How this site is produced
Emerging Tech Risk is a technology-risk research publication for financial-services risk, governance, and technology professionals. Everything on it is built from public information, and the code and data behind every project are open.
What is here
The site has two kinds of content. Readiness Signal is a filtered archive of technology-risk developments relevant to the financial sector — cyber, fraud, artificial intelligence, data, operational resilience, third-party risk, and risk quantification. It is a filter, not a feed: it publishes only what clears a deliberately high materiality bar. The other projects are reference dashboards and briefings on frontier AI risk, cyber and technology risk quantification, and the post-quantum cryptography transition. They are point-in-time assessments of fast-moving areas and are labeled as prototypes.
Sources
Readiness Signal reads only public sources, listed by class in a source registry published in its repository (pipeline/sources.json): regulators and supervisory bodies, standards bodies, industry and trade bodies, vendor threat research, research and analysis, and established news outlets. Paywalled publications are used for headline and lead-level reference only; their body text is never fetched, quoted, or paraphrased. Every published item links to its source.
Editorial process
Each run follows a binding selection standard (pipeline/FILTER.md) and runbook (pipeline/RUNBOOK.md), both in the repository. Runs are scheduled four times a day, at 06:00, 10:00, 14:00, and 18:00 Eastern. In brief: candidates are collected from the registry; a domain-relevance gate removes the clearly irrelevant; every survivor is judged against the section tests and checked for duplicates; each admitted item is tagged with exactly one mechanism — a candidate issue, a KRI/KPI, PRAF coverage, or awareness only; and the result is validated mechanically before it is appended. When nothing clears, the run is silent. Every run, published or silent, is logged with its funnel. The archive is append-only, so editions are never overwritten.
Automation and human review
Fetching, drafting, and verification are automated under the standard above, with the process, prompts, and logs open for inspection. The standard itself, the source allowlist, and the selection thresholds are the responsibility of the author, who reviews the record and corrects it when it is wrong.
Independence
This is a personal research project. It is not affiliated with, sponsored by, or reviewed by any employer, former employer, or regulator, and it does not represent the views of any organization. There is no advertising, no sponsorship, and no commercial relationship with any source or vendor mentioned.
Limits
The record reflects what its allowlisted sources published, when they published it. It is not comprehensive, it is not real time, and an item's absence means nothing. Assessments are stated with an explicit confidence level and should be read as one practitioner's reading of the public record, not as advice for any particular organization.