PROTINTEL petr.hummel@protintel.com

A notebook, not a brochure

I take things apart to understand them.

Neural networks in 2001, to see how they learn. AI systems now, to see what they did and why - and what it takes for them to hold up under inspection. What I find ends up here, in talks, and in the reading list at the bottom.

Prague · in-house by day; the talks and the writing are my own.

Taking apart

2001

A neural network, watched while it learns

My master's thesis: self-organizing networks with every step of the learning drawn on screen, so you could see the map form instead of trusting the numbers. Rebuilt for the browser with verification notes. The 2001 look was kept on purpose.

Twenty-five years later the question is the same, only the networks are bigger and nobody draws the learning any more.

2026

The AI Act, read line by line

876 rows, each traced to the article it comes from. What is left when you do that is not a checklist. It is three questions, in the order the Act itself asks them: know and govern · build and prove · run and respond. Everything else is a row under one of the three.

What surprised me most: how much of the work is deciding, per system, which rows apply at all - and how little of it is the rows themselves.

Vocabulary

Three words that get used for one thing

Triage sorts by how bad it would be if it failed - no likelihood, no controls, minutes. Assessment asks how likely, what to do about it, and what is left afterwards - days. Assurance asks whether what you did actually works - tested, not estimated.

Most arguments about "AI risk" are three people using one word for three different things. Name the level first; the argument usually ends.

“Nobody has AI under control. The work is not to chase reliability but to manage unreliability. The way we already do with people: checks, second readings, recertification.”

Work

2021 → 2023
E-health platform and a digital production line for blood-sampling kits - built and run in production for a regulated laboratory group; kits notified with SÚKL.
2020 → 2024
ISMS certified to ISO/IEC 27001 with 27701 - designed, run and certified (DNV, UKAS) for my own consulting firm.
2025 · 2026
Kyberprostor na hraně zákona - cybersecurity conference for students, initiated and co-organised; 2026 hosted by FEL CTU.
Talks 2026
CZECRIN Brno · Czech Electrotechnical Association, Mikulov · AMPER Brno · Czech Accreditation Institute, Prague (October) - on AI and clinical data, a CEO blackmailed by AI, ransomware negotiations, and classifying AI systems so that an assessor can follow the trail.

What I read, and why

Karpathy
karpathy.ai - the clearest explanations of what these models actually are. When he changes his mind, I re-read.
System cards
The frontier labs' own system cards - the primary source on what a model was built to do and where it was tested; a biased witness on dates, an honest one on intent.
METR
metr.org - measures what models can do over long tasks, which is the number that decides what an organisation should let them do alone.
Epoch AI
epoch.ai - the trend lines: compute, cost, capability. Planning horizons come from here, not from press releases.
AI Office · NÚKIB
Guidance from the European AI Office and NÚKIB - what the regulators say they will look for, in their own words, before anyone else paraphrases it.

Five sources, on purpose. The output of reading them is a note here or a change in a talk - not a folder.