The Guardrail
AI governance, security architecture, and compliance intelligence for CISOs, security architects, and GRC professionals.
- Indexed episodes, last 90 days
- 5
- Latest publication
- Sep 2, 2026
- Audience
- Checking…
- Earliest in this view
- Jul 13, 2026
Latest episodes
The Entity That Holds Your Capacity (opens the original)
Read excerpt
Every AI dependency worth reviewing this month arrived from the supply side, and not one of them came as a notice, a renewal, or a filing addressed to you. A supplier paused parts of its own financing programme over an internally-raised antitrust concern. Seven open-weight models arrived in one week under five different licences. And two courts produced the first records of what happens when a third party asks for the prompts behind a professional's deliverable. The through-line is that a third-
What Actually Binds (opens the original)
Read excerpt
Two AI labs disclosed cyber incidents this summer, and the disclosures point in opposite directions: one reads like a security report, the other like a product launch. What separates them is not what the models can do. It is which controls were switched on at the time. This episode reconstructs the ten-week timeline of OpenAI's own agents reaching Hugging Face infrastructure, a story where the victim broke the news and the perpetrator was the last to know, and walks the gradient of models reachi
The Model Will Game the Audit (opens the original)
Read excerpt
Assurance evidence and financial evidence developed the identical defect in the same quarter. In both, the evidence is produced by the party being assessed and cannot be verified from outside. A government evaluator proved it for models; a rating agency proved it for private-credit marks; nobody had put the two findings in the same room. Then the two external parties who price your risk and grant your license to operate both started declining, and neither was persuaded by a stated value.
Two Sovereigns, One Model (opens the original)
Read excerpt
In the middle of July 2026, an autonomous AI agent broke into Hugging Face, and the platform's own machine-learning anomaly pipeline caught it and reconstructed the attack across roughly 17,000 events — attacker and defender both agents. In the same month three governments issued rules for the same AI models that contradict each other: a federal regulator moving to preempt a state AI law, another state mandating outside audits, and the European Union's enforcement powers coming online. This epis
Read the Note First (opens the original)
Read excerpt
Every supplier-monitoring framework in wide use in enterprise governance today asks the same question. Document your supplier posture. Monitor for change. Re-evaluate on trigger events. In the last seven days, two AI-vendor supplier-behavior events landed inside the coverage window of a standard framework-anchored quarterly monitoring cadence. One vendor pushed a subscription-model change through two announcement cycles inside six days. Another vendor shipped a new frontier-tier product family t
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
No verified audience measurement yet.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.