// INSIGHTS

FIELD NOTES
& ANALYSIS

Practitioner perspectives on AI security, adversarial testing, and governance from the team that builds the attack tools.

When AI Agents Go Rogue: The Swarm Behind the Headline

How coordinated agents create useful capabilities—and dangerous collective behaviour.

READ ARTICLE →

How agents become victims...

EchoLeak (CVE-2025-32711) scored a 9.3 and earned a distinction nobody wanted: the first zero-click attack on an AI agent.

READ ARTICLE →

The Thermodynamics of Threat

What Entropy Can and Cannot Tell Us About Agent Runtime Security. When a language model moves from chat to agent, the security boundary moves with it.

READ ARTICLE →

Readiness Is Dead. Containment Is Readiness.

AI no longer arrives as a project you can prepare for. It arrives as behaviour. Why readiness now means containing what already runs.

READ ARTICLE →

Why Frameworks for Agentic AI Fail Before They Start

Governance frameworks for agentic AI arrive with a familiar promise: responsible deployment, proportionate oversight and trust by design.

READ ARTICLE →

AI Does Not Belong in OT. Yet It Is Already There.

Operational technology is built around predictability, availability, safety and long equipment lifecycles. A control system is expected to perform a defined function, within known tolerances, for many years. Changes are controlled because even a technically correct modification can have consequences for production or safety.

READ ARTICLE →

The Missing Layer in Enterprise AI

AI governance can establish accountability, document controls and authorise deployment. It cannot prove that a generative AI system will preserve the facts entrusted to it. Enterprises now need a second layer: continuous, evidence-based verification of AI outputs

READ ARTICLE →

Restricted Frontier Models

Restricted frontier models — evaluated under controlled conditions by a small number of organizations — exist in a space between research artifact and operational tooling.

READ ARTICLE →

AI-Assisted Security Assessments

Capable Tool, Not God Mode The claim is simple. The claim is wrong. Somewhere between a LinkedIn post and a vendor pitch deck, the narrative solidified: modern AI-powered security scanners can replace a full red team. Minutes, not weeks. Comprehensive, not sampled. Autonomous, not human.

READ ARTICLE →

The Morning the Models Are Gone

The morning AI goes dark — and you realize the skills were never yours. A sharp look at borrowed competence, cognitive atrophy, and what you actually know.

READ ARTICLE →

Why We Named It Quantropic

On Quantum Mechanics, Entropy, and the Only Honest Way to Secure AI.

READ ARTICLE →

RL Agents for Network Defence

From CSLE and CybORG to Autonomous Network Agents. Reinforcement learning agents are moving from research ranges into production networks. What CSLE and CybORG have proven in the lab — and what the dual-use reality means for security teams.

READ ARTICLE →

Why LLMs Lie...

Why LLMs confabulate confidently false answers — the failure modes, mitigations, and the post-Transformer architectures emerging to fix it.

READ ARTICLE →

Why Your AI Strategy Engagement Failed

The 2023–2024 AI strategy wave is maturing into a 2025–2026 implementation crisis. Here is what went wrong, and what a security-first remediation looks like.

READ ARTICLE →