Writing archive
AI systems and assurance
Writing on what technology makes possible, how it changes the business and what it takes to make the change real.
-
One question to ask before you approve an AI program
A question directors can ask before approving an AI program: can the team produce its data-source inventory and demonstrate that it is complete?
-
Data provenance is no longer an engineering “nice-to-have”
Why data provenance matters to automated-decision transparency and AI assurance, and what a useful record of sources and transformations should contain.
-
Encryption won’t save your training data
Encryption protects confidentiality. Training-data integrity also needs controls over provenance, write access and changes along the pipeline.
-
Data poisoning only takes about 250 documents?
What a data-poisoning study found about small numbers of malicious documents, the limits of the experiment and the implications for training-data controls.
-
The secure AI data pipeline, end to end
Follow seven stages of an AI data pipeline to examine provenance, access and change detection alongside the checks that make data useful.
-
AI security belongs to the CISO. Except in 3 cases.
When AI security fits within the CISO remit, where a different structure may be justified and why organisational boundaries need clear ownership.
-
What APRA means by “assurance” of your AI estate
An examination of AI assurance through evidence, accountability, risk tolerance and independent assessment, using APRA’s expectations as the context.
-
Why your existing controls show green while failing to protect your AI estate
Why familiar controls can appear effective while missing AI-specific risks, and how to examine their coverage across models, tools and actions.
-
The AI attack surface: in 9 layers
A nine-layer reference map of the AI attack surface, connecting infrastructure, data, models, tools and human decisions with organisational ownership.
-
What does “AI Security” actually mean
Four distinct disciplines behind the phrase AI security: securing AI, using AI in defence, AI safety and governance. Different work needs clear owners.









