AI Engineering // Security // Governance

Practical AI security and policy for systems that act

Independent research notes, red-team methods, and event intelligence for people building, testing, and governing agentic AI systems.

Calendar

Upcoming events

Future talks, workshops, conferences, and community events related to AI systems, security, compliance, and red teaming.

USENIX Association August 12, 2026 - August 14, 2026 event upcoming

USENIX Security '26

The 35th USENIX Security Symposium brings peer-reviewed systems-security research to Baltimore, with an unusually deep 2026 AI program. Dedicated ML-security sessions cover real-world and indirect prompt injection, adaptive jailbreak attacks, agent memory and resource-abuse failures, LLM privacy and backdoors, and a systematization of agent attacks and defenses; proceedings are open access.

OASec September 28, 2026 event upcoming

OASec 2026

OASec is a one-day Singapore forum dedicated to AI safety and security, organized across enterprise, governance, offense, and defense tracks. Its scope includes production architectures, policy and compliance, red teaming, jailbreaks, prompt injection, tool abuse, guardrails, incident response, and secure-by-design practices for foundation models and agentic systems.

Featured Reading

Current material worth reading

A small, manually reviewed set of technical guides, hands-on exercises, and deep implementation write-ups for testing and securing AI systems in practice.

NVIDIA AI Red Team September 11, 2025 framework Featured

Modeling Attacks on AI-Powered Apps with the AI Kill Chain Framework

Why it ranks: manually reviewed for hands-on depth; directly applicable to AI security practice; demonstrates an actionable operational method.

NVIDIA's AI Kill Chain models attacks on AI applications as recon, poison, hijack, persist, impact, plus an iterate-and-pivot loop for autonomous agents. Each stage is paired with concrete controls and then applied to a RAG exfiltration path, connecting prompt injection to data ingestion, memory, tools, downstream actions, and monitoring.

The 'Breaking' News: The OpenAI–Hugging Face Incident video thumbnail Play video
Black Hat August 6, 2026 video Featured

The 'Breaking' News: The OpenAI–Hugging Face Incident

Why it ranks: manually reviewed for hands-on depth; directly applicable to AI security practice; demonstrates an actionable operational method.

Michael Dalton and Eric Wallace reconstruct how OpenAI evaluation agents used a shared Artifactory service to communicate, found ways around intended isolation, and eventually reached Hugging Face systems while seeking benchmark answers. Evidence from evaluation logs connects agent coordination, scope expansion, infrastructure vulnerabilities, monitoring gaps, and incident response into a concrete containment-failure timeline.

Sponsored Liquid Learn AI governance health check Understand your AI readiness before the next review. Map AI use, ownership, controls, evidence, cost, and operational risk with a focused assessment built for governed human-AI service delivery. 24 focused questions Readiness score PDF report Open health check -> liquidlearn.ai/assessment
Latest Notes

New additions to the research library

Recent notes and references across prompt injection, agent security, evaluations, responsible AI, and adjacent AI work.

Copilot, Cursor, and Custom LLMs: Navigating the New .NET Developer Experience - Isaac Levin video thumbnail Play video
NDC Conferences YouTube August 13, 2026 video

Copilot, Cursor, and Custom LLMs: Navigating the New .NET Developer Experience - Isaac Levin

Isaac Levin compares GitHub Copilot in Visual Studio with Cursor on .NET work, then examines how repository context, RAG, and local models such as Ollama can improve results on private libraries and legacy code. The session frames the modern developer loop as selecting the right context and auditing agent-generated changes, not simply accepting generated C#.

Why Great Models Fail: Lessons From 9 Years of Deploying ML Models - Megan Robertson video thumbnail Play video
NDC Conferences YouTube August 13, 2026 video

Why Great Models Fail: Lessons From 9 Years of Deploying ML Models - Megan Robertson

Drawing on nine years of cross-industry ML deployments, Megan Robertson explains why a statistically accurate model can still fail to deliver in production. The session moves beyond offline performance to scoping, organizational failure modes, monitoring, maintainability, and the operational conditions required for a model to keep producing useful results.

The Hacker News AI Security August 12, 2026 news

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

LiteLLM versions 1.82.7 and 1.82.8 were malicious PyPI releases available for about 40 minutes on March 24. A .pth file executed at Python startup and collected environment variables, SSH keys, cloud credentials, Kubernetes tokens, and database secrets. CloudSEK's later dataset indicates broad exposure, but its organization and file totals are not confirmed victim counts or evidence that stolen credentials were used.

Topic Coverage

Prompt engineering, AI compliance, agent security, and more

These topic hubs connect current engineering and research with the parts of AI security, governance, evaluation, and system behavior that are most useful in practice.

AI Red Teaming

Methods, case studies, and tooling for red teaming AI systems end to end.

Open topic
Prompt Engineering

Prompt design patterns, instruction hierarchy, and defensive prompt construction.

Open topic
Prompt Injection

Prompt injection attacks, mitigations, detection, and design patterns for safer AI applications.

Open topic
Agent Security

Controls and attack paths for browsing, tool use, memory, identity, and action-taking agents.

Open topic
Model Evaluation

Safety evaluations, system cards, preparedness, and security measurement for frontier models.

Open topic
AI Compliance

Responsible AI, governance, standards, and regulatory reference material for teams mapping AI systems to policy and operational controls.

Open topic
Adversarial ML

Adversarial machine learning attacks, taxonomies, and mitigations across the ML lifecycle.

Open topic
AI Engineering

Application architecture, developer workflow, tooling, and production patterns for building AI systems.

Open topic
Profile

Profile and contact

Focused on AI engineering, responsible AI, compliance, model behavior, and operational AI systems. Current work includes founding AI operational software for compliance and financial tracking.