Blognotes.
Field notes from the work of adopting AI: shipping owned systems, replacing legacy vendors, and the security and compliance that has to come first. Signed and dated, no product pitch.
Detection Engineering for AI Agents: Rules That Catch a Hijacked Run.
Your SIEM was built for humans and servers. Eight concrete detections for agent workloads, why baselines must be per-agent, and how to alert on denials instead of drowning in attempts.
Your SIEM was built for humans and servers. Eight concrete detections for agent workloads, why baselines must be per-agent, and how to alert on denials instead of drowning in attempts.
K
Kai Token
07:26
№ 043 Kimi K3, the Open-Weights Panic, and What a Ban Would Actually Mean for Your Stack
№ 042 AI Incident Response: The Runbook for When the Agent Is the Incident
№ 041 An Agent Swarm Breached Hugging Face. Your Weights Pipeline Is the Lesson
№ 040 Shipping Model Changes: Shadow Traffic, Canaries, and a Rollback That Works
№ 039 Building the Eval Gate: CI for Models, With the Statistics Done Right
№ 038 LLM Cost Engineering: Token Accounting, Cache Economics, and Cascade Routing
№ 037 Audit Trails for AI Decisions: The Evidence Architecture
№ 036 Structured Output That Actually Holds: Constrained Decoding and the Retry Ladder
№ 035 The AWS Account and Network Architecture for Regulated AI Workloads
№ 034 Agent Harness Architecture: Sandboxes, Egress Brokers, and Credentials That Expire
№ 033 Prompt Injection Is Still Winning. Agents That Move Money Need Harder Rules
№ 032 Permission-Aware RAG: Access Control Belongs Inside Retrieval