The Daily Log

Saturday, 11 July 2026

Dr. iur. Servatius von Tatzenberg

Two FINMA technical guidances land at once — quantum preparedness and product-risk documentation — while Casimir von Firn completes the CJEU sequence from the week with three complementary angles; the agentic-tool sovereignty piece is the one that should interrupt someone's Friday afternoon plans.

FINMA quantum-computing guidance: crypto-agility is now a file-able obligation, not a future-planning exercise

Unter Vorbehalt (de)

Casimir von Firn covers the substance in today's piece. The core obligation FINMA has articulated is a documented migration path for cryptographic systems — not awareness, not a theoretical roadmap, but a file-able artefact that an examiner can review. The practical pressure comes from sequencing: NIST finalised its post-quantum standards in August 2024, and FINMA is treating that date as the starting gun, not a distant marker. The immediate action item for any institution that has not yet begun: an inventory of which cryptographic dependencies — HSMs, TLS termination, signing keys, inter-system authentication tunnels — would need replacing first. Without that inventory, no one can write a credible migration timeline, and without the timeline, the guidance has no anchor.

The governance connection to the agentic-tool piece below is structural rather than coincidental. Both items identify the same gap: compliance frameworks were not built for infrastructure-level risk. Cryptographic infrastructure and tool-access infrastructure are different technical layers, but the question they raise for in-house counsel is identical — what is your institution's documented position on each, and who is responsible for keeping that position current?

Prediction: Institutions that treat crypto-agility as a 2028 project will find it on FINMA's 2027 examination shortlist instead — the guidance makes the sequencing expectation explicit.

FINMA product-risk guidance: discretionary managers must now document what used to live in the portfolio manager's head

Unter Vorbehalt (de)

Dr. iur. Servatius von Tatzenberg's piece today builds on the per-instrument suitability shift we identified in the July 8 article. The earlier piece mapped the suitability documentation obligation; today's maps the upstream product-risk assessment — the step that precedes the per-instrument suitability analysis and determines which products are eligible to appear in mandates at all. The operative word in the guidance is again 'document': product-risk assessments that currently live in investment committee memory or pricing-desk expertise need a paper trail that survives both personnel turnover and an audit. For smaller asset managers, this is a staffing and process question before it is a compliance one — the assessment has to be made by someone who can articulate it in writing. Read this before the next mandate structure review, not after the first finding.

Agentic tool sovereignty: the procurement clause your AI vendor does not want you to read

Unter Vorbehalt (de)

Casimir von Firn's piece today is the most structurally urgent item of the week for any organisation that has deployed an agentic AI system in the last two years. Standard AI vendor agreements treat the roster of tools an agent can call as a product feature — meaning the vendor can change it, and you agreed that they could, when you signed. The procurement clauses identified in the article create contractual sovereignty over the tool layer: what the agent can reach, who decides when that roster changes, and what internal approval process is required before a change takes effect. This is a live governance gap in every enterprise operating agentic AI on a standard vendor agreement, not a theoretical one. The general counsel's question is not whether the gap exists — it does — but whether the next contract renewal is soon enough to close it or whether an interim amendment is warranted.

The point generalises: as agents proliferate into legal, compliance, and finance workflows, the boundary of what the vendor controls versus what the institution controls expands with each new tool integration. The contracts that governs that boundary were written before most organisations understood what they were agreeing to.

Prediction: The first contentious disputes over agentic tool-access clauses will surface in commercial arbitration within 18 months — enterprises will discover that standard 'tool access' language authorised considerably more than their implementation teams understood at signing.

When state access to financial data becomes arbitrary — the Charter ceiling that most bulk-data requests have not been tested against

Unter Vorbehalt (de)

Casimir von Firn's piece today identifies where the proportionality requirement bites in practice. For financial institutions: the Charter ceiling gives structured grounds to push back on bulk data demands that lack specific justification — and it raises the question of whether standing AML bulk-data arrangements have ever been assessed against it. The answer, at most institutions, is no. For companies: it is a usable counterargument the next time a regulator or tax authority requests 'all transactions for the last five years' without specifying the transaction or person they are looking for. The May piece on Art. 47 BankG and Art. 271 StGB covered the Swiss hard stops on the direct route; this ruling adds an EU-law proportionality ceiling on the routes that are, individually, lawful. The combination means the legal frame for financial data requests is narrowing from both ends.

EDPB anonymisation guidelines — Casimir von Firn on what the three tests mean for your compliance programme

Unter Vorbehalt (de)

Yesterday's piece (Dr. iur. Servatius von Tatzenberg) laid out the legal framework of EDPB Guidelines 02/2026 — singling out, linkability, inference — and noted that the guidelines are in public consultation until 30 October 2026 and not yet final. Casimir von Firn's piece today goes one level down: what does each test require operationally from the data governance team, and which corporate data use cases fail at least one? The practical consequence arrives before the guidelines are finalised, because the test standard they articulate is already the interpretive baseline regulators and DPAs are working from. Read both pieces together — yesterday's for the legal architecture, today's for the compliance programme.

RT broadcasting ban: Casimir von Firn maps what "enabling distribution" now covers beyond broadcasters

Unter Vorbehalt (de)

Yesterday's piece identified that C-67/25 extended the 'operator' definition in Article 2f(1) of Regulation (EU) No 833/2014 to non-commercial website operators — the ruling arose from a German criminal prosecution of individuals running a donation-funded site, not a cable carrier. Casimir von Firn's piece today maps the downstream compliance implications for the infrastructure layer: CDN operators, API providers, and hosting companies that carry sanctioned content passively are within the definition. The question for tech procurement and infrastructure teams: which of your infrastructure providers has conducted its own Art. 2f(1) assessment, and do you need that answer in writing before the next contract renewal? The compliance conversation has moved from editorial policy to technical stack.

C-277/25 Helpfind: the litigation funder angle — assigning a motor-liability claim to a funder is EU-law proof

Unter Vorbehalt (de)

Yesterday's piece covered C-277/25 from the cross-border enforcement dimension — the insurer side of the claim and cross-border recognition. Casimir von Firn's piece today goes to the litigation finance structure: assigning a motor-liability claim to a third-party funder is valid under EU law. For in-house teams managing fleet liability or high-volume motor-claims programmes, this closes the legal uncertainty that some counterparties were using to resist assignment proposals. The structural viability of litigation funding for this claim class is now settled at EU level. Evaluate funding proposals on economics, not on residual legal risk that no longer exists.

Private equity is refinancing international law firms — your panel review needs a new question

Law.com International

Law.com's survey of private equity investment in international law firms documents a structural shift that affects how in-house counsel should run panel reviews. When a major PE firm holds a minority or majority stake in your external counsel, several questions that were previously theoretical become practical: who controls the firm's strategic decisions about which client relationships to prioritise in a conflict; what happens to matter confidentiality in a portfolio restructuring; and does the firm's capital position change its appetite for contingency arrangements or early exits from long-running mandates? None of these are hypothetical risks — each has a specific answer that varies by investment structure and jurisdiction. The next panel review is the right moment to ask for the firm's ownership and governance disclosures, not after a conflict arises.

Quantum migration paths, tool-access governance, and a Charter proportionality ceiling on data requests: three different legal frameworks, one underlying message — document your position before someone asks for it.