Blog

The thinking behind AI security review.

Threat models, governance evidence, and the decisions that hold up under scrutiny. Written for security architects and the committees they report to.

Newsletter

New posts in your inbox,
when they publish.

Threat modeling, governance evidence, and what AI Committees actually need — written for security architects and AI governance leads. No cadence promises.

No spam. Unsubscribe anytime.

Regulation10 min

The EU AI Act timeline and what to prepare first

EU AI Act provisions apply in phases. Which obligations hit when, and the preparation steps that deliver value first.

Regulation12 min

Running RAG over regulated data — the review checklist

RAG over GDPR, HIPAA, or financial data needs controls at data, retrieval, and output layers. Checklist mapped by data class with evidence requirements.

Reference14 min

The OWASP Agentic Top 10, explained for security reviewers

OWASP Agentic Top 10 explained for practitioners: each threat category with actionable controls and evidence requirements a security reviewer can use.

Technical10 min

System prompt leakage and why it matters for security

System prompts encode trust assumptions, scoping rules, and sometimes credentials. When they leak, the system's entire trust model is exposed.

Foundations9 min

A lightweight AI security review for fast-moving teams

Minimum-viable AI security review for fast-moving teams: three questions, three artefacts, one decision record.

Foundations10 min

What makes an AI decision record defensible

A defensible decision record lets a regulator understand what was decided and why -- without the people who made it. The required standard.

Regulation10 min

Reviewing how an AI vendor handles your data

Is your data used for training? Who accesses it? Where is it stored? The DPA rarely answers these. The data-handling review for AI vendors.

Reference12 min

NIST AI RMF vs ISO 42001 — Which Framework to Choose

NIST AI RMF vs ISO 42001: the two leading AI governance frameworks compared across structure, certification, and evidence.

Technical10 min

Securing an internal MCP server exposed to agents

Internal MCP servers exposing tools, databases, or APIs to agents have different security requirements than public ones. The review checklist.

Regulation11 min

General-purpose AI obligations under the EU AI Act

GPAI provisions create obligations for foundation model providers. What they mean and what deployers of GPAI-powered systems need to know.

Technical11 min

Evaluating a RAG pipeline for security, not just relevance

RAG evaluation frameworks measure relevance. Security evaluation asks: what boundaries are crossed, what can be extracted, and what enforces the scope?

Technical12 min

Agentic AI Privilege Escalation — 5 Attack Paths

Agentic privilege escalation needs no kernel exploit — just a model convinced to invoke unintended tools. Maps escalation paths and blocking controls.