Latest Articles
AI on AI Part III: Convergence (Hacking the infra and Cracking the math)
Two weeks ago, an OpenAI agent broke into Hugging Face. Last week, an AI model killed HAWK, a PQC candidate designed to resist quantum computers, using classical mathematics. This convergence of AI accelerating both hacking and cracking the maths cannot be ignored. Until now, we were preparing for a predicted event in the future (Q-Day). Now, we must prepare for an unpredictable event that could happen anytime. Part III extends the CISO’s action plan from Part II with crypto-agility deliverables built to endure both threats.
AI on AI Part II: Actions for a CISO amidst agent chaos
Part I argued the headlines overblew the OpenAI and Hugging Face incident. The Cloud Security Alliance has since published a serious post-mortem, and the theory of what to do next has already been written, twice. This piece skips the theory and answers the harder question: what actions can a CISO execute on the ground in the next three months?
AI on AI Part I: Overblown Headlines Likely to Spook Insurers
An OpenAI model broke out of its own test lab and hacked Hugging Face, unsupervised. Everyone is calling it unprecedented. It isn't. Two of the most sophisticated AI companies on the planet got caught out by security mistakes any first-year analyst would recognise, and the insurance market is already taking note.
The Four Laws and a Playbook for AI Agents
Singapore clearly leads on Agentic AI governance. The principle is plain: accountability rests with humans, not with code. Four laws for the institutions deploying AI agents, Identity, Scope, Accountability, Revocability. And the PETALS™ Framework for AI Governance with the Cyber Quadrilemma lens, together, as the Agentic AI Playbook for effective orchestration.
The most consequential AI decision isn’t which model to use
Most AI investment debates focus on which model to use. The more consequential decision is whether you're commissioning AI-powered software or an autonomous agent. Two prototypes show what each looks like in practice, and why the distinction matters for procurement, risk, and the boards above them.
x402 and the Quiet Shift in How Money Moves
Visa took decades to scale. AI agents on a public blockchain have settled more than 100 million stablecoin transactions in just nine months. Stripe, Circle, and Chainalysis have confirmed the quiet shift now under way across stablecoins, tokenised assets, and blockchain infrastructure. A briefing for senior leaders responsible for payments, treasury, technology, risk, or strategy.