Blog

The thinking behind AI security review.

Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.

Newsletter

New posts in your inbox,
when they publish.

Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.

No spam. Unsubscribe anytime.

Foundations9 min

Scoping an AI security review without boiling the ocean

Scope an AI security review to the decision you need: the system, the deployment context, and the pass/fail threshold.

Governance10 min

The restricted-pilot pattern for risky AI systems

A restricted pilot is a formal disposition: defined scope, named controls, explicit re-review triggers. How to write one that holds.

Regulation10 min

AI subprocessor risk in your vendor chain

When a vendor's AI runs on a third-party model provider, that provider is a subprocessor. Retention, training, and transfer risks your DPA missed.

Reference11 min

AI risk assessment under ISO 42001

ISO 42001 requires a documented AI risk assessment. What it must cover, how it differs from IT risk assessments, and what complete looks like.

Technical9 min

Transport security for MCP servers

MCP runs over HTTP/SSE or stdio — each with distinct security requirements. Covers TLS, mutual auth, and transport review questions.

Technical12 min

Indirect prompt injection through retrieved documents

Indirect injection via retrieved documents is harder to detect than direct — the attacker is in the knowledge base, not the conversation.

Regulation12 min

The technical documentation the EU AI Act expects

Annex IV defines what technical documentation high-risk AI needs before market placement. What it requires, what it means, and the common gaps.

Technical11 min

Agent memory as an attack surface

Agents with persistent memory carry forward context that can be poisoned. A past interaction plants instructions that execute in future sessions.

Technical11 min

Sensitive information disclosure in LLM applications

LLMs leak data through three channels: training memorisation, system prompt leakage, and retrieval boundary failures. Each needs distinct controls.

Foundations10 min

AI security review vs penetration testing — different questions

A pentest asks if a system can be exploited. A security review asks if it should ship and under what conditions. Both needed.

Governance10 min

Conditional approval for AI systems — making conditions stick

Conditional approval is the most common AI disposition. Most are written so the conditions can't be enforced. How to make them stick.

Governance9 min

Model-change notification — the vendor clause procurement teams forget

Vendors swap models without notice, invalidating your security review. The contractual clause and review trigger that keeps assessments current.