AI models have become substantially more capable since the EU AI Act entered into force in August 2024. OpenAI’s current GPT-5.6 models can support complex professional work, use tools and complete multi-step tasks with much less human guidance than earlier GPT generations.
Greater capability does not remove the need for governance. It makes it more important to understand where AI is operating, which decisions it influences and how humans supervise its output.
Under the EU AI Act, a spam filter, an AI recruitment system and a general-purpose model are not treated as the same kind of risk. The obligations depend on the use case, the system’s role and its potential effect on health, safety and fundamental rights. Businesses may also face transparency requirements when people could reasonably mistake AI-generated output for human-created content.
By mid-2026, AI literacy and prohibited-practice requirements are already applicable, as are obligations for general-purpose AI model providers. Further transparency rules apply from 2 August 2026, while major high-risk-system requirements follow later.
Read the article for a practical overview of the timeline and its implications for your business.
https://mkdev.me/posts/when-does-the-eu-ai-act-come-into-force-and-what-does-this-mean-for-your-business
Greater capability does not remove the need for governance. It makes it more important to understand where AI is operating, which decisions it influences and how humans supervise its output.
Under the EU AI Act, a spam filter, an AI recruitment system and a general-purpose model are not treated as the same kind of risk. The obligations depend on the use case, the system’s role and its potential effect on health, safety and fundamental rights. Businesses may also face transparency requirements when people could reasonably mistake AI-generated output for human-created content.
By mid-2026, AI literacy and prohibited-practice requirements are already applicable, as are obligations for general-purpose AI model providers. Further transparency rules apply from 2 August 2026, while major high-risk-system requirements follow later.
Read the article for a practical overview of the timeline and its implications for your business.
https://mkdev.me/posts/when-does-the-eu-ai-act-come-into-force-and-what-does-this-mean-for-your-business
mkdev.me
EU AI Act: Key Dates & Business Compliance | mkdev
The EU AI Act is here — learn what it means for your business, key dates, high-risk AI rules and AI risk classifications, compliance requirements, and penalties. Stay ahead of AI regulations in the EU.
Without open standards, every container tool could have its own incompatible image format, runtime and registry protocol. This video explains how OCI prevents that fragmentation. Watch it here: https://www.youtube.com/watch?v=oUlD_dOdL04
Discover the foundations of OpenShift 4 cluster management, starting with its reimagined installation experience and continuing through its most important features. Free mkdev course —
Articles: https://mkdev.me/posts/production-openshift-cluster-in-35-minutes-first-look-at-okd-4-and-the-new-openshift-installer
Videos: https://www.youtube.com/playlist?list=PLozcbFx8FoPGM-Dk1jVBu58pwUGP9WGIX
Articles: https://mkdev.me/posts/production-openshift-cluster-in-35-minutes-first-look-at-okd-4-and-the-new-openshift-installer
Videos: https://www.youtube.com/playlist?list=PLozcbFx8FoPGM-Dk1jVBu58pwUGP9WGIX
mkdev.me
Deploy OKD 4 on AWS in 35 Minutes with OpenShift Installer
In this article, Kirill Shirinkin will show you how to install the new production-ready OKD 4 cluster on AWS and demonstrate the benefits of the new openshift-installer.
A request passing through a CDN can arrive at your backend with much more context than it had when it left the user’s browser.
Depending on the provider and configuration, that context can include an approximate country, region, city, timezone, postal code and coordinates. Cloudflare and Amazon CloudFront can generate this information from the visitor’s IP address and forward it as HTTP headers.
This is fast, inexpensive and requires very little application code. It is not precise enough for navigation or other location-sensitive features, but it is often sufficient for analytics, localisation and broad geographic restrictions.
We explain the setup and trade-offs in this article: https://mkdev.me/posts/free-and-lightning-fast-ip-geolocation-from-a-cdn-provider
Depending on the provider and configuration, that context can include an approximate country, region, city, timezone, postal code and coordinates. Cloudflare and Amazon CloudFront can generate this information from the visitor’s IP address and forward it as HTTP headers.
This is fast, inexpensive and requires very little application code. It is not precise enough for navigation or other location-sensitive features, but it is often sufficient for analytics, localisation and broad geographic restrictions.
We explain the setup and trade-offs in this article: https://mkdev.me/posts/free-and-lightning-fast-ip-geolocation-from-a-cdn-provider
mkdev.me
CDN IP Geolocation: Fast, Free & Edge-Powered | mkdev
In this article, Kirill Shirinkin demonstrates how to leverage your CDN for seamless IP-based geolocation. Learn to configure Cloudflare and Amazon CloudFront to deliver visitor location data directly via HTTP headers, streamlining your analytics and location…
🔥1
Kubernetes complexity can hide security gaps, wasted capacity and operational friction. mkdev audits your clusters and applications, then delivers practical recommendations and concrete backlog items. Check out the page and schedule a call: https://mkdev.me/b/audits/kubernetes-audit-assessment
mkdev.me
Kubernetes Audit and Assessment | mkdev audits for business
As part of Kubernetes Audit and Assessment, we take a deep review of your setup from security and high availability to cost and automation. We provide you with a detailed report on all angles of Kubernetes usage, from cluster operations to developer experience
“We only use ChatGPT as a copilot, so the EU AI Act does not really apply to us.”
That is an understandable assumption, but it is incorrect. Article 4’s AI literacy requirement applies to organisations whose employees use tools such as ChatGPT for professional purposes, including relatively ordinary tasks such as drafting marketing copy or translating text.
A human reviewing the answer does not remove the requirement. The person providing that oversight needs enough knowledge to recognise unreliable information, inappropriate recommendations, disclosure of confidential data and situations in which AI should not be used at all.
This has become more relevant with GPT-5.5 and GPT-5.6. Current models can perform deeper analysis, interact with tools and complete multi-step work that earlier chatbots could not reliably handle. Treating them as slightly more convenient search engines is no longer an adequate approach to governance.
The AI Act does not prescribe one identical course for everyone. It expects organisations to take a role-specific and risk-based approach. Our article looks at why ChatGPT falls within the requirement and where companies should begin.
https://mkdev.me/posts/my-company-is-using-chatgpt-does-the-ai-act-literacy-requirement-apply-to-us
That is an understandable assumption, but it is incorrect. Article 4’s AI literacy requirement applies to organisations whose employees use tools such as ChatGPT for professional purposes, including relatively ordinary tasks such as drafting marketing copy or translating text.
A human reviewing the answer does not remove the requirement. The person providing that oversight needs enough knowledge to recognise unreliable information, inappropriate recommendations, disclosure of confidential data and situations in which AI should not be used at all.
This has become more relevant with GPT-5.5 and GPT-5.6. Current models can perform deeper analysis, interact with tools and complete multi-step work that earlier chatbots could not reliably handle. Treating them as slightly more convenient search engines is no longer an adequate approach to governance.
The AI Act does not prescribe one identical course for everyone. It expects organisations to take a role-specific and risk-based approach. Our article looks at why ChatGPT falls within the requirement and where companies should begin.
https://mkdev.me/posts/my-company-is-using-chatgpt-does-the-ai-act-literacy-requirement-apply-to-us
mkdev.me
ChatGPT & EU AI Act: AI Literacy for Business
With the EU's AI Act now in effect, businesses are facing a critical new reality: AI compliance is no longer optional. Paul Larsen's article dives deep into the 'AI Literacy' requirement, revealing how everyday use of tools like ChatGPT unexpectedly places…
Struggling to decide what matters when learning a new technology? Start with the concepts, explore the details when a real project demands them, and don’t confuse theoretical knowledge with experience. Learn more through the Prometheus example in this article.
https://mkdev.me/posts/how-to-learn-new-technologies-prometheus-example
https://mkdev.me/posts/how-to-learn-new-technologies-prometheus-example
mkdev.me
Effective Tech Learning: The Prometheus Approach | mkdev
Learning new technologies as a beginner is extremely hard! In this article, Kirill Shirinkin will give one rule, distilled from over a decade of experience, which will allow you to learn new technologies in shortest time possible.
In the 95th mkdev dispatch Kirill talks about cloud providers inventing new execution layers for AI Agents to operate in. Also inside: trusting Claude Code a bit too much, tracking Amazon Bedrock Costs, spinel and more!
https://mkdev.me/posts/do-ai-agents-need-new-containers-95
https://mkdev.me/posts/do-ai-agents-need-new-containers-95
mkdev.me
AI Containers: Innovation or Marketing Spin? | mkdev
In the 95th mkdev dispatch Kirill talks about cloud providers inventing new execution layers for AI Agents to operate in. Also inside: trusting Claude Code a bit too much, tracking Amazon Bedrock Costs, spinel and more!
Should you define every GKE resource yourself or use a Terraform module?
Building a basic cluster from individual resources is a good way to understand what Terraform is actually creating. A maintained module becomes useful once you need repeatable configurations, multiple environments and more advanced GKE features without duplicating large amounts of code.
This article demonstrates both approaches, including VPC-native networking, node pools, service accounts and the complete Terraform deployment lifecycle.
A practical introduction for anyone starting to automate GKE: https://mkdev.me/posts/deploying-gke-clusters-with-terraform
Building a basic cluster from individual resources is a good way to understand what Terraform is actually creating. A maintained module becomes useful once you need repeatable configurations, multiple environments and more advanced GKE features without duplicating large amounts of code.
This article demonstrates both approaches, including VPC-native networking, node pools, service accounts and the complete Terraform deployment lifecycle.
A practical introduction for anyone starting to automate GKE: https://mkdev.me/posts/deploying-gke-clusters-with-terraform
mkdev.me
GKE Cluster Automation: A Terraform How-To Guide
Discover how to deploy a GKE cluster using Terraform! We walk through using basic and advanced configurations with hands-on examples to set up your Google Kubernetes Engine effectively. Dive into our tutorial for practical insights.
Your delivery pipeline should help you move faster without sacrificing stability. mkdev designs CI/CD systems around your team, product and business, from organizational challenges to technical implementation. Check out the page and schedule a call: https://mkdev.me/b/consulting/majestic-pipeline
mkdev.me
Majestic Pipeline for your business | mkdev
Schedule a call to receive the Majestic Pipeline consultation from industry experts
The more capable AI becomes, the easier it is to trust it too much.
The current GPT-5 generation is better at understanding intent, reasoning across large amounts of context and using external tools. Its answers can be detailed, polished and highly convincing. But a convincing answer is not automatically a correct one, and an autonomous workflow is not automatically an appropriate one.
AI literacy in 2026 therefore involves much more than learning how to write prompts. Employees need to understand what information may be shared, when external sources must be checked, which actions require human approval and where the model’s output should never be treated as a final decision.
This is both the carrot and the stick of the EU AI Act’s literacy requirements: better-trained teams can use AI more effectively, while companies without suitable guidance expose themselves to avoidable operational, legal and reputational risks.
Our article looks at how companies can turn AI literacy from a compliance exercise into a practical business capability.
https://mkdev.me/posts/the-carrot-and-stick-of-the-eu-ai-act-s-literacy-requirements-benefits-compliance-and-risks
The current GPT-5 generation is better at understanding intent, reasoning across large amounts of context and using external tools. Its answers can be detailed, polished and highly convincing. But a convincing answer is not automatically a correct one, and an autonomous workflow is not automatically an appropriate one.
AI literacy in 2026 therefore involves much more than learning how to write prompts. Employees need to understand what information may be shared, when external sources must be checked, which actions require human approval and where the model’s output should never be treated as a final decision.
This is both the carrot and the stick of the EU AI Act’s literacy requirements: better-trained teams can use AI more effectively, while companies without suitable guidance expose themselves to avoidable operational, legal and reputational risks.
Our article looks at how companies can turn AI literacy from a compliance exercise into a practical business capability.
https://mkdev.me/posts/the-carrot-and-stick-of-the-eu-ai-act-s-literacy-requirements-benefits-compliance-and-risks
mkdev.me
EU AI Act Literacy: Benefits, Compliance & Risks | mkdev
Navigate the EU's AI Act requirements and unlock the full potential of AI for your business. Paul Larsen's guide provides actionable steps to build tailored AI literacy programs, minimizing risks and maximizing benefits through practical, targeted training.
Serving a SaaS app on customer-owned domains gets complicated when every hostname needs TLS. AWS ALBs start with a quota of 25 additional certificates, while Cloudflare for SaaS offers a more scalable custom-domain workflow. Watch the video: https://www.youtube.com/watch?v=hy1feUVVejQ
YouTube
Cloudflare for SaaS: AWS fail connecting multiple CNAME, DNS & SSL Capabilities!
In this video we are going to see how Cloudflare for SaaS is able to connect unlimited CNAME to the same endpoint everyone with a different certificate, something that AWS can't do, because it has a 25 as a limit.
AWS Load Balancer Controller with EKS,…
AWS Load Balancer Controller with EKS,…
👍1
The free Argo CD Lightning Course will teach you how Argo CD works, what problems it solves, and why it has become an important tool for managing Kubernetes deployments. Available as both articles and videos, the course also covers Argo CD’s essential features and how it structures projects and applications.
Article series: https://mkdev.me/posts/what-is-argo-cd-and-why-would-you-need-gitops
Video form: https://www.youtube.com/playlist?list=PLozcbFx8FoPHUHoKfuSrkMO0ulZD-CHHu
Article series: https://mkdev.me/posts/what-is-argo-cd-and-why-would-you-need-gitops
Video form: https://www.youtube.com/playlist?list=PLozcbFx8FoPHUHoKfuSrkMO0ulZD-CHHu
mkdev.me
ArgoCD & GitOps: Lightning Course for Kubernetes | mkdev
Dive into the introductory lesson of our ArgoCD Lightning Course. Designed for Kubernetes and Helm users, this article outlines ArgoCD's basics, explaining its role as a declarative GitOps deployment tool. Understand the difference between imperative and…
AWS Lambda and Google Cloud Functions have both evolved, but the main lesson from our pricing comparison remains relevant in 2026: serverless costs depend heavily on the shape of your workload.
Google’s second-generation Cloud Functions are now called Cloud Run functions and follow the Cloud Run pricing model. AWS Lambda continues to bill according to requests, execution duration and allocated resources.
Billing granularity, concurrency, architecture, region, networking and supporting services can all affect which platform is more economical.
Instead of asking which service is cheaper in general, ask which one is cheaper for your actual application.
Read the full article: https://mkdev.me/posts/aws-lambda-pricing-vs-google-cloud-functions-pricing-explained
Google’s second-generation Cloud Functions are now called Cloud Run functions and follow the Cloud Run pricing model. AWS Lambda continues to bill according to requests, execution duration and allocated resources.
Billing granularity, concurrency, architecture, region, networking and supporting services can all affect which platform is more economical.
Instead of asking which service is cheaper in general, ask which one is cheaper for your actual application.
Read the full article: https://mkdev.me/posts/aws-lambda-pricing-vs-google-cloud-functions-pricing-explained
mkdev.me
AWS Lambda vs. Google Cloud Functions: Price Comparison
It's not simple to understand the complexity in the pricing models of AWS Lambda and Google Cloud Functions, so Pablo Inigo Sanchez is here to explain it.
Is your AWS setup secure, cost-effective and built for reliable growth? mkdev’s In-Depth AWS Audit reviews your architecture, services and applications, then delivers practical recommendations and concrete backlog items. Check out the page and schedule a call: https://mkdev.me/b/audits/in-depth-aws-audit-and-assessment
mkdev.me
Amazon Web Services | mkdev audits for business
As part of Amazon Web Services audit and assessment, we take a deep review of your setup from security and high availability to cost and automation. We provide you with a detailed report on all the AWS services you are currently using
GPT models have become much better since the early days of ChatGPT, but one lesson from GenAI security has survived every generation: a prompt is not a security boundary.
Prompt injection remains one of OWASP’s major LLM risks, and agentic systems have increased the potential consequences because a manipulated model may now have tools, credentials and access to other systems.
That means securing an AI application cannot consist of writing an increasingly elaborate system prompt telling the model what it must never do.
Input and output validation, least-privilege permissions, secret management, logging, dependency controls and conventional application security still have to surround the model.
GPT-5.6 may be far more capable than the models developers were experimenting with a few years ago. The surrounding software still needs to assume that the model can make mistakes, misunderstand instructions or be manipulated.
https://mkdev.me/posts/don-t-let-cyber-risk-kill-your-genai-vibe-a-developer-s-guide
Prompt injection remains one of OWASP’s major LLM risks, and agentic systems have increased the potential consequences because a manipulated model may now have tools, credentials and access to other systems.
That means securing an AI application cannot consist of writing an increasingly elaborate system prompt telling the model what it must never do.
Input and output validation, least-privilege permissions, secret management, logging, dependency controls and conventional application security still have to surround the model.
GPT-5.6 may be far more capable than the models developers were experimenting with a few years ago. The surrounding software still needs to assume that the model can make mistakes, misunderstand instructions or be manipulated.
https://mkdev.me/posts/don-t-let-cyber-risk-kill-your-genai-vibe-a-developer-s-guide
mkdev.me
Navigating GenAI Cyber Risks: Guide for PMs | mkdev
The second article in the new series by Paul Larsen explains how GenAI-assisted coding can amplify existing cybersecurity risks and introduce new ones—like data leakage, insecure code, prompt injections, and malicious dependencies—while offering practical…
If networking still feels like a collection of acronyms, this one from the mkdev archives is worth revisiting.
It walks through switches, routers, DNS, DHCP, NAT, VPNs and more, with practical examples along the way.
Read the full article: https://mkdev.me/posts/how-networks-work-what-is-a-switch-router-dns-dhcp-nat-vpn-and-a-dozen-of-other-useful-things
It walks through switches, routers, DNS, DHCP, NAT, VPNs and more, with practical examples along the way.
Read the full article: https://mkdev.me/posts/how-networks-work-what-is-a-switch-router-dns-dhcp-nat-vpn-and-a-dozen-of-other-useful-things
mkdev.me
Networking Basics: Switches, Routers, DNS, DHCP, NAT & VPN
We'll figure out how networks work and solidify the knowledge in practice using libvirt and Linux networking. We'll learn everything: from bridges, switches and routers to tcpdump, NAT and VPN.
In the 96th mkdev dispatch, Pablo talks about what technology companies can learn from Spain’s football philosophy: competing with ambition, structure, creativity, and integrity to build systems that win for years instead of relying on shortcuts for short-term victories. Sign up for mkdev dispatch today!
https://mkdev.me/posts/you-don-t-win-by-cheating-96
https://mkdev.me/posts/you-don-t-win-by-cheating-96
mkdev.me
Integrity Wins: Tech Lessons from Spanish Football | mkdev
In the 96th mkdev dispatch, Pablo talks about what technology companies can learn from Spain’s football philosophy: competing with ambition, structure, creativity, and integrity to build systems that win for years instead of relying on shortcuts for short…
Moving data into AWS is usually the easy part. Moving it around — and eventually back out — is where the pricing becomes more interesting.
AWS currently gives customers 100 GB of data transfer out to the internet per month for free, aggregated across supported AWS services and Regions, excluding China and GovCloud. CloudFront also includes 1 TB of free data transfer out each month. Beyond that, outbound pricing varies by Region and volume.
Inside AWS, topology matters too. Crossing Availability Zones can create transfer charges, and moving data between Regions has pricing based on the source and destination Regions. A seemingly small architectural choice can therefore become significant once you are moving terabytes every day.
Caching, compression, CloudFront, VPC endpoints and simply understanding your application's traffic patterns can all make a difference.
We break down these costs and optimization options in our guide to AWS data transfer pricing.
https://mkdev.me/posts/understanding-aws-data-transfer-costs
AWS currently gives customers 100 GB of data transfer out to the internet per month for free, aggregated across supported AWS services and Regions, excluding China and GovCloud. CloudFront also includes 1 TB of free data transfer out each month. Beyond that, outbound pricing varies by Region and volume.
Inside AWS, topology matters too. Crossing Availability Zones can create transfer charges, and moving data between Regions has pricing based on the source and destination Regions. A seemingly small architectural choice can therefore become significant once you are moving terabytes every day.
Caching, compression, CloudFront, VPC endpoints and simply understanding your application's traffic patterns can all make a difference.
We break down these costs and optimization options in our guide to AWS data transfer pricing.
https://mkdev.me/posts/understanding-aws-data-transfer-costs
mkdev.me
AWS Data Transfer Costs: Pricing, Tips & Optimization
Worried about surprise AWS data transfer costs? Kirill Shirinkin breaks down where those charges come from and shares smart strategies to avoid them. Read this to stay in control of your cloud bill.
Logs, metrics and traces are only part of observability.
The real goal is understanding what happened, tracing problems across systems and making sure the right people get the right alerts — without alert fatigue.
Take a look at mkdev’s approach and arrange a call with us: https://mkdev.me/b/consulting/observability
The real goal is understanding what happened, tracing problems across systems and making sure the right people get the right alerts — without alert fatigue.
Take a look at mkdev’s approach and arrange a call with us: https://mkdev.me/b/consulting/observability
mkdev.me
Monitoring & Observability consulting for business | mkdev
Schedule a call to receive the Monitoring & Observability consultation from industry experts