BLOG

Articles & guides.

Practical pieces on the EU AI Act, AI system security and compliance — written for small and mid-sized businesses, without the legalese.

Five Eyes warning: AI turns cyber incidents into business crises — act now
Intelligence chiefs from 5 countries warn AI is compressing cyber timelines from years to months. Five urgent actions for every business.
Read →
AI security audit: why running a scanner yourself isn't enough
Automated AI security scanners are cheap and useful — but "I ran the scanner" isn't "I'm secure." Three reasons, and where the human comes in.
Read →
AI governance audit: what it includes — and why your clients ask for it
The gap between "I understand AI security" and "I can deliver it as a service" is mostly about clarity. Here's how it's packaged. Wrong angle, right a…
Read →
Four compliance gaps in an AI SaaS — found before launch
briofy is an AI SaaS built in-house — it generates social captions from photos/videos and schedules posts. Before launch, a Tier-1 AI governance audit…
Read →
The 5 questions before any AI security audit
Before a laptop opens or a document is read, a good AI audit starts with five simple questions. Not technical — basic: What does this system actually …
Read →
Why output filters don't stop indirect prompt injection
In a prompt-injection training game (Gandalf), the goal is to extract a password from an AI told not to share it. Level 4 had an output filter: a seco…
Read →
NIST AI RMF: what makes an AI risk report "audit-ready"
A threat model without a Document Control section is a worksheet, not a deliverable. The technical analysis can be excellent — and still earn no audit…
Read →
EU AI Act Article 19: how long you actually have to keep AI logs
"Keep your high-risk AI logs for six months." That's the usual summary of Article 19 — and it's incomplete in a way that matters. Six months is the fl…
Read →
Evasion attack: when someone games your AI without breaking it
An insurance broker found a pattern: shift the applicant's age by 2 years and income by 5%, and the AI always approves — even when the real numbers ge…
Read →
AI threat modeling with STRIDE: the 5-step method for any LLM
"Threats" is a useless word until you answer one thing first: a threat to what? Start with assets A threat never free-floats. It's always a threat to …
Read →
EU AI Act Article 50: when you must disclose that someone is talking to AI
A common assumption about AI tools for social media and inboxes: "It's just an auto-reply — the recipient doesn't need to know it's AI." Under the EU …
Read →
AI failure or attack? The rule that tells them apart
Not every "AI gone wrong" story is a security attack. Telling which is which decides what rulebook you reach for. The first question Is there an adver…
Read →
What is prompt injection — and why "be more careful" doesn't fix it
Prompt injection is one of the most misunderstood threats to AI systems. A real incident explains it better than any definition. What happened An auto…
Read →
The AI that found 10,000 vulnerabilities is coming for the attackers too — within 6 months
Anthropic is expanding Project Glasswing and warning that within 6–12 months code-scanning models will be in other hands too, possibly without safeguards. What it means for any business that runs on software.
Read →
Enterprise AI chatbot hallucinations: the risk most deployments underestimate
A company's technical-support chatbot was reviewed recently. On tone and intent recognition it scored well. On reliability, it scored 2 out of 10. The…
Read →
Anthropic shut down two models on a US order — what it means for your business
A government directive forced Anthropic to disable two models for everyone, overnight. The lesson for any business that relies on a third-party AI model.
Read →
The Air Canada chatbot case: who's liable when your AI gets it wrong
Air Canada's chatbot invented a policy that didn't exist and the tribunal held the company liable. What it means for any business running a chatbot or AI agent.
Read →
EU AI Act: what every small business should know in 2026
You don't need to build AI for the regulation to apply to you. If you use a chatbot, text tools or AI in office software, you already have obligations. What it means in practice.
Read →