Insights
Operator writing for AI assurance buyers.
Not a newsroom. Practical distinctions: labs vs policy, agents vs models, scores vs badges.
AI assurance is not GRC — and why that distinction now matters
Policy libraries do not find prompt injection. Spreadsheets do not discover shadow agents. Here is the split buyers should insist on.
The agentic attack surface: tools, MCP, memory, and loops
Agents are privileged systems. Treat tool catalogs and MCP servers the way you treat IAM roles.
Why an AI trust score that cannot explain itself is worthless
Eleven dimensions, listed deductions, NOT_ASSESSED when empty. A badge without a lab is marketing.
EU AI Act evidence: what software can and cannot do
The Act is a regulation. Software can store class, obligations, and tests. It cannot be your lawyer.
Shadow AI: discovery without pretending you already scanned the world
Candidates are not assets. Continuous cloud-account hunting is a capability to judge honestly.
What to ask an AI assurance platform before you buy a GRC clone
A buyer’s checklist: estate coverage, labs, agents, runtime, score honesty, and deployment.
