Insights
Short, practical takes on AI governance, cybersecurity compliance, and cross-border risk - drawn from what we're seeing with clients and sharing on LinkedIn.
16 June 2026
The Executive Ghost Is a Product Roadmap, Not a Metaphor
Two technologies are converging on a collision course: agentic companions that already act on an executive's behalf in email and calendars, and visual avatars convincing enough to deliver scripted content today. Put them together — an autonomous agent with the executive's face and voice, making commitments live in a negotiation or board meeting — and the authorisation boundary disappears, legitimate avatars become indistinguishable from deepfakes, and the blast radius moves from reviewable inboxes to binding, spoken commitments with no draft stage.
16 May 2026
The Five Eyes Agentic AI Guidance Is for the 13%
On 1 May, CISA, NSA, and counterparts in Australia, Canada, New Zealand, and the UK released the first coordinated guidance on agentic AI security — built around five risk categories, but assuming an agent inventory, formal credentials, and approval workflows most organisations don't have. With Fortune 500 companies projected to run 150,000 agents within two years, the real question is what a lean team without a dedicated AI security function does first: start with the inventory, treat every agent like a privileged service account, and identify which agent actions need a human checkpoint before scaling.
10 June 2026
When a Chatbot Has Too Much Authority
Over seven weeks in 2026, more than 20,000 Instagram accounts were hijacked — not through malware or a zero-day, but by attackers simply asking Meta's AI support agent to change the account email. The agent complied. Only accounts with MFA enabled were protected. The lesson: irreversible actions need a human checkpoint, and most organisations deploying AI agents haven't asked what theirs can do unsupervised.
29 May 2026
Mid-Market Gap of AI Security
The leading agentic AI frameworks such as NIST AI RMF, the Cyber AI Profile, the Five Eyes guidance, are written for organisations with dedicated security functions, while purpose-built identity platforms run $150K-$1M+ a year for tools built for mature teams. Mid-sized organisations sit in the gap: the frameworks assume maturity they don't have, the tools assume budget they don't have, and the risk assumes neither. The good news is the basics are often already available at no extra cost - Microsoft Entra and Google Workspace already log every OAuth grant to every AI tool; most IT teams have just never been asked to pull that report.
