Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
Topic

AI Security

Writing on AI security: agent credentials and non-human identity, deepfake voice fraud, shadow AI, control-plane gaps, and vendor claims worth auditing.

Where AI meets the security program: agent credentials that already outnumber your people, deepfake voice fraud against authentication, the shadow-AI line between personal tools and unreviewed production systems, and what "we don't train on your data" actually buys you. The lens is a fintech security team defending real workloads, not lab demos.

20 posts, newest first

Jul 21, 2026 9 min

'We Don't Train on Your Data' Is Not Enough

An agent told to open no files obeyed — while the product uploaded the whole repo, canary included. "We don't train on your data" answers the wrong question.

AIAI SecurityAI GovernanceFintech
Jul 20, 2026 9 min

A Convincing Voice Is Not Authenticated

A cloned voice with matching caller-ID is recognition, not authentication. Move trust onto channels you control: callback on record, dual authorization.

AIAI SecurityFraudDeepfakesFintech
Jul 18, 2026 8 min

Your Prompt Is the Approval. That's the Gap.

An MCP connector executes writes with no approval screen — your prompt becomes the one boundary nobody governed. That missing gate is a control-plane gap.

AIAI AgentsAI SecurityAI GovernanceNon-Human IdentityFintech
Jul 9, 2026 10 min

Shadow AI: Your "Personal Tool" Is Production

A coding agent stands up a data-touching tool in an afternoon. The moment it needs a login or gets shared, it's a production system nobody reviewed.

AIAI GovernanceAI AgentsSecurityGRC
Jun 28, 2026 13 min

Why We Built AgentOS

One model scored 78% in one agent harness and 42% in another. In regulated fintech the harness is where governance lives, so we built our own: AgentOS.

AIAI AgentsAI GovernanceSecurityFintech
Jun 20, 2026 7 min

Nobody Is Governing Your Agents' Credentials

Your agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.

AINon-Human IdentityIAMCloud Security
Jun 18, 2026 7 min

Stop Trying to Patch Prompt Injection

Prompt injection isn't a bug a vendor will patch — it's a property of how models read context. Design systems that stay safe even when the model is hijacked.

AIAI SecurityPrompt InjectionAppSec
Jun 17, 2026 8 min

The Control Plane Is the Job

Standing up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.

AIAI AgentsSecurityPlatform Engineering
May 19, 2026 6 min

Shadow AI Is the New Shadow IT

Every abandoned notebook and weekend prototype is a credential-bearing asset nobody owns. The fix isn't a ban — it's discovery, demotion, and real sunsets.

AI SecurityShadow ITDevOpsFintech
May 12, 2026 6 min

Three Token Counts, Zero You Can Attest To

Codex says one number, Claude another, your gateway a third. That isn't a metering problem — it's an attestation problem regulated industries can't afford.

AI GovernanceFintechDevOpsCloud Security
Apr 18, 2026 4 min

What AI Actually Changes for Attackers

Cutting through the threat inflation: what AI genuinely changes for attackers, what it doesn't, and where a defender's hardening effort actually pays off.

AIThreat IntelligencePhishingDefense
Apr 9, 2026 7 min

Make Your Enterprise Agent-Readable First

Everyone is racing to buy agents; almost no one builds the substrate that lets them act safely. The productivity is real — so is the blast radius.

AI AgentsPlatform EngineeringSecurityFintech
Mar 24, 2026 6 min

AI Found 271 Bugs in Firefox. Now Your Repos?

AI-assisted fuzzing found hundreds of bugs in hardened open-source code. The question is whether you run it before someone else runs it against you.

AI SecurityDevOpsVulnerability ManagementFintech
Mar 19, 2026 6 min

Source-Map Leaks: Your Pipeline's Confession

One packaging mistake can publish hundreds of thousands of lines of internals. The leak is a confession: release controls never caught up to release velocity.

AI SecurityDevOpsSupply ChainFintech
Mar 17, 2026 7 min

Shadow-Agent Discovery for Regulated FIs

Unsanctioned AI agents already run in your environment with your credentials. Find, classify, and gate them before they touch member data or an exam does.

AI SecurityAI GovernanceFintechRisk Management
Mar 12, 2026 3 min

Automate the Boring, Not the Judgment

A framework for deciding which security work to hand to machines — and the judgment line you should never let automation cross, no matter the headcount math.

Security OperationsAutomationAITeam Building
Mar 3, 2026 6 min

Agent Safety: Engineer the Blast Radius

Most agent "safety" is a politely worded request to a model that need not honor it. The only controls that count still hold after the model goes wrong.

AI AgentsFintechCloud SecurityDevOps
Feb 26, 2026 6 min

Your Browser Agent Has Your Cookies

Browser AI agents don't request access to your systems — they inherit it from the authenticated sessions in your tabs. A threat model nobody provisioned for.

AI SecurityIdentityShadow ITFintech
Feb 17, 2026 6 min

Anchoring Bias Is Already in Your KYC Agent

The failure modes that made medical LLMs unsafe sit inside your fraud, dispute, and onboarding agents. They don't announce themselves — you have to hunt.

AI SecurityFintechRisk ManagementLLM Evals
Feb 13, 2026 6 min

Agent Onboarding Was Easy. Offboarding Isn't.

Every team shipped an agent in a weekend. Almost none can say how it gets fired, what credentials it still holds, or who would notice if it went rogue.

AI AgentsNon-Human IdentityIdentity SecurityFintech