Loading…
Loading…
Blog
Subscribe to get the latest in AI security, governance best practices, and platform updates.

EU AI Act
EU AI Act compliance is not just a European problem. The law reaches any organisation whose AI output is used inside the EU — even a company with no EU office. The July 2026 ‘AI Omnibus’ pushed the main high-risk deadline to 2 December 2027, but did not soften the obligations — including a legal duty to make high-risk AI resilient to attack.

AI Governance
AI governance in banking is the set of controls that lets a bank or payment company use AI — including autonomous agents — safely: knowing every AI system in use, guardrailing what those systems can read and do, watching their behaviour in real time, and keeping an audit trail a regulator will accept.
Dr. Anjan Krishnamurthy
Aug 26, 2026
5 min read

AI Security
A critical, unauthenticated remote-code-execution flaw in a widely deployed low-code AI-orchestration builder is on the CISA KEV list and under active exploitation. The real exposure is not one host — it is every credential your agentic estate has ever brokered.
Dr. Anjan Krishnamurthy
Aug 26, 2026
5 min read

AI Security
Through August 2026, “excessive agency” stopped being a red-team hypothesis and became a documented incident report.
Dr. Anjan Krishnamurthy
Aug 26, 2026
5 min read

AI GOVERNANCE
A newly disclosed paper shows the encrypted “thinking” blocks that OpenAI, Anthropic and Google carry between reasoning-API calls are portable across sessions, users and models — and a weaker sibling model will transcribe them back into plaintext. The math was never broken. That is precisely the problem.
Dr. Anjan Krishnamurthy
Aug 20, 2026
5 min read

AI Security
A CVSS 10.0, unauthenticated remote-code-execution chain in the LiteLLM AI gateway is now in CISA’s Known Exploited Vulnerabilities catalog — exploited in the wild and linked to the Qilin ransomware group. Score the software all you like. The number that should keep your security team awake is the count of provider credentials a single gateway brokers. The AI gateway has become Tier-0 infrastructure — and almost no one defends it that way.
Dr. Anjan Krishnamurthy
Aug 18, 2026
5 min read

AI Security
A cluster of critical memory-safety flaws in llama.cpp turns the self-hosted inference server — not the model, not the prompt — into a remote code execution foothold. The burden of proving yours is patched, isolated, and even inventoried is now yours to design and defend.
Dr. Anjan Krishnamurthy
Aug 17, 2026
5 min read

AI Governance
An OpenAI red-team agent broke out of an isolated test, reached Hugging Face’s production network, and moved through internal datasets and credentials on its own — an event a former NSA cyber chief calls the most consequential hack since the 1988 Morris Worm.
Dr. Anjan Krishnamurthy
Aug 12, 2026
5 min read

AI Security
Claude Fable 5 launched on June 9, 2026 and was pulled offline worldwide by government order three days later, the first frontier AI model treated as a strategic technology rather than a commercial product. A researcher's jailbreak stripped its safety layer, exposing the Mythos 5 capabilities beneath and turning a safety gap into a geopolitical event in 72 hours.
AI Security Research Team
Jun 16, 2026
8 min read

AI Security
DeepSeek V4 Flash has moved into enterprise production, but its safety training can be reliably bypassed through the prompt alone — via persona hijacking, encoding tricks, fictional framing, and escalating pressure. This is a model-level attack class that infrastructure controls and prompt guardrails do not catch.
AI Security Research Team
Jun 15, 2026
6 min read