PAGES16
WORDS13,058
SOURCES33
READ TIME57 min
TYPEHUB
CHECKED25 AUG 26
What goes wrong when AI systems touch real data, real credentials and real money — and the checks that catch most of it.
The checklist
Ordered so stopping partway still covers the expensive part.
THE CRAFT · 3 MIN · 2 SOURCESA Security Checklist for AI-Built SoftwareThree tiers ordered by what it costs to get wrong, plus the three AI-specific checks nobody inherits from conventional security prTHE RECORD · 3 MIN · 1 SOURCESVibe Coding: What It Is and What It CostsBuilding software by describing it and not reading the result. Where the practice genuinely works, the four costs when it does not
Injection and boundaries
Fetched content is data. Models cannot reliably tell.
THE CRAFT · 3 MIN · 2 SOURCESAgent GuardrailsFour lines that belong in every agent prompt. Scope, negatives, injection defence and stopping conditions — the permission model tTHE CRAFT · 2 MINPermission Tiers for AgentsFive levels of permission, assigned per task by how hard the action is to undo rather than by how much you trust the agent — and wTHE CRAFT · 3 MIN · 1 SOURCESSkills Are a Supply ChainInstalling a skill means loading someone else’s instructions into your agent’s context. An audit of 3,984 published skills found 1
Verification
Checking output, checking vendors, and knowing when to stop.
THE RECORD · 3 MIN · 1 SOURCESAuditing AI-Generated WorkChecking everything is not a strategy. Four risk tiers with a different check for each, the five signals worth looking for specifiTHE RECORD · 3 MIN · 3 SOURCESAuditing a Vendor’s AI ClaimsEvery demo works — that is what a demo is. Nine questions that separate a product from a demonstration, what to ask about accuracyTHE RECORD · 3 MINThe Cost of Checking Too MuchEverything says check more. Almost nothing says where checking stops paying. Review theatre, uniform attention, and the failure noTHE CRAFT · 2 MINDiagnosing a Run That Went WrongThe agent finished, the output is wrong, and you have a transcript. How to find the first wrong step rather than debugging its con
Fraud and fakes
What the same tools do in the wrong hands.
EXPLAINER · 6 MINHow AI Fraud Actually WorksSeven specimens of AI-assisted fraud, pinned and annotated: the cloned executive, the deepfake video call, the fake job…THE RECORD · 6 MIN · 4 SOURCESDeepfake Self-DefenceVoice clones need about three seconds of audio. Sourced, dated, and revised when the numbers move.THE RECORD · 1 MINSPOT FAKE IMAGES & VIDEOWhat still gives away AI-generated images, video and cloned voices in 2026 — and why the visual tells are disappearing…THE RECORD · 6 MIN · 1 SOURCESHOW TO SPOT AI WRITINGNine reliable signals of AI-generated text, why detector tools cannot be trusted to accuse anyone, and what to do…
Your own data
What leaves, and where it goes.
THE RECORD · 4 MIN · 2 SOURCESWHAT HAPPENS TO WHAT YOU TYPERetention, training, human review and whose data it legally is — four separate questions people collapse into one.DATED · 7 MIN · 13 SOURCESTHE RULES ARRIVINGThe EU AI Act became broadly applicable on 2 August 2026. What changed, when, and what it actually means.THE RECORD · 4 MIN · 3 SOURCESTHE HOUSEHOLD GUIDEPrintable. Sourced, dated, and revised when the numbers move.