Quick take: Today’s developments are less about invention than about whether institutions can make technology answerable to human needs. A valve adapts to a growing child; proposed rules invite scrutiny before markets and platforms harden; and a serious breach shows why a warning without accountable follow-through is not protection.
A heart valve can now be enlarged as a child grows
On 1 October, the US Food and Drug Administration approved the Autus Size-Adjustable Valve, the first pulmonary heart valve designed to be expanded after implantation as a child grows. A balloon catheter can widen it from roughly 13 to 22 millimetres, potentially replacing some repeat open-heart operations with less invasive procedures. The pivotal study enrolled 62 children; early blood-flow performance was acceptable, and two valves were successfully enlarged when their recipients began to outgrow them. That is a meaningful engineering response to a child’s changing body. But the evidence is still small and short-term. Three frame fractures and two cases of reduced leaflet movement occurred without symptoms, and patients will be followed for ten years. Families should not read “grows with the child” as “lasts for life.” A realistic action is to ask a congenital-heart team about eligibility, centre experience, follow-up obligations and what evidence would still trigger replacement. Independent clinical context.
Possible Alkemata article: Designing Medical Devices for Bodies That Change
Europe opens its proposed child-safety rules to public scrutiny
The materially new step is participatory: on 2 October, the European Commission opened feedback on the proposed EU Kids Act until 26 November. The September proposal would set an EU-wide age of 15 for autonomous accounts on specified social and video platforms, require safety-by-design measures and use privacy-preserving age assurance. A common rule could reduce the current patchwork and move responsibility away from children finding the right setting. The danger lies in implementation: age checks can become surveillance, blunt account restrictions can displace vulnerable young people into less visible spaces, and formal compliance can leave recommender systems unchanged. The proposal is not yet law, and feedback is not a vote; Parliament and the Council will decide its final shape. Children, parents, teachers and civil-society groups can act now by submitting concrete scenarios—what data an age check should never retain, how appeals should work and which safety outcome should be independently measured.
Possible Alkemata article: How to Test an EU Child-Safety Rule Before It Becomes Law
US regulators begin writing rules for leveraged retail crypto trading
On 5 October, the US Commodity Futures Trading Commission issued an advance notice of proposed rulemaking for leveraged and margined retail crypto transactions. It asks whether a purpose-built “crypto asset market” category could bring exchanges into a uniform federal regime and prevent abusive practices before losses occur. The promise is a clearer route for supervision where leverage can turn a price move into a rapid liquidation. The limit is equally important: this is an information-gathering stage, not a final consumer-protection rule, and the agency says broader authority still depends on Congress. A federal pathway could improve disclosure and custody standards, but it could also lend legitimacy to products whose risks remain difficult for ordinary users to price. Individuals should not interpret consultation as endorsement. Anyone considering leveraged crypto can check liquidation mechanics, custody, conflicts and complaint routes—and assume the entire stake can disappear. Written comments are due within 60 days of Federal Register publication. Independent report.
Possible Alkemata article: What Consumer Protection Must Explain Before Crypto Leverage Is Sold
The FBI breach becomes a lesson in accountable patching
A breach disclosed in September now has a materially clearer cause. On 5 October, the FBI said a contractor failed to install an explicitly issued security patch on a third-party-managed platform; the bureau removed the contractor and said it had taken steps to limit further risk. Reuters identified the provider as Accenture and the platform as Oracle PeopleSoft, citing two sources; neither identification was made by the FBI. The intrusion exposed sensitive details of thousands of employees, reportedly including addresses, medical records and descriptions of counterintelligence work. The useful lesson is not “patch faster” in isolation. Enterprise updates need named ownership, tested maintenance windows, proof of deployment and escalation when deadlines slip. The remaining uncertainty is the breach’s full scope and whether the vulnerable system was adequately segmented. Individuals cannot repair institutional governance, but staff and suppliers can ask who verifies critical patches, preserve breach notices and use credit or identity monitoring when offered. The FBI’s earlier statement.
Possible Alkemata article: A Warning Is Only Real When Someone Can Act