills demonstrated greater adaptability and productivity, enabling their organizations to better navigate technological disruptions. Additionally, companies that prioritized learning cultures saw higher retention rates, as employees valued the investment in their professional growth. As digital transformation accelerates, the ability to upskill and reskill the workforce will be a key differentiator for organizations aiming to remain competitive.[6]

7. Convergence of AI and IoT:

The integration of AI and the Internet of Things (IoT) reached new heights in 2024, driving advancements in smart factories, connected healthcare, and autonomous vehicles. AI-enabled IoT devices allowed businesses to predict equipment failures before they occurred, reducing downtime and maintenance costs by up to 20%. In healthcare, AI-powered wearable devices provided real-time insights into patient health, enabling early intervention and personalized treatment plans. The growing adoption of edge computing further enhanced the responsiveness of AI-IoT systems, enabling real-time decision-making at the device level. This convergence is set to redefine operational efficiency and customer experiences in 2025 and beyond.[7]

8. The Decentralized Finance (DeFi) Evolution:

Decentralized Finance (DeFi) continued to mature in 2024, overcoming early criticisms of security vulnerabilities and lack of regulation. Enhanced interoperability between DeFi platforms and traditional financial systems enabled seamless cross-border transactions, attracting institutional investors. Innovations such as decentralized insurance and automated compliance tools further bolstered confidence in the ecosystem. As traditional banks increasingly explore blockchain for settlement and lending services, the line between centralized and decentralized finance is beginning to blur. In 2025, DeFi’s scalability and innovation are poised to challenge the dominance of legacy financial institutions, creating new opportunities for both consumers and businesses.[8]

Looking Ahead:

The intersection of AI, cybersecurity, digital strategy, and cryptocurrency offers unprecedented opportunities for value creation. However, success will hinge on leaders’ ability to navigate complexity, embrace innovation, foster outstanding leadership, and prioritize ethical stewardship. As these trends continue to evolve, businesses must remain agile and forward-thinking.

About the Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.


Footnotes:

  1. Smith, J. (2024). “AI’s Business Integration Challenges.” Tech Review.
  2. European Commission. (2024). “AI Act Regulatory Guidelines.” EU Tech Law Journal.
  3. Cybersecurity Ventures. (2024). “The Cost of Cybercrime: Annual Report.”
  4. Quantum Computing Report. (2024). “Quantum Progress and Cryptographic Implications.”
  5. Blockchain Association. (2024). “The Blockchain Beyond Crypto Study.”
  6. World Economic Forum. (2024). “The Future of Work: Digital Upskilling.”
  7. IoT Analytics. (2024). “The AI-IoT Convergence Report.”
  8. DeFi Pulse. (2024). “State of Decentralized Finance.”

Review of the New Link to Windows Application

Fig. 1. Screen Clip of the Link to Windows Application. Microsoft. Fair use Journalistic and AI created, 2025, Jeremy Swenson.

Minneapolis—

In today’s interconnected world, managing tasks across multiple devices has become second nature for many. The Link to Windows application takes this multitasking to the next level, creating a seamless bridge between Android smartphones and Windows PCs. It’s not just about convenience; it’s about enhancing productivity, ensuring security, and even adding a touch of fun to your digital life. Here’s a closer look at what the app offers, how it works, and why it’s worth integrating into your daily routine.


How It Works:

The Link to Windows app is like a personal assistant for your devices, synchronizing your Android smartphone with your Windows PC using a Microsoft account and a Wi-Fi connection.[1] Once paired, the app allows users to access essential phone functions directly from their computer. This includes:

  • Sending and receiving text messages.
  • Managing calls.
  • Accessing mobile apps right on the PC.
  • Viewing and transferring photos.
  • Mirroring notifications in real time.

Samsung and Surface Duo devices, the app is built-in, while others can easily download it from the Google Play Store. On the PC side, it integrates with Microsoft’s Phone Link app, pre-installed on Windows 10 and 11. The setup process is intuitive and guided, ensuring even beginners can start using the app with ease.


Key Benefits:

1. Security: Keeping Your Data Safe

Security is a cornerstone of the Link to Windows experience.

  • End-to-End Encryption ensures that messages and notifications are private and protected from prying eyes.
  • Granular Permissions empower users to decide exactly which features are shared between their devices, offering peace of mind.
  • For professionals, the app’s enterprise-friendly design makes it a great tool for IT-managed systems, maintaining compliance with corporate security standards.
  • Microsoft Account Integration leverages robust authentication protocols, including multi-factor authentication, to secure your data.

2. Convenience: Simplifying Multitasking

Imagine texting with the speed and ease of a full keyboard—that’s just one of the standout features of Link to Windows. Typing messages on your PC eliminates the frustration of small on-screen keyboards and lets you copy-paste content seamlessly between apps. Whether you’re drafting a quick response or multitasking during a meeting, this feature alone is a game-changer. Beyond texting, the app’s convenience extends to:

  • Unified Notifications: No more juggling devices; get all your alerts in one place and respond directly from your computer.
  • Drag-and-Drop File Transfers: Share photos, documents, and other files instantly between your phone and PC.
  • App Streaming: Run Android apps on your PC in a separate window, perfect for accessing mobile-only tools while working on a larger screen.

3. Fun: Enhancing Everyday Life

Link to Windows isn’t all about work—it’s also about fun and personalization.

  • Gaming Fans can play their favorite mobile games on a larger screen with keyboard and mouse controls for better precision.
  • Media Enthusiasts will love the ease of browsing photo galleries or streaming music directly from their phone to their PC.
  • Customization Options let you tailor notification styles and app layouts to match your workflow or personal aesthetic, making the experience uniquely yours.

Competitors in the Market:

While Link to Windows shines as a leader in device integration, it isn’t without competition. Apps like AirDroid and Pushbullet offer similar functionalities, such as file transfers, notifications, and messaging synchronization. However, these competitors often require premium subscriptions to unlock full features, whereas Link to Windows integrates seamlessly and cost-effectively with the Windows ecosystem.

Even Samsung recommends it as their own attempt at it failed: “The DeX for PC on Windows OS will end support from the One UI 7 version. We encourage customers to connect mobile phones and PCs through the Link to Windows feature.”[2]

Additionally, Apple users may point to the Apple Continuity suite, which offers exceptional integration between iOS devices and Macs. Though limited to Apple’s ecosystem, its smooth handoff capabilities, messaging sync, and call management rival those of Link to Windows. For those in mixed-device households, Link to Windows provides a more versatile alternative, particularly for Android-Windows users.


Why It’s Revolutionary:

The magic of Link to Windows lies in its ability to make your devices feel like extensions of one another. Instead of viewing your phone and PC as separate entities, the app integrates them into a single ecosystem. For instance, you can answer a text message on your PC, drag a photo into a PowerPoint slide, and then pick up a call—all without ever touching your phone. This unified experience is not just convenient; it’s empowering.


Room for Improvement:

While the app is a stellar achievement, it does have some room for growth:

  • The initial pairing process can be slightly clunky for non-tech-savvy users.
  • Not all features, such as app streaming, are available on every Android device, which can limit its appeal.
  • Apple users are left out, as there’s no comparable integration for iOS devices, making it a missed opportunity for cross-platform connectivity.

Final Verdict:

The Link to Windows app represents a new era in device integration. It’s a must-have for Android users who rely on Windows PCs, offering unparalleled security, convenience, and even an element of fun. From the ease of sending texts with a full keyboard to the joy of playing mobile games on a larger screen, the app transforms everyday tasks into streamlined experiences.


About the Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.


References:

[1] Microsoft. “Use Phone Link to Sync Your Android or iPhone”. 12/06/24. https://www.microsoft.com/en-us/windows/sync-across-your-devices?r=1

[2] Bowe, Zac. “Samsung is killing DeX for Windows — suggests Microsoft Phone Link as a replacement”. 12/03/24. https://www.windowscentral.com/software-apps/windows-11/samsung-is-killing-dex-for-windows-suggests-microsoft-phone-link-as-a-replacement

Why You Should Spit Out the Corporate Kool-Aid if You Want Innovation

Fig. 1. The Fallacy of Corporate Kool-Aid, Jeremy Swenson, 2024.

Minneapolis—

Corporate culture often prides itself on “innovation” and “forward-thinking,” yet more often than not, it’s hindered by bias, malignant egos, and groupthink. Ironically, in organizations claiming to embrace innovation, employees can become immersed in an environment where dissent is discouraged, and adherence to the company’s established perspectives is a prerequisite for professional survival. This “corporate Kool-Aid” fosters an atmosphere where true innovation struggles to survive. For those who genuinely want to innovate, shedding these restrictive mindsets is essential.

The Innovation Blockers: Bias, Malignant Egos, and Groupthink:

Biases are deeply embedded in most corporate structures, forming an invisible barrier that subtly yet persistently stifles new ideas. Whether it’s confirmation bias, where decision-makers favor ideas that reinforce their pre-existing beliefs, or status quo bias, which resists significant change, these biases ensure that only certain perspectives are entertained. When an organization prioritizes only safe, incremental improvements, true breakthrough ideas are abandoned. Biases in corporations thus serve as a gatekeeper against ideas that could lead to substantial innovation, as anything that doesn’t fit within the current framework is dismissed as too risky.

Ego also plays a significant role in corporate stagnation. In large corporations, leaders are often incentivized to maintain their status, limiting the emergence of truly groundbreaking ideas that may disrupt existing hierarchies. Malignant egos—those that view challenges to the status quo as personal affronts—tend to quash any idea that questions their own vision. When ego takes precedence over objective evaluation, promising concepts are often sidelined or dismissed outright, limiting the potential for progress.

Perhaps the most insidious blocker of innovation is groupthink, a phenomenon that thrives in environments where conformity is rewarded. Groupthink arises when employees, out of fear of ostracization or in pursuit of consensus, align their ideas with what they believe to be the dominant perspective. This limits a company’s ability to approach problems creatively. Once groupthink takes hold, organizations become less adaptable, focusing on pleasing internal stakeholders instead of exploring unconventional approaches that could lead to innovation.

The Alternative: Start-Ups and Their Blueprint for Innovation:

Unlike large corporations, small start-ups are known for their nimbleness and freedom from these entrenched mindsets. Start-ups, by necessity, must adopt a creative approach to stand out in a competitive market. Their size allows them to quickly adapt, test, and refine ideas based on real-world feedback. They lack the layers of management and rigid protocols that stifle creativity in corporations, allowing them to pivot and re-imagine solutions as challenges arise.

Start-ups encourage dissent and debate rather than penalizing it, knowing that innovation rarely emerges from echo chambers. In these environments, groupthink is less likely to flourish because diverse, disruptive perspectives are often essential to a start-up’s success. Without the burden of malignant egos dominating decision-making, start-ups can remain focused on solving genuine problems instead of adhering to individual agendas.

Another advantage of start-ups is their natural resistance to the biases that pervade larger corporations. Start-ups often draw talent from diverse backgrounds and ideologies, meaning biases are more likely to be challenged and less likely to dictate outcomes. This environment fosters resilience against the conformity that stifles corporate innovation, creating an ecosystem where unique ideas can grow.

Breaking Free: Encouraging Innovation Outside the Corporate Mindset:

For those within corporate structures who still wish to innovate, breaking free from the influence of corporate Kool-Aid requires courage and a willingness to challenge entrenched perspectives. Start by questioning assumptions and biases, both personal and organizational, and by fostering a culture where dissent and debate are embraced rather than discouraged. Encourage cross-departmental collaboration, and resist the urge to fall in line with the dominant viewpoint. Innovation rarely emerges from comfort zones; it thrives in the challenging, often uncomfortable process of questioning and exploring new perspectives.

To truly innovate, corporations must consider restructuring their approach. They could adopt leaner, start-up-like teams with the flexibility to pursue independent projects. They must create a culture where ideas are judged on merit, not on the ego or position of the proposer.

Conclusion:

Innovation and corporate Kool-Aid are often incompatible. The groupthink, biases, and egos prevalent in large organizations act as barriers to breakthrough thinking, driving companies to favor predictability over exploration. By shedding these restrictive mindsets and looking to the adaptable, challenge-embracing cultures of start-ups, those genuinely committed to innovation can find ways to foster creativity, disruption, and genuine progress. In doing so, they have the potential to reshape not only their organizations but also their industries—proving that sometimes, the best way forward is to spit out the Kool-Aid.

About the Author:

Jeremy A. Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and seasoned senior management tech risk and digital strategy consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds a certificate in Media Technology from Oxford University’s Media Policy Summer Institute, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota’s Technological Leadership Institute, an MBA from Saint Mary’s University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale, and New Hope Community Police Academy (MN), and the Minneapolis FBI Citizens Academy. You can follow him on LinkedIn and Twitter.