Blog

The thinking behind AI security review.

Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.

Newsletter

New posts in your inbox,
when they publish.

Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.

No spam. Unsubscribe anytime.

Foundations9 min

Clearance vs approval — why the distinction matters for AI governance

Security clearance and business approval are separate gates. Conflating them produces systems that are approved but not cleared.

Regulation8 min

Is your AI system high-risk under the EU AI Act? How to find out

Determine whether your AI system is high-risk under the EU AI Act's Annex III categories and what that classification requires.

Regulation10 min

An AI Risk Disposition that holds up in regulator review

Most risk dispositions are written for internal approval. What must change so they survive external regulator scrutiny.

Technical12 min

Security review for fine-tuned models — what changes from base model assessment

Fine-tuned models inherit base-model risk and add training data provenance, alignment drift, and capability overhang concerns.

Technical13 min

Why your existing threat modeling tool doesn't model agents

STRIDE and commercial tools model deterministic software. Agents have five properties they can't represent -- each one an attack surface.

Reference10 min

Assessing third-party AI vendors — the questions procurement skips

AI vendor risk assessment beyond SOC 2: model governance, incident notification, and the evidence to re-assess when vendors change models.

Worked example12 min

A worked example: AI Risk Disposition for a Copilot Studio procurement agent

A full worked example: every disposition section filled in for a Copilot Studio procurement agent. Decision, controls, residual risk, sign-off.

Technical11 min

Threat modeling an MCP server — the parts AppSec tools miss

MCP servers have four attack surfaces: transport, tool surface, context injection, auth boundary. AppSec tools model one. The full threat model.

Regulation13 min

EU AI Act Article 9 risk management — what evidence is required

Article 9 requires a risk management system for high-risk AI. Six requirements translated into evidence artefacts auditors will request.

Reference14 min

OWASP Agentic Top 10 mapped to required controls

OWASP Agentic Top 10 threats mapped to controls, lifecycle gates, and evidence -- a working checklist for your AI Committee, not just a list.

Foundations11 min

What an AI Risk Disposition actually contains

AI Committees approve systems they can't defend later. The Risk Disposition memo fixes this -- section by section, with real examples.

Governance11 min

What an agentic AI audit trail must capture

Auditing an agentic system post-incident requires what the model decided and why — not just what happened. Most implementations miss the reasoning trace.