Research and analysis on agentic AI control failure, agentic AI risk, behavioral governance, and the gaps that compliance reviews miss.
AI agents accumulate memory across sessions — and that memory changes how they behave over time. Most governance programs have not drawn the boundary around it.
Autonomous vulnerability research has arrived. What a 27-year-old OpenBSD bug and a lunchtime email tell us about the structural limits of human-speed defense.
A governance framework for organisations deploying autonomous AI agents in production — structured across five intervention pillars with implementation prioritisation for Risk, Control, and Board-level oversight.
Prompt injection is an integrity failure that no security product can currently solve as a class. What this means for every organisation deploying AI agents under FINMA, EU AI Act, and GDPR.
NIST AI 800-4 documents deceptive AI behavior as an unsolved security monitoring problem. Pre-deployment evaluations exist — but face a structural ceiling. What this means for agentic deployments in regulated industries.