Writing
Essays, research notes, practical observations, and ideas on trustworthy technology.
The OpenAI–Hugging Face Incident Changes the Threat Model for AI Agents
The OpenAI–Hugging Face incident offers an unusual glimpse into what happens when capable AI agents persist, coordinate and discover paths beyond the boundaries humans intended. The deeper lesson is not simply about sandbox escape — it is about how agentic AI changes the cybersecurity threat model.
Read article →The Cybersecurity Metrics That Boards Should Actually Care About
Cybersecurity dashboards often measure what security teams are doing rather than whether the organisation can withstand a serious incident. Boards need fewer activity metrics — and better intelligence about risk, resilience and the decisions that require their attention.
Read article →AI Governance Needs an Incident Response Plan
AI governance has focused heavily on preventing AI failures. But as AI systems become increasingly autonomous, organisations also need a plan for what happens when prevention fails — and clear authority over who can stop the system.
Read article →Trust Cannot Be Static in Decentralised Federated Learning
Trust in decentralised federated learning is often treated as a relatively static property. This article argues that trust should instead be viewed as a dynamic capability—continuously reassessed as participants, behaviours, and network conditions evolve throughout collaborative learning.
Read article →Trust Is the Missing Layer in Decentralised Federated Learning
Most federated learning research focuses on protecting data, yet privacy alone cannot secure decentralised collaboration. This article explores why trust should become a fundamental design layer alongside privacy in peer-to-peer federated learning.
Read article →Beyond Human-in-the-Loop: Governing Agentic AI at Operational Speed
Human-in-the-loop was designed for systems that recommend. Agentic systems act. Governance now has to work at the speed of the machine while keeping authority firmly with people.
Read article →Why Digital Trust Must Become a Board-Level Responsibility
Trust in an organisation's digital conduct is now a balance-sheet issue. Boards that delegate it entirely to technical functions are governing yesterday's risk register.
Read article →Privacy and Trust in Peer-to-Peer Federated Learning
Removing the central server from federated learning removes a single point of failure — and a single point of trust. Notes on what replaces it.
Read article →When AI Governance Becomes a Compliance Theatre
Committees, principles, and registers can coexist comfortably with ungoverned AI. The test of real governance is whether it ever changes a decision.
Read article →Building Cyber Resilience Beyond Technical Controls
Controls prevent incidents. Resilience determines what an incident costs. The second is an organisational property, not a technical one.
Read article →Governing AI-Driven Incident Response in Public-Sector Organisations
Public-sector security operations are adopting AI faster than public-sector governance frameworks are adapting. Notes on closing that gap responsibly.
Read article →