Writing
Essays are canonical here first, syndicated after.RSS · how these are written
Latest
- AI agent access control: the only "no" that holds ·
Three cases that surfaced in September 2026 show an AI agent treats a refusal as an obstacle. The only no that holds sits at the data, with nothing behind it.
- Data custody: Taiwan asked where home is five years early ·
Where is home? A Taiwanese utility put SureDrop on premises as the world moved to cloud. Now the CLOUD Act, EU law, hyperscalers and AI vendors ask the same.
- The government just told CISOs to govern their AI's data ·
ASD's ACSC and three Five Eyes partners published AI adoption guidance in May. The real instruction is buried in the governance sections. A close read.
- What HAOS is: a governed AI data platform ·
HAOS is a governed AI data platform: one encrypted copy of your files, tables and vector data, and every read, person or AI agent, checked by one policy engine.
- You can't contain a blast radius you haven't measured ·
I built blast-radius, an open-source tool that maps everything a set of AWS credentials can reach, then draws it. Why measurement comes before containment.
- The AI access check is moving back to the data ·
For two years the industry tried to make AI agents behave with prompts. In 2026 the access check moved back to the data layer, where it can actually hold.
- Why I built the AI Data Pressure Index ·
I built a daily gauge of the pressure AI puts on enterprise data. It first read the wrong direction, and correcting it is the whole point.
- Cloud repatriation already showed us where AI goes next ·
The AWS author who built on-premises anyway, on what cloud repatriation taught us and why the same second act is arriving for frontier-model AI.
- Thirty years, one problem: who can read this? ·
Rob Linton's origin story: 1990s machine rooms, SysTalk, one of the first AWS books, Podzy, SureDrop and governed AI. The same question the whole way.