Blog
Notes on verified AI inference, regulated industries, and the infrastructure of trust.
Subscribe via RSS-
When an Agent Takes the Action, Its Own Logs Are Not the Proof
A chat agent that only produces text has weak felt pain. It concentrates where an agent takes a consequential action — moving money, denying a claim, filing to a regulator. Then the question stops being 'what did the model output' and becomes 'what did this agent actually do, and on what basis.' Observability is the system's word about itself; an independent receipt is something a third party can check.
Read article → -
You Have Logs. Logs Can Be Edited.
In Mobley v. Workday a court let discrimination claims proceed against the AI vendor itself — on what the model actually did. Every AI vendor in a regulated industry now has to prove what its model ran, on which input, producing which output. Self-kept logs, SOC 2, and contracts all collapse the moment it turns adversarial. The fix is a tamper-evident receipt verified by a party that never ran the job.
Read article → -
The Trust Mark of Independent Compute
Billions are flowing into AI compute, but almost none of it buys a guarantee about the work performed. Independent providers are cheaper, yet serious buyers default to the incumbents because they cannot check the work — so they buy the reputation instead. A verifiable receipt, produced by a prover separate from the executor, lets independents sell proof instead of a name.
Read article → -
When the Sign-Off Stops Being the Last Line of Defense
A compliance officer or ISO 42001 assessor signs off on an AI system's outputs after reading a model card and a sample of predictions. That signature has carried the trust for years — but a reviewer who attests to correctness without a way to independently check the computation is holding liability they cannot discharge. Separating the executor from the prover turns the sign-off into something anyone downstream can check.
Read article → -
The Executor Runs the Model. The Prover Answers for It.
Across the regulated AI sector, production inference runs on managed cloud the company doesn't operate — yet the compliance obligation stays with the licensee. The human-review tier that used to close that gap attests but never reproduces. A cryptographic receipt from a prover separate from the executor does.
Read article → -
Inference Has No Controller
Kubernetes learned a decade ago that a system cannot be trusted to report its own state, so the controller sits outside the object. AI inference never learned it: the operator runs the model, writes the log, and vouches for itself. The executor cannot be the prover.
Read article → -
The Reviewer and the Reviewed Cannot Be the Same Agent
Separation of duties — the party doing the work can't be the only one checking it — is load-bearing in every GRC framework. When an AI agent acts and another AI reviews, that independence is cosmetic. What agentic systems do to one of the oldest controls in the book.
Read article → -
What ISO 42001 Asks For, and What It Cannot Give You
ISO 42001 asks you to measure, monitor, and keep records of how your AI behaves. None of those clauses, on their own, proves what the model did on one specific decision — the difference between a record and a proof, and where it starts to matter.
Read article → -
Cheaper Compute, Borrowed Trust
Moving inference off the hyperscalers is cheaper, but the trust model changes. When the hardware isn't yours, a cryptographic receipt — not the provider's word — is what makes the result usable for regulated work.
Read article → -
The Four Questions I Ask Every AI Vendor Before Signing
I sign the vendor contract and I answer for it later. Four questions, none of them technical, that decide whether I can prove what an AI model did — or only repeat what the vendor told me.
Read article → -
The Regulator Is Already in the Building
While most of the AI industry watches the EU AI Act's deadlines slide into 2027, insurance examiners in twelve states are already asking carriers to account for their AI. The instrument exists, it is in use, and your vendor cannot answer it for you.
Read article → -
I'm Not the Engineer. I'm the One Who Has to Defend It.
The people who actually decide whether an AI tool gets bought look more like me than the people pitching it. An operator's view of the gap between a vendor demo and what a compliance team can defend.
Read article → -
The EU Just Blinked. The Trajectory Didn't Change.
A delay is not a reprieve. It is extra time to build what every version of these rules converges on: proving which model made a decision, on what data, and how you know.
Read article → -
$100 Billion of AI Inference Runs on Blind Trust
Every AI model powering insurance pricing, fraud detection, and clinical decisions today produces outputs that no third party can independently verify. That era is ending.
Read article →