5 essays

Writing

Essays on where AI governance is actually going, why most of it has no teeth yet, and which parts of security practice transfer straight across. Written for people who have to make the decision, not for people scoring it.

AI Security Isn't a Feature. It's the Whole Game Now.
May 9, 2026AI Security Isn't a Feature. It's the Whole Game Now.Zero-click prompt injection on production LLMs, why prompt injection is architectural not patchable, securing RAG and MCP, excessive agency as least privilege, governance with enforcement, and operating at machine speed.AI · Security · Prompt Injection
Slowness Is the Vulnerability Nobody Patches
April 24, 2026Slowness Is the Vulnerability Nobody PatchesTime is the real attack surface now. Why MTTD/MTTR are existential, how to move from spatial to temporal architecture, where to automate without blowing up like CrowdStrike, and what to actually measure when the adversary runs at machine speed.AI · Security · SOC
The Philosophy Problem Nobody in AI Security Wants to Talk About
April 7, 2026The Philosophy Problem Nobody in AI Security Wants to Talk AboutWhy AI security debates keep hitting philosophical fault lines: undefined agent identity, probabilistic truth, non-deterministic behaviour, and governance models that still assume predictable human-operated systems.AI · Security · Governance
AI Governance Without Teeth Is Just Theatre
March 30, 2026AI Governance Without Teeth Is Just TheatreWhy most AI governance is a PDF nobody reads, and what operational governance — enforcement gates, AI inventories, zero trust for agents, and prompt injection playbooks — looks like in practice.AI · Governance · Security
Building an AI Navigator for ISO 27001 and NIST CSF 2.0: Fine-Tuning, RAG, and Why Precision Isn't Optional
March 23, 2026Building an AI Navigator for ISO 27001 and NIST CSF 2.0: Fine-Tuning, RAG, and Why Precision Isn't OptionalHow I fine-tuned LLaMA 8B and 70B on ISO 27001:2022 and NIST CSF 2.0, built a three-pass RAG pipeline with a semantic control ID resolver, and why AI in GRC demands a different standard of accuracy than almost any other domain.AI · Security · ISO 27001 · NIST CSF · Fine-Tuning · RAG · GRC