Point of view · Jul 2026
You Made an AI Policy. So Now What?
A policy is not governance. The five ways an AI council fails, mapped to Lencioni's five dysfunctions, and the cheapest fix available before its next meeting.
Read →Media
Point of view · Jul 2026
A policy is not governance. The five ways an AI council fails, mapped to Lencioni's five dysfunctions, and the cheapest fix available before its next meeting.
Read →Point of view · Jun 2026
A control framework tells you what to do. Whether a healthcare organization can actually do it is a question of people, ownership, and maturity.
Read →Point of view · Jun 2026
Policy borrows patch-management language for AI systems. But fine-tuning, retraining, and weight editing are not patches, and the difference matters.
Read →Research · May 2026
Our SPIE DS26 paper ran 14,850 evaluations across five model families and three quantization tiers. Temperature is the safety variable to watch.
Read →Point of view · Feb 2026
Chinese labs drained Claude's intelligence with 16 million automated exchanges. The AI industry has an operational maturity problem, not just a security one.
Read →Field notes · Jan 2026
A look back at our first year: research at the NATO IST-210 symposium, CAMLIS, BSides Las Vegas and SPIE DCS, and where we take it next.
Read →Research · Nov 2025
AI fails in ways firewalls cannot see: data poisoning, model theft, prompt injection. The three layers of a deliberate offensive AI security strategy.
Read →Point of view · Nov 2025
Developers once fought over whether IDEs were cheating. Now it is AI assistants. What automation research says about losing the fundamentals.
Read →Research · Jun 2025
Our research on how attackers exploit every stage of a RAG pipeline, from poisoned vector stores to leaked prompts, and the controls that stop them.
Read →Point of view · Apr 2025
The industry is racing to bolt security onto AI systems that were never designed to be safe. Securing an unsafe system is the wrong place to start.
Read →Research · Apr 2025
An independent Future of Life Institute assessment graded leading AI companies on safety, and no vendor scored above a C. The vendor's risk becomes yours.
Read →