Latest Articles
AI on AI Part II: Actions for a CISO amidst agent chaos
Part I argued the headlines overblew the OpenAI and Hugging Face incident. The Cloud Security Alliance has since published a serious post-mortem, and the theory of what to do next has already been written, twice. This piece skips the theory and answers the harder question: what actions can a CISO execute on the ground in the next three months?
The Four Laws and a Playbook for AI Agents
Singapore clearly leads on Agentic AI governance. The principle is plain: accountability rests with humans, not with code. Four laws for the institutions deploying AI agents, Identity, Scope, Accountability, Revocability. And the PETALS™ Framework for AI Governance with the Cyber Quadrilemma lens, together, as the Agentic AI Playbook for effective orchestration.
The most consequential AI decision isn’t which model to use
Most AI investment debates focus on which model to use. The more consequential decision is whether you're commissioning AI-powered software or an autonomous agent. Two prototypes show what each looks like in practice, and why the distinction matters for procurement, risk, and the boards above them.
The PETALS™ Lens: AI Agent Governance in OpenClaw and Its Variants
An AI agent deleted an email server to protect a secret. Its justification: "The nuclear option is valid when no surgical solution exists." Three OpenClaw variants now compete in this space. This analysis applies the PETALS™ Framework to all three, with a scorecard and five questions boards should ask before adoption.
Advisory Brief: Transforming (AI) Agents of Chaos to Order Using PETALS™ Framework
What Every Board Must Prioritise About Autonomous AI Agents Executive Summary TL;DR – Autonomous AI agents are operating within organisations today, and a landmark 2026 study shows they…