The AI security signal, not the noise.
Concise field notes on emerging threats, defensive patterns, and what's actually working — written for teams shipping AI in production.
Get the trends digest
New AI security field notes delivered to your inbox. No noise, unsubscribe any time.

Agentic Commerce Fraud: When the Buyer Is a Bot With a Real Card
AI agents that shop, book and pay on a user's behalf break every fraud signal built on human behaviour. Merchants are now approving or declining transactions with no way to tell delegation from compromise.

Your Email Assistant Reads Attacker Mail Too
An inbox assistant with send and calendar permissions turns every inbound message into a potential instruction. The mitigation is not a better model, it is a smaller blast radius.

NIS2 and AI Incidents: The 24-Hour Clock Nobody Has Rehearsed
An assistant that leaks customer data is a reportable incident in most EU member states. Very few security teams have a written answer for what counts, who decides, and what goes in the first notification.

Synthetic Identities Are Passing Your Onboarding Checks
Generated faces, consistent document sets and live video that responds to challenges. KYC flows built for photocopy-era fraud are not holding, and the fix is behavioural rather than visual.

Jailbreak-as-a-Service: Guardrail Bypasses Became a Subscription
Prompt bypasses used to circulate on forums for free. In 2026 they ship as maintained products with uptime promises, model coverage matrices and refunds when a patch lands.

Autonomous SOC Agents: What Is Actually Working, and What Is Marketing
AI agents now close a real share of tier-one alerts. The teams getting value from them share one thing: a hard boundary between what the agent may decide and what it may do.

Malicious AI Browser Extensions Are the New Endpoint Agent
"Summarise this page" extensions ask for read access to every tab. A wave of 2026 takeovers shows what happens when that permission changes hands.

Vector Databases Are Leaking Data Your DLP Cannot See
Embeddings are not anonymised. They are reversible enough to matter, they usually sit outside your classification tooling, and in most deployments every user can retrieve every chunk.

The AI Coding Assistant Is Now Part of Your Software Supply Chain
Autocomplete writes a growing share of production code, and it happily suggests hallucinated packages, outdated crypto and credentials copied from a neighbouring file. Governance has not caught up.