Practice / AI and LLM security

AI and LLM security: risk, adversarial behavior and agentic systems

AI risk conversations tend to swing between nothing here is new and this ends the world, and neither one is much help to a team that has to ship something this quarter. This page is how I actually reason about LLM and agentic systems as things you can attack, run and defend.

Treat the model as one component, not the whole system

A model on its own doesn't have much reach. It gets interesting once you hand it tools, memory, credentials or the ability to act on behalf of a user, because at that point you're back to questions security people have been asking for twenty years. What can this identity reach? What does it trust as input? Who notices when it starts behaving oddly?

The risk starts when a system treats untrusted content as instructions. Every tool an AI agent can use also gives it a way to act. Review that access as you would for any other automated account: what it can reach, what it can change and who can stop it.

  • AI and LLM risk framing for leadership teams and boards
  • Adversarial AI and agentic risk: prompt-borne instruction, tool abuse, over-broad permissions
  • Defensive architecture around models, retrieval and agent execution
  • Deciding what to build, what to buy and what to refuse

Helping a leadership team reason through AI risk

Executives usually aren't asking for a taxonomy. What they need is to know which uses they can move on today, which ones need a control before launch and which ones aren't worth the exposure at any price. Most of my job there is turning an open-ended technology question into a handful of decisions someone can put their name on.

A policy needs people who own the decisions it describes. Name those owners and revisit their decisions when the system changes.

Hands-on, not only advisory

Since January 2025 my independent work has been AI and ML engineering alongside security research: LLM fine-tuning, prompt-injection defense, agentic risk. I keep my hands in it because advice that stops at the principle isn't much use to whoever has to implement it.

Read the original writing

Ongoing long-form writing on leadership, cybersecurity and decision-making, published openly. Read First Order (opens in a new tab)

Work with me on thisBackgroundWriting & Publications