What I've learned doing this work, written for people who ship.
AI SECURITY
July 2026
Three findings from July 2026 define the new AI attack surface: 36% of agent skills carry prompt injection payloads, low-skilled attackers breached 14 companies using AI as their toolkit, and a design-level MCP vulnerability left 200,000+ AI servers exposed to RCE.
Read Article →
ASSESSMENT
2026
Five findings from a static source code analysis of an open-source AI agent orchestration platform. Mapped to OWASP LLM Top 10 (2025) and MITRE ATLAS, with prioritized remediation recommendations.
Read Article →
AI SAFETY
2025
Patterns from analyzing AI incidents, testing AI systems, and evaluating model outputs daily. Most failures aren't sophisticated attacks. They're preventable. Someone just didn't ask the right questions.
Read Article →
CHECKLIST
2025
27 questions compiled from analyzing AI incidents and observing what separates successful deployments from failures. Drawn from security research and reverse-engineering what should have been asked before launch.
Read Article →
OBSERVATIONS
2025
I evaluate AI outputs from frontier models daily. Here's what actually works, what doesn't, and what the hype misses. The truth is more nuanced than either the AI doom or the AI utopia narratives.
Read Article →