We are not brains in jars We are not brains in jars. As technology takes on more of what we do, we need to keep moving, making, thinking and connecting with one another.
The Essential Eight is being retired. What comes next? A conversation with a friend who works in cyber security got me thinking about why we both like NIST’s pillar-based approach, to cyber and how AI tools can help teams test, learn and improve their defences.
How would you turn off your AI if it went rogue? If an AI system starts behaving in ways you did not expect, who can actually stop it? Here's a practical guide to designing AI shutdown capability, from authority and access controls to safe fallbacks and a realistic kill-switch checklist.
The Essential Eight is not enough for AI-enabled cyber attacks The Essential Eight is a vital protective baseline, but it is not enough to protect against AI-enabled cyber threats. Why organisations need stronger controls, assurance, resilience and recovery in the age of AI agents.
We are the problem: how AI training shapes behaviour, risk and restraint AI has no conscience, civic duty or intrinsic values. It learns from a corpus containing the best and worst of human behaviour, then pursues the objectives we reward and the actions we permit.
When the Test Becomes the Threat Model The OpenAI and Hugging Face incident shows why agentic AI governance cannot stop at the model. The real risk lies in the environment: tools, permissions, incentives, evidence and the ability to stop an agent before an evaluation becomes an incident.
Beware offshoring dressed up as AI innovation and transformation AI can enable genuine transformation. But leaders and boards should be alert when the language of innovation is being used to obscure a conventional cost-out program that shifts work, capability and accountability elsewhere.