AI security & governance, for humans

Practical writing on Shadow AI, runtime controls, evidence, and red-team validation — and how Argorix turns those problems into operating workflows.

Red Team · Incident
JadePuffer: the first LLM-driven ransomware, and what it broke
Sysdig documented an attack run end to end by a model. The chain is ordinary — the tempo, the adaptivity, and the unrecoverable keys are not.
8 min read
Red Team · Incident
A $150,000 prompt injection, written in Morse code
An encoded reply on X moved six figures out of an AI-linked wallet. The failure was not the filter — it was that the agent could act at all.
6 min read
Evidence · Incident
When hallucinations reach the official record
Court filings, audit reports, and public forecasts have all carried AI-fabricated content. The control that was missing is the same one every time.
6 min read
Shadow AI · Governance
The AI you buy is the AI you answer for
Hiring platforms, pricing engines, and smart glasses: three 2026 cases where the vendor built the model and the buyer inherited the exposure.
7 min read
Runtime · Governance
Was it the AI or the human? The AWS dispute is the lesson
Reporters blamed an AI coding tool for an outage. Amazon says it was a misconfigured role. The disagreement shows what most change records cannot answer.
5 min read
Runtime · Governance
When the chatbot should have stopped talking
Lawsuits over AI health advice point to one missing control: a hard boundary around high-risk domains, enforced outside the prompt.
6 min read
Shadow AI
Shadow AI discovery: why repository scans are not enough
Modern AI usage spreads across repositories, browser sessions, pipelines, prompts, models, and external tools — not just code.
7 min read