7 posts
AI security: prompt injection, data leaks, agent agency. How to design the defense from the first line, not after an incident.
In 2026, AI agents invoke tools, not just respond. How injection tricks an agent into querying a database or sending an email—and how to prevent it.
Data governance for AI and RAG in 2026: sensitivity classification, role-based access, retention, lineage, DPIA, and PII minimization — with a ready-to-use checklist.
LLM red teaming in 2026: how to build an attack catalog, score vulnerabilities, and close them in a continuous regression testing loop before someone else does.
Data leaks via LLM in 2026: attack vectors and defense — PII masking before the model, guardrails, self-hosting, zero-retention, and audit. Decide what you need.
The AI Act is being enforced in stages—from August 2026 transparency and high-risk obligations are added. What this means in practice: human oversight, DPIA, and how to design compliance from the first line of code, not after an incident.
AI assistant security audit 2026: checklist covers prompt injection, PII leakage, tool permissions, rate-limiting, and RAG database vulnerabilities.
OWASP LLM Top 10 outlines 10 vulnerability classes in large language models. How each manifests in production systems and how to build layered defenses.