Knowledge Hub

Field notes on securing the intelligence layer.

Practical, principal-authored guidance on agentic AI risk, AI security, and governance. Written for the people accountable for the decision—CEOs, CISOs, and legal counsel—not for search engines.

Proof over promises · Vendor-agnostic

Browse by theme

Four tracks, one question: can you trust what your AI does next?

Each track collects short, decision-ready briefs. Titles below are the planned launch set—publish them in order to build authority on agentic risk.

Track 01

Agentic risk & autonomy

What changes when AI stops answering and starts acting—and how to keep autonomy accountable.

  • Indirect prompt injection, explained for the board

    Why untrusted content is now an attack surface, in one page.

    Primer
  • The tool-use blast radius: scoping what an agent can touch

    A method for bounding agent permissions before deployment.

    Playbook
  • When agents chain: emergent risk in multi-agent systems

    Failure modes that only appear when agents call agents.

    Analysis
Track 02

AI security in practice

Threat models, guardrails, and controls that hold up under a real adversary.

  • A CISO's threat model for LLM and RAG applications

    The paths that matter, mapped to controls you can own.

    Framework
  • LLM firewalls and guardrails: what they do and don't stop

    Setting realistic expectations for runtime enforcement.

    Buyer's guide
  • Shadow AI: finding the models no one told you about

    A repeatable discovery method for the unmanaged AI estate.

    Playbook
Track 03

Governance & the EU AI Act

Turning obligations into controls, owners, and evidence—without theater.

  • High-risk or not? Reading Annex III without a law degree

    A working guide to the classification that drives everything.

    Guide
  • Human-in-the-loop that survives an audit

    Designing approval gates that are real, not rubber stamps.

    Playbook
  • From policy PDF to enforced control

    How to make an AI policy something a system actually obeys.

    Method
Track 04

When AI goes wrong

Detection, containment, and communication for model-era incidents.

  • Your model hallucinated into a decision. Now what?

    An incident-response path for failures of judgment, not just systems.

    Runbook
  • Detecting model drift before your customers do

    Signals and thresholds worth wiring into monitoring.

    Analysis
  • Kill-switches and rollback for autonomous agents

    Designing the stop button before you need it.

    Playbook

Try the AI Act Risk Classifier Ask about a briefing for your team

Why publish this

Authority is earned in public.

The firms worth trusting in security demonstrate depth through what they publish, not what they claim. This hub exists to show the thinking behind the engagements—so a first conversation starts from evidence, not a pitch.

Contribute a question

Facing an agentic-risk problem you can't find written up anywhere? Send it. The most useful briefs here start as a real question from a CISO or counsel.

Want these briefs as they publish—or a private walkthrough for your leadership?

Start a direct conversation about the agentic risks specific to your program.

Request a discovery call