Archive
AI controls, agent systems, banking governance, production practice. 409 essays, newest first.
- AI Controls Architecture
Risk teams know risk. The open problem is designing controls for systems that are non-deterministic, probabilistic, and attackable in natural language.
- Governing Agents the Way Cells Govern Themselves
Six cell biology mechanisms that reveal what the networking 'control plane' metaphor misses about governing AI agents.
- The Risk Without an Engineering Solution
Every other agentic AI risk has an engineering answer. Prompt injection doesn't. That changes everything about how you design controls.
- When Code Gets Cheap, Coordination Gets Expensive
Coding agents move the bottleneck from implementation to shared intent.
- After Automation, Judgment Becomes Infrastructure
When execution gets cheap, the scarce work moves to framing, review, and the systems that preserve judgment.
- What a port forgets
Porting a tool's API ports its constraints. Design from the target environment's ideal, then reconcile against the source's primitives.
- What the receipts cost
On the arithmetic and the binary in Susan Zhang's case for technologist careers.
- Recovery Is Not Control
Fast repair is useful, but it does not prove that a system remains understandable.
- The Label Is Not the Risk
AI governance needs domain knowledge where technical behaviour changes route, evidence, controls, and monitoring.
- The Agent Is Not the Control Point
Finance agents are evidence custody systems before they are model systems.
- Govern the Workflow, Not the Model
Agent governance cannot stop at model behavior. Once AI systems use tools, the governed object is the whole workflow.
- Autonomy Starts at the Check
An agent is not autonomous because it can try a task. It is autonomous when the system can tell whether the task worked.
- Tool Health Is the Missing Layer of Agent-Native Apps
Agent-native apps do not become trustworthy when an agent can call tools. They become trustworthy when the app can prove those tools worked.
- Unknown Is Not Low Risk
Proportionate AI governance only works when the lighter path is earned by evidence, not granted by missing concerns.
- Published Is a Reader State
A system has not published when the source is correct. It has published when the reader-facing surface is correct.
- A Garden Is Not a Changelog
Recent work only becomes public writing when the claim survives the removal of the event that produced it.
- Latest Is a Race Condition
In a concurrent agent system, verifying the latest artefact is not verification. It is a scheduling bet.
- Move the gate to the package manager
When a supply chain attack lands and the timeline is asking for discipline, the durable fix is one layer down — at the package manager, not at your attention span.
- The check belongs at the trigger
Corrections that fire by judgment drift; checks that fire by trigger don't. When your AI assistant keeps making the same mistake, move the gate.
- When defender news weakens the Ask
Citing a vendor defender product in a paper that argues the threat surface is moving faster than controls undercuts the case it is supposed to support.
- The Thirty-Minute Fix for a Non-Existent Bug
If you are about to assert that a tool isn't installed, run `which` first. The check is one line. The cost of skipping it is a half-hour of defensive scaffolding for a problem that wasn't there.
- Lint as Cartography
The first time you run a quality gate against real data, the output is less about the gate and more about the data.
- Detect-and-Degrade
When your tool depends on the host, declare the dependency at the gate. Don't wrap it. Don't patch around it.
- The missing layer between model risk and application security
Model risk reviews the model. Application security reviews the application. Neither sits behind the agent at execution time, watching the verbs as they go out.
- Multi-persona AI review models the receiver, not the commission
Persona-based AI reviews predict how stakeholders will react to a paper. They cannot tell you whether to act on those predictions, because the commissioning history is invisible to the lens.
- Legibility Precedes AI
AI cannot help an enterprise that cannot describe itself, and governance failure surfaces faster than optimisation failure.
- Format is thinking discipline
Compression did not simply shorten the notes. It sharpened them. Headers and bullets had been doing the thinking the prose was supposed to do.
- A framework rejection is not the end of the evaluation
Forty thousand stars are voting on something. The framework verdict was correct. Closing the file was premature — the value still lives in the dependency tree.
- The engine is the policy
A clever optimisation that was a silent regression. The override flags survived out of habit. None of the reasons survived contact with the actual numbers.
- Operating papers and board papers can't be the same document
One paper for two audiences reads like leverage. It is actually a trap. The director commissions; the board governs a portfolio. They cannot read the same document.
- The Lens Trick: Why One AI Review Isn't Enough
Five rounds of the same question produced diminishing returns by round three. Then I changed the question — same document, different reviewer.
- The OAuth Token You Forgot About
Vercel was breached through a third-party AI tool's OAuth token. The lesson is not about Vercel's security — it is about how every AI tool you onboard extends your attack surface in ways your governance framework does not track.
- The Search-and-Replace Test for AI Governance
If you can replace 'agent' with 'application' and the principle still reads fine, it was never about agents.