Writing.
1142 postsTutorials, case studies, and field notes from the engineers and reviewers shipping with agents at Noqta.
● More from the archive
1139 posts · sorted by dateIntermarché breach: 287,605 Drive customers exposed, CNIL and prosecutor notified
Groupement Les Mousquetaires confirms unauthorised access to the data of 287,605 Drive users: name, postal address, phone, date of birth, loyalty card number and order history. No banking data involved. The incident was notified to the CNIL and the Paris prosecutor — and it is a reminder that the regulatory clock starts at awareness, not at intrusion.
EU AI Act Transparency Rules Are Now Law: What Every Developer Needs to Know
The EU AI Act's transparency obligations took effect on August 2, 2026, requiring AI chatbots to identify themselves and mandating machine-readable labels on all AI-generated content — with penalties reaching €15 million for non-compliance.
Breach notification readiness: dating awareness and holding the 72 hours
The GDPR's 72-hour clock runs from the moment you become aware of a breach — a moment most teams cannot date after the fact. This tutorial builds the personal-data inventory, a tamper-evident incident log, bulk-read detection, and generation of the four elements a notification must contain, in TypeScript on Next.js and PostgreSQL.
Monetizing a Next.js API for AI Agents with x402 and Stablecoin Payments
Learn how to charge AI agents per API call using the x402 protocol. This tutorial covers the HTTP 402 payment flow, protecting Next.js route handlers with withX402, building an agent buyer that pays automatically, exposing paid endpoints through MCP, and shipping to Base mainnet.
GitHub Copilot SDK: Embed the Agent Runtime
GitHub's Copilot SDK ships the real agent runtime in six languages. Learn sessions, hooks, custom tools, fleet mode and credit budgets with working code.
Qwen3.8-Max Is Live: Alibaba's 2.4T MoE Model Developer Guide
Alibaba's Qwen3.8-Max — a 2.4T multimodal MoE model with a 983K-token context window — is now live. Open weights arrive this week. Here's the developer access guide.
Coldcard Firmware Flaw Drains 1,816 BTC as Attacks Enter Fourth Wave
A five-year-old build error in Coldcard hardware wallets replaced the chip's hardware random number generator with a predictable software fallback, letting attackers recompute seed phrases and sweep roughly 1,816 BTC across more than 5,200 addresses since July 30.
EU AI Act Enforcement Goes Live: What Every AI Business Must Do Now
The EU AI Act reached a landmark enforcement milestone on August 2, 2026 — chatbot disclosure rules and GPAI fining powers are now fully active, with penalties up to €15 million or 3% of global revenue.
Sandboxing AI Agent Code Execution with Microsoft MXC and TypeScript
Learn how to use Microsoft Execution Containers (MXC) to isolate untrusted code run by AI agents. This tutorial covers installation, policy configuration, one-shot and stateful sandbox execution, and integration with Claude tool calls in TypeScript.
Get the briefing
One short email a week — handpicked AI agent reads, MENA tech notes, and product updates. No spam.


