skip to content

Archive

AI controls, agent systems, banking governance, production practice. 409 essays, newest first.

  1. AI Controls Architecture

    Risk teams know risk. The open problem is designing controls for systems that are non-deterministic, probabilistic, and attackable in natural language.

  2. Governing Agents the Way Cells Govern Themselves

    Six cell biology mechanisms that reveal what the networking 'control plane' metaphor misses about governing AI agents.

  3. The Risk Without an Engineering Solution

    Every other agentic AI risk has an engineering answer. Prompt injection doesn't. That changes everything about how you design controls.

2026
  1. When Code Gets Cheap, Coordination Gets Expensive

    Coding agents move the bottleneck from implementation to shared intent.

  2. After Automation, Judgment Becomes Infrastructure

    When execution gets cheap, the scarce work moves to framing, review, and the systems that preserve judgment.

  3. What a port forgets

    Porting a tool's API ports its constraints. Design from the target environment's ideal, then reconcile against the source's primitives.

  4. What the receipts cost

    On the arithmetic and the binary in Susan Zhang's case for technologist careers.

  5. Recovery Is Not Control

    Fast repair is useful, but it does not prove that a system remains understandable.

  6. The Label Is Not the Risk

    AI governance needs domain knowledge where technical behaviour changes route, evidence, controls, and monitoring.

  7. The Agent Is Not the Control Point

    Finance agents are evidence custody systems before they are model systems.

  8. Govern the Workflow, Not the Model

    Agent governance cannot stop at model behavior. Once AI systems use tools, the governed object is the whole workflow.

  9. Autonomy Starts at the Check

    An agent is not autonomous because it can try a task. It is autonomous when the system can tell whether the task worked.

  10. Tool Health Is the Missing Layer of Agent-Native Apps

    Agent-native apps do not become trustworthy when an agent can call tools. They become trustworthy when the app can prove those tools worked.

  11. Unknown Is Not Low Risk

    Proportionate AI governance only works when the lighter path is earned by evidence, not granted by missing concerns.

  12. Published Is a Reader State

    A system has not published when the source is correct. It has published when the reader-facing surface is correct.

  13. A Garden Is Not a Changelog

    Recent work only becomes public writing when the claim survives the removal of the event that produced it.

  14. Latest Is a Race Condition

    In a concurrent agent system, verifying the latest artefact is not verification. It is a scheduling bet.

  15. Move the gate to the package manager

    When a supply chain attack lands and the timeline is asking for discipline, the durable fix is one layer down — at the package manager, not at your attention span.

  16. The check belongs at the trigger

    Corrections that fire by judgment drift; checks that fire by trigger don't. When your AI assistant keeps making the same mistake, move the gate.

  17. When defender news weakens the Ask

    Citing a vendor defender product in a paper that argues the threat surface is moving faster than controls undercuts the case it is supposed to support.

  18. The Thirty-Minute Fix for a Non-Existent Bug

    If you are about to assert that a tool isn't installed, run `which` first. The check is one line. The cost of skipping it is a half-hour of defensive scaffolding for a problem that wasn't there.

  19. Lint as Cartography

    The first time you run a quality gate against real data, the output is less about the gate and more about the data.

  20. Detect-and-Degrade

    When your tool depends on the host, declare the dependency at the gate. Don't wrap it. Don't patch around it.

  21. The missing layer between model risk and application security

    Model risk reviews the model. Application security reviews the application. Neither sits behind the agent at execution time, watching the verbs as they go out.

  22. Multi-persona AI review models the receiver, not the commission

    Persona-based AI reviews predict how stakeholders will react to a paper. They cannot tell you whether to act on those predictions, because the commissioning history is invisible to the lens.

  23. Legibility Precedes AI

    AI cannot help an enterprise that cannot describe itself, and governance failure surfaces faster than optimisation failure.

  24. Format is thinking discipline

    Compression did not simply shorten the notes. It sharpened them. Headers and bullets had been doing the thinking the prose was supposed to do.

  25. A framework rejection is not the end of the evaluation

    Forty thousand stars are voting on something. The framework verdict was correct. Closing the file was premature — the value still lives in the dependency tree.

  26. The engine is the policy

    A clever optimisation that was a silent regression. The override flags survived out of habit. None of the reasons survived contact with the actual numbers.

  27. Operating papers and board papers can't be the same document

    One paper for two audiences reads like leverage. It is actually a trap. The director commissions; the board governs a portfolio. They cannot read the same document.

  28. The Lens Trick: Why One AI Review Isn't Enough

    Five rounds of the same question produced diminishing returns by round three. Then I changed the question — same document, different reviewer.

  29. The OAuth Token You Forgot About

    Vercel was breached through a third-party AI tool's OAuth token. The lesson is not about Vercel's security — it is about how every AI tool you onboard extends your attack surface in ways your governance framework does not track.

  30. The Search-and-Replace Test for AI Governance

    If you can replace 'agent' with 'application' and the principle still reads fine, it was never about agents.