Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
AI

Writing on AI

AI governance, agents, AI security, and FinOps — for the CIOs, CISOs, and architects who have to ship.

More posts

6/26/2026 7 min

Bake the Audit Evidence Into Your AI Pipeline Before the Examiner Asks

Audit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its normal operation emits evidence as exhaust.

AIAI ComplianceAuditNIST AI RMF
6/24/2026 7 min

The 2026 AI Regulatory Map That Fits on One Page

Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part that fines you 3% of global revenue turns on in August. The four 2026 rules with teeth, on one page.

AIAI GovernanceComplianceNIST AI RMF
6/22/2026 8 min

Design Your AI Inference Like the Model Could Vanish Tomorrow, Because One Just Did

A frontier model went dark three days after launch; here's how I make AI inference survivable on AWS when the provider is a dependency you don't control.

AIAWSResilienceAI Infrastructure
6/20/2026 7 min

Your AI Bill Is the New Cloud Bill, and Nobody Is Watching the Meter

We spent a decade learning cloud FinOps and are repeating every mistake with LLM spend — here's the operating model that meters, routes, and caps it.

AIFinOpsCloud CostLLMOps
6/19/2026 7 min

Your Agents Already Outnumber Your People. Nobody Is Governing Their Credentials.

Your agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.

AINon-Human IdentityIAMCloud Security
6/17/2026 7 min

Stop Trying to Patch Prompt Injection

Prompt injection isn't a bug a vendor will patch — it's a property of how models read context, so design systems that stay safe even when the model is fully hijacked.

AIAI SecurityPrompt InjectionAppSec
6/16/2026 8 min

The Agent Is the Easy Part. The Control Plane Is the Job.

Standing up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.

AIAI AgentsSecurityPlatform Engineering
6/15/2026 7 min

Pick the Model Like You Size a Cluster, Not Like You Pick a Sports Team

Most teams pick a frontier model like a sports team and never revisit it — but model selection is a routing, capacity, and risk decision you already know how to make.

AIModel SelectionFinOpsInfrastructure
5/25/2026 6 min

Your Agent Dashboard Is Green and Lying to You

Uptime tiles tell you the service answered. They tell you nothing about whether the answer was right — and that gap is exactly where a model-risk review will eat you alive.

AI GovernanceObservabilityRisk ManagementFintech
5/18/2026 6 min

Shadow AI Is the New Shadow IT, and Your Prototype Graveyard Is Leaking Secrets

Every abandoned notebook, demo agent, and weekend prototype is a credential-bearing asset nobody owns. The fix isn't a ban — it's a discovery-and-demotion program with a real sunset workflow.

AI SecurityShadow ITDevOpsFintech
5/11/2026 6 min

When Three Tools Report Three Token Counts, You Can't Attest to Any of Them

If Codex says one number, Claude says another, and your gateway says a third, you don't have a metering problem. You have an attestation problem — and in regulated industries, that's the one you can't afford.

AI GovernanceFintechDevOpsCloud Security
4/20/2026 6 min

Vendor Concentration Risk in the Age of the Three-Lab AI Stack

Most of the AI in your roadmap traces back to three labs running on the same chips, the same supply chain, and increasingly the same balance sheets. That's not a feature. That's a concentration risk your board hasn't priced yet.

AI GovernanceVendor RiskBoard StrategyResilience
4/17/2026 4 min

What AI Actually Changes for Attackers (and What It Doesn't)

Cutting through the threat inflation: what genuinely shifts for attackers, what doesn't, and where to harden.

AIThreat IntelligencePhishingDefense
4/8/2026 7 min

Make Your Enterprise Agent-Readable Before You Buy Another Agent

Everyone is racing to buy agents. Almost no one is building the substrate that lets agents act safely. The productivity is real — but so is the blast radius you're about to hand out.

AI AgentsPlatform EngineeringSecurityFintech
4/6/2026 6 min

Dark Code Is a Control Failure, Not Tech Debt

AI is filling our repos with code nobody can explain. We keep calling it tech debt. It's actually a control failure — and it should fail CI for the same reason a missing approver does.

AI GovernanceDevOpsSoftware Supply ChainFintech
3/23/2026 6 min

AI Found 271 Bugs in Firefox. What Happens When It Reads Your Repos?

When AI-assisted fuzzing starts finding hundreds of bugs in hardened open-source code, the question isn't whether the technique works. It's whether you're running it before someone else runs it against you.

AI SecurityDevOpsVulnerability ManagementFintech
3/18/2026 6 min

The Source-Map Leak Is Your Build Pipeline's Confession

A single packaging mistake can publish hundreds of thousands of lines of your internals to a public registry. The leak isn't the bug — it's the confession that your release controls never caught up to your release velocity.

AI SecurityDevOpsSupply ChainFintech
3/16/2026 7 min

A Shadow-Agent Discovery Playbook for Regulated FIs

Unsanctioned AI agents are already running inside your environment with your credentials. Here's how to find, classify, and gate them before they touch member data — mapped to the controls your examiners and auditors already expect.

AI SecurityAI GovernanceFintechRisk Management
3/11/2026 3 min

Automate the Boring, Not the Judgment

A framework for what security work to hand to machines, and the line you should never let automation cross.

Security OperationsAutomationAITeam Building
3/4/2026 6 min

An AI Agent Dropped Prod. Here's the Change-Management Playbook.

Coding agents are now committing real change to real systems. The question isn't whether to let them — it's how to give them speed without handing them a SOC 2-fatal mistake.

AI GovernanceDevOpsComplianceFintech
3/2/2026 6 min

Stop Prompting Your Agents to Behave. Engineer the Blast Radius.

Most agent "safety" is a politely worded request to a model that doesn't have to honor it. In fintech, the only controls that count are the ones that hold after the model is wrong.

AI AgentsFintechCloud SecurityDevOps
2/25/2026 6 min

Your Browser Agent Has Your Cookies, and Your DLP Never Saw It

Browser-resident AI agents don't request access to your systems. They inherit it — from the authenticated sessions already sitting in your tabs. That's the threat model nobody provisioned for.

AI SecurityIdentityShadow ITFintech
2/23/2026 6 min

Agent Memory Is a Data-Residency Problem Wearing a Productivity Costume

Give every agent a durable, MCP-connected brain and you haven't just bought productivity — you've quietly stood up a new data lake full of PII and PCI scope that nobody classified, nobody encrypted, and nobody can purge.

AI GovernanceData ProtectionFintechDevOps
2/16/2026 6 min

Anchoring Bias Is Already in Your KYC Agent

The same structural failure modes that made medical LLMs unsafe are sitting quietly inside your fraud, dispute, and onboarding agents. They don't announce themselves. You have to go hunt them.

AI SecurityFintechRisk ManagementLLM Evals
2/12/2026 6 min

Onboarding Your Agents Was Easy. Nobody Built the Offboarding.

Every team has a story about the AI agent they shipped in a weekend. Almost none of them can tell you how that agent gets fired, what credentials it still holds, or who would notice if it went rogue.

AI AgentsNon-Human IdentityIdentity SecurityFintech