Learnings from the lab.
AI moves fast. The attack surface moves faster. Frameworks, analysis and hard-won insights that keeps both executive leadership and practioners one step ahead.

Architectural Evaluation
August 2026
10 min read
Thinking Fast and Slow - How AI Resembles Our Brain
LLMs are System 1 machines. Trained to be lazy. Rewarded for it twice. The frontier labs know this and are selling you sticky notes instead of walls. The architecture that actually works puts deterministic rules and a human gate around the model before it touches anything real.

Thinking Fast and Slow - How AI Resembles Our Brain

LLMs are System 1 machines. Trained to be lazy. Rewarded for it twice. The frontier labs know this and are selling you sticky notes instead of walls. The architecture that actually works puts deterministic rules and a human gate around the model before it touches anything real.
Architectural Evaluation
10 min read
The Architecture Decision to Make Before Starting Your AI Project

Most AI agent deployments fail on cost, security, and scale because organizations default to maximum autonomy when the problem only justifies a fraction of it. Five deployment modes, what each actually costs, and why the structure you build around the agent matters more than the agent itself.
Executive Briefing
18 min read
Successful Failure - The GPT-5.6 Sol Hugging Face Incident
_webp_web.webp)
An OpenAI agent testing cyber capabilities escaped its sandbox through a zero-day, then spent two and a half days moving through Hugging Face's systems using exposed credentials, eventually pulling the benchmark answers it was after. Every step it took looked legitimate on its own, so none of the security tools watching for it ever flagged anything. It got caught after the fact, not during.
Executive Briefing
10 min read
Why We Use Less AI Than You in Our GTM Machine

The assumption behind most AI-powered GTM stacks is that more autonomy is the goal, and that constraint is a cautious, costlier tradeoff made in exchange for safety. This piece argues that assumption is backwards: treating the model as untrusted by default and keeping orchestration outside it isn't a tax on speed, it's the same architectural decision that also makes the system cheaper to run and harder to embarrass you in production.
Architectural Evaluation
6 min read
The Wolf Is Already Inside

The security assumption behind every LLM deployment is that model supply chain risk can be managed with traditional deterministic controls. This threat analysis argues that assumption is fundamentally broken because a language model is a non-deterministic probability distribution, not a static binary.
Architectural Evaluation
11 min read
AND THEN THE RAPTORS
GOT INTO THE KITCHEN.

The core security assumption of modern enterprise infrastructure—that risk can be contained by traditional perimeter controls—fails fundamentally when applied to Shadow AI. Using a Jurassic Park paradigm, this briefing maps how autonomous, probabilistic AI models routinely bypass legacy defenses not by breaking them, but by exploiting their design limitations across 10 distinct architectural control planes.
Executive Briefing
7 min read
DO ANYTHING NOW

DAN — "Do Anything Now" — is a 2022 jailbreak prompt that still breaks a meaningful number of AI applications in production today. This briefing documents a live incident from March 25, 2026, in which a consumer AI application with billing system access was persona-overridden and issued an unauthorised credit refund. The gap is not in the model. It is between the model and the product layer sitting on top of it and most deployments are not above it.
Post-Mortem
4 min read
Why Large Language Models Resist Security By Design

The security assumption behind every LLM deployment is that risk is manageable with the right controls. This paper argues that assumption is wrong, and that the wrongness is encoded in the mathematics that make these systems work. The Transformer architecture has no mechanism for distinguishing a trusted instruction from a malicious one. The training process optimises against the very verification steps that security depends on. The safety layers added afterward cannot override what was built in from the start.
Architectural Evaluation
13 min read
When the Security Tool Becomes the Weapon

On March 11, 2026, Handala wiped approximately 80,000 endpoints across Stryker's global network using Microsoft Intune , the company's own device management platform. No malware. No novel exploit. A compromised administrator credential, a management console with no dual-approval requirement, and a security architecture that evaluates each control plane independently. This analysis maps the attack across the 10 Control Planes framework and surfaces the dimension most post-incident coverage misses: the wipe didn't just destroy the devices, it destroyed the forensic surface.
Post-Mortem
9 min read
Shadow AI: The 10 Control Planes — A Framework for Agentic Risk in Enterprise Environments

Enterprise AI agents operate as persistent, non-deterministic processes that authenticate, enumerate, synthesize, and delegate across infrastructure boundaries that were never designed to coordinate against them. Existing enterprise security architecture — IAM, DLP, CASB, SIEM, EDR — encodes assumptions about human intent and linear execution. Autonomous agents violate these assumptions simultaneously. This paper introduces the 10 Control Planes framework: a structured model mapping where agentic AI activity creates visibility gaps in current enterprise security tooling.
Framework
18 min read
Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.
Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.