Category: AI
-

The ‘AI in Security’ Vendor Pitch Is Not the Same as AI in Security
Every security vendor now says they use AI. The phrase, in the security context, is even more inflated than the broader ‘we use AI’ problem. The products that actually use AI in security, in ways that materially change detection, response, or prevention, are a small subset.
-

The ‘We Use AI’ Vendor Claim Is Meaningless Now
Every vendor says they use AI. The phrase means nothing. In 2026, ‘we use AI’ is a signal of nothing, and treating it as a signal is how buyers get had.
-

What AI Agents Actually Cost to Run (the Unit Economics Nobody Publishes)
The published API price is the price for one call. The real cost of running an AI agent in production is typically 3x to 10x the published price. Companies that budgeted for the published price are discovering this.
-

Microsoft Recall: One Year Later
A 2026 deep-dive on Microsoft Recall: the original 2024 panic, the April 2025 redesign, the Hagenah TotalRecall Reloaded finding, the same-user malware…
-

The AI Bubble Is Real. It Is Also Not the Problem.
There are two AI bubbles. The one in the press is about GPUs and data centres. The one nobody is talking about is the consulting and integration layer that has built up around AI deployment. The first one might pop. The second one will quietly deflate.
-

Your AI Tool Sprawl Is Your New Shadow IT
The board wants a number for the AI rollout. The honest answer is around 30 to 50 tools in active use, depending on how you count. That number is conservative. Most CISOs I have talked to in the last quarter think the real number is north of 100 if you include browser extensions and shadow…
-

The accidental insider: when your own AI agent causes a breach
The dominant breach pattern of 2026 is not the external attacker. It is the autonomous agent, internal, with credentials, acting on its own. The pattern has a name now, and the playbook for defending against it is taking shape.
-

Prompt injection in agent memory: the OWASP top 10 got the threat order wrong
The OWASP GenAI LLM Top 10 for 2026 still leads with prompt injection. The 2026 attack class is not the one the list leads with, and the gap is shaping what teams defend against first.
-

Human in the Loop Has Become a Marketing Checkbox
The phrase ‘human in the loop’ used to mean a human reviewed and approved the AI’s significant actions. In 2026 it usually means a human is somewhere in the system, possibly asleep.
-

The AI Safety Industrial Complex Is Asking the Wrong Questions
The most famous AI safety organisations in the world are funded by the same companies building the most powerful AI systems. That is not a coincidence, and it is not nothing.