About

EST. 2026 / THE EDITORIAL DESK

About Human Required.

A small, independent publication writing plainly about AI, cybersecurity, and the systems quietly reshaping how software gets built, how identity works, and how attacks actually happen.

Human Reviewed

Most coverage of AI and cybersecurity is some combination of hype, fear, recycled press release, or prose shaped to satisfy a recommendation algorithm. We are not in the business of any of those, and the assumption behind this place is that the reader is an adult who would rather be correctly informed than briefly flattered.

We use AI for research, summarisation and first drafts. That is not a confession; refusing to use the best tools available to a working publication would be stubborn and stupid, and pretending otherwise would be a kind of theatre. What we will not do is hand a model the keys to the job: a human reads, edits, checks the facts, and signs off on every article that goes out under our name. The byline is the responsibility, not the prompt.

This is a small, independent publication. We write about the systems that are reshaping how software gets built, how identity works, how attacks happen, and how the open source everyone quietly depends on keeps the lights on. We are not a content farm, a vendor blog, or a research group with a quarterly target; we are a small number of people who think this material is worth writing about carefully, and we are doing it for as long as it stays fun and solvent.

Dark developer workbench at night: a laptop showing terminal code, a worn DEV FUEL coffee mug, scattered handwritten notes with TODO items and flow diagrams.
The edit table. Everything we publish passes through it.

What we cover

Not in the spirit of a tag cloud, and not because we sat in a room brainstorming categories. The shape of the publication follows the work, in roughly this order of attention.

AI, with a particular interest in the gap between a polished demo and a system that actually survives a year in production; agents, infrastructure, evals, the bits of the stack nobody talks about until they break, and the unit economics of running models at scale without the marketing budget to disguise the bill. The hype is the most boring part of the field. The interesting part is what survives contact with real users and real cost.

Cybersecurity, written for people who run systems rather than people who write about people who run systems. Threat actors, breaches, defences, identity and the practice of keeping a production environment honest. A threat actor saying something is true does not make it true; we try to label those claims as such, and not pass them along as fact.

Open source, including the unglamorous question of who is paying for the libraries the rest of the industry quietly depends on, from bus factor to governance to sustainability, and the projects doing too much work for too little credit. Worth covering, not because it is fashionable, but because the whole stack sits on top of it.

Identity, hardware repair, practical security, the slow death of the open web, the state of AI-generated music, the way vibe coding is changing how software gets written; all of it gets covered when there is something worth saying.

What we will not do

Publish unattributed claims as fact, especially when the source has a financial or political interest in the answer; recycle press releases as news; use absolute language where the data will not carry it (the trick where “every major bank” quietly becomes “some major banks” before it gets anywhere near a sentence); run sponsored content, affiliate links, or hidden advertising of any kind. If that ever changes, the article will say so. So far it has not.

Editorial standards

Every claim is sourced. Major statistics, regulatory claims, security incidents and product capabilities link back to primary sources: vendor documentation, government advisories from CISA, NIST and ENISA, regulator filings or court documents. Where a fact comes from a threat actor, a marketing department or a third-party reporter, that is stated in the article and reflected in the confidence label.

Corrections are visible. If you spot an error, email corrections@humanrequired.org with the URL and the claim; we verify every correction against primary sources and issue a dated note in the article. Substantive corrections also update the JSON-LD dateModified field so search engines do not keep indexing the wrong version.

The “Human Reviewed” badge is earned, not decorative. It only appears on articles where a real human has read the draft, checked the claims and signed off before the post went live. If a post does not carry the badge, treat it as a draft, even if it is on the site.

How to read what we publish

On any article where claims are easy to overstate, we attach a confidence label so you can calibrate your reading without doing our job for you.

Confirmed means the claim is documented in an official disclosure, a regulator filing, a court document or a primary source we have personally read. Claimed means a threat actor, vendor or third-party reporter asserted it, but we have not independently verified it. Inferred means it is consistent with the available evidence, but no one has directly stated it on the record. Unknown means we do not have a reliable source, and we are not going to guess.

If a number sounds too round or too convenient, it is probably from a press release, and we try to flag that. When the honest answer is that nobody knows yet, we say so, and we say why we think nobody knows yet.

Correction policy

The first version of any honest piece of writing is a draft.

Corrections go up as visible notes at the bottom of the affected article, with the date and what changed; substantive corrections update the article body and the JSON-LD dateModified field. Minor corrections (typos, broken links, the occasional awkward sentence) update the article without a visible note, on the assumption that nobody needs a banner to learn that we fixed a missing comma.

Send corrections to corrections@humanrequired.org with the URL, the claim, and ideally a primary source. We respond to every credible correction request within seven days, faster when the error is consequential.

Get in touch

Tips, criticism, security stories, strange findings and article ideas all go to the same place; we read everything, and we respond to most of it. The contact page has the addresses by topic, including a PGP key for the security mailboxes.

Two notes that have saved people time before. First, we do not publish rumour as news: if you are sending us a tip that requires discretion, say so up front, and we will keep you posted about whether we can use it. Second, pitch ideas are welcome, but we are not the right home for product launches, sponsored placements or guest posts that already exist as marketing copy. If you are not sure whether something fits, send it anyway; we will tell you.

Otherwise, see you in the next dispatch.

Open the channel

Tips, pitches, criticism, PGP-encrypted security mail. We read everything, and we reply to most of it.

Go to contact →

Recent from the desk

The four most recent pieces. The full archive is at the Index.

font-family:’JetBrains Mono’,monospace;font-size:0.85em”>Loading the latest…

FOLLOW / HUMAN VERIFIED / NO TRACKING

Read what we publish, in the order we publish it.

No newsletter, no algorithm, no growth team reordering the post titles to maximise clicks. Subscribe via RSS and the next piece lands in your reader when it lands.

Subscribe via RSS Read the latest