Insights

What a security practitioner sees in AI builds

Long-form pieces on the things that decide whether an AI system survives contact with real data and real people. Written from delivery, not from the sidelines.

Governing AI before the regulation arrivesWhat a security practitioner sees in AI builds
Governing AI before the regulation arrives

Seven new institutions, and nobody to check a footnote

South Africa's draft National AI Policy proposed an AI Safety Institute, an Ethics Board and an AI Regulatory Authority. It was withdrawn sixteen days after gazetting because its own citations were fabricated. The failure was not the AI.

24 August 2026 · 5 min read
What a security practitioner sees in AI builds

Before I ask what your AI should do, I ask what data it touches

The first question on every build is not what the system does. It is what it is allowed to see — and that answer sets the architecture and the price before anyone writes a line of code.

21 August 2026 · 6 min read
What a security practitioner sees in AI builds

What to actually look at when an AI can use tools

Every agent in a recent DeepMind study was compromised at least once. Meanwhile 82% of executives believe their policies cover agents and 14% deploy them with security approval. Eight controls, and why most organisations have them in the wrong place.

20 August 2026 · 9 min read
Governing AI before the regulation arrives

"Regional" doesn't mean your data stays there

Picking a local cloud region governs where data is stored. It does not govern where inference runs, where control-plane logs land, or what your embeddings still contain. Four places the residency assumption quietly fails.

19 August 2026 · 8 min read
Governing AI before the regulation arrives

Governing the AI you didn't approve

Roughly 80% of workers use AI tools their employer hasn't sanctioned, and IT can see under a fifth of them. Shadow AI isn't an edge case to police — it's the default state of any organisation that hasn't looked.

18 August 2026 · 7 min read