Skip to content

Resources

Notes on safe, efficient AI

Practical writing, research, and frameworks on AI security, governance, and getting more from what you spend.

NewsletterSeptember 9, 2026

The Enterprise AI Brief — Issue 13

A database connector says “read only.” Then a query it was supposed to stop gets through. A newly disclosed AWS vulnerability shows why the permissions behind an AI connector can matter more than the label in front of it.

Read the post

NewsletterMay 15, 2026

The Enterprise AI Brief — Issue 9

AI agents may not expose their reasoning, but their tools leave a trail. New MCP security research is treating tool-call sessions as a detection surface, where the sequence of file reads, database queries, emails, errors, and arguments can reveal misuse that a single prompt log might miss. The catch is that the same traffic used for detection may also contain secrets, customer data, and execution paths. MCP tool-call monitoring is becoming useful evidence, but it also has to be handled like sensitive infrastructure telemetry.

Read the post

NewsletterMay 4, 2026

The Enterprise AI Brief — Issue 8

Anthropic says its unreleased Mythos Preview model found and exploited high-severity vulnerabilities across every major operating system and browser, then chose to restrict access rather than release it. Independent researchers reproduced much of the discovery work using models costing a fraction of a cent per thousand tokens. The article examines what that split between cheap discovery and frontier exploitation means for enterprise patching programs that were built around a slower cycle.

Read the post

NewsletterMarch 10, 2026

The Enterprise AI Brief — Issue 7

AI coding assistants have moved beyond autocomplete. Claude Code Security can scan full repositories, verify vulnerability findings, and propose patches directly in the pull request workflow. That puts it alongside CI servers and build pipelines as a component with its own credentials, configuration surfaces, and access to sensitive code. Security teams that have not yet accounted for it in their supply chain governance probably should.

Read the post

NewsletterFebruary 19, 2026

The Enterprise AI Brief — Issue 6

LLMjacking takes a familiar attack pattern — stolen cloud credentials — and points it at a new target: managed LLM inference. Recent incident writeups document a repeatable workflow, from stolen keys to quiet AI API probing to sustained model invocations that can drain budgets and exhaust quotas. For organizations where AI usage is growing faster than logging and cost controls, this attack class can turn a routine credential leak into an operational incident quickly.

Read the post

NewsletterFebruary 11, 2026

The Enterprise AI Brief — Issue 5

BitBypass hides one sensitive word as a hyphen-separated bitstream, then uses system-prompt instructions to make the model decode and reinsert it. In testing across five frontier models, this approach substantially reduced refusal rates and bypassed multiple guard layers. All five tested models produced phishing content at rates between 68-92%. If your safety controls assume plain-language detection will catch malicious intent, this research deserves close attention.

Read the post

NewsletterJanuary 23, 2026

The Enterprise AI Brief — Issue 3

A single poisoned document. An agent following instructions it should have ignored. An audit log that points to the wrong person. AI agents are no longer just automation: they're privileged identities that can be manipulated through their inputs. Regulators are catching up. NIST is collecting security input, FINRA is flagging autonomy and auditability as governance gaps, and Gartner predicts 25% of enterprise breaches will trace to agent abuse by 2028. The question isn't whether agents create risk. It's whether your controls were built for actors that can be turned by a document.

Read the post

The newsletter

The Enterprise AI Brief goes out roughly monthly: what moved in AI security, operations, engineering and governance, and why it matters. Past issues are in the hub above.

Ready to build what’s next?

Start with a roadmap, a readiness assessment, or a structured takeover.