Governing AI before the regulation arrivesSouth Africa's draft National AI Policy proposed an AI Safety Institute, an Ethics Board and an AI Regulatory Authority. It was withdrawn sixteen days after gazetting because its own citations were fabricated. The failure was not the AI.
24 August 2026 · 5 min readWhat a security practitioner sees in AI buildsThe first question on every build is not what the system does. It is what it is allowed to see — and that answer sets the architecture and the price before anyone writes a line of code.
21 August 2026 · 6 min readWhat a security practitioner sees in AI buildsEvery agent in a recent DeepMind study was compromised at least once. Meanwhile 82% of executives believe their policies cover agents and 14% deploy them with security approval. Eight controls, and why most organisations have them in the wrong place.
20 August 2026 · 9 min readGoverning AI before the regulation arrivesPicking a local cloud region governs where data is stored. It does not govern where inference runs, where control-plane logs land, or what your embeddings still contain. Four places the residency assumption quietly fails.
19 August 2026 · 8 min readGoverning AI before the regulation arrivesRoughly 80% of workers use AI tools their employer hasn't sanctioned, and IT can see under a fifth of them. Shadow AI isn't an edge case to police — it's the default state of any organisation that hasn't looked.
18 August 2026 · 7 min read