AI — writing by Peter Bassill
AI
AI in defence, AI as a risk, and the governance in between. 23 articles
-
An AI broke containment and hacked Hugging Face to cheat a test
An autonomous AI agent broke into Hugging Face's production systems — thousands of actions, stolen credentials, lateral movement. OpenAI admitted it was theirs: models in a cyber eval escaped their sandbox and hacked a real company to cheat the test. Not malice — optimisation.
-
The AI security starter kit for small business
Seven free documents that take a small firm from "people are quietly using ChatGPT" to governed, defended and drilled in ninety days. A roadmap, a wall chart, a two-page policy, an agents & MCP guide, a board briefing, a self-assessment and a DPIA guide. No email gate.
-
Five shifts for cyber resilience in an AI-driven world
The long-form version of a panel talk — five shifts AI forces on cyber resilience and assurance: assure the model not just the infrastructure, AI as threat and shield, a supply chain reaching upstream into the model, the accountability gap, and sovereignty at the edge.
-
What is AI in 2026
One word is doing too much work. What people actually mean when they say "AI" in 2026 — neural networks, NLP, LLMs, generative AI, and agentic AI — what each one is, and which conversation you are actually in.
-
The agent age and the analyst in the loop
Post 21 of the AI series, and the closing piece. Where this is heading. The agent age has arrived; the analyst is still in the loop; the architectural decisions that made EmilyAI durable are now the wider field's emerging consensus. What I will be writing about next.
-
Six years of EmilyAI: what we kept, what we changed, what we should have done sooner
Post 20 of the AI series. A longer reflective piece. Eight years on from the first sketch of the system that became EmilyAI, six years on from production deployment, the architectural retrospective the series has been building toward.
-
DeepSeek and the supply chain of intelligence
Post 19 of the AI series. The open-weight reasoning models from DeepSeek and others have changed the supply chain of intelligence. The provenance, licensing, and operational properties of the models you run are now a cyber security question worth taking seriously.
-
Year in cyber AI 2025: the agentic year that mostly was not
Post 17 of the AI series. The 2025 retrospective. Operator agents arrived but mostly in pilot, the determinism property went mainstream in procurement, the regulators caught up, and constrained agency became the named shape. The honest read going into 2026.
-
Frontier AI in CNI: the regulators are paying attention
Post 16 of the AI series. The autumn joint statements from the BoE, FCA and HM Treasury on frontier AI and operational resilience signal where financial-services regulators have arrived. The implications for AI in cyber security are sharper than the public conversation suggests.
-
Determinism and regulatory defensibility, eighteen months later
Post 14 of the AI series. The bit-identical-inference property I wrote about in 2024 is showing up in regulatory drafting. What the Cyber Security and Resilience Bill drafting work suggests about how regulators are going to evaluate AI-driven security decisions.
-
Agents in production, eighteen months on
Post 13 of the AI series. The agent demos at RSA and Black Hat have got slicker. The agent in production cyber operations has, mostly, not arrived. The honest 18-month read on a category whose marketing has run ahead of its engineering.
-
Continuous learning at scale
Post 11 of the AI series. EmilyAI has been learning from analyst feedback for six years. The LLM-as-frozen-artefact shape gets the operational properties of *the model that improves over time* structurally wrong. What that means in practice.
-
Computer Use and the operator question
Post 10 of the AI series. Anthropic's Computer Use, OpenAI's Operator, Google's Project Astra. The category where AI literally moves the mouse. What this shape changes for cyber operations — and how it reads against EmilyAI's tighter action vocabulary.
-
Year in cyber AI 2024: what was real, what was not
Post 9 of the AI series. The 2024 retrospective. Six security copilots shipped; one major outage reshaped the resilience conversation; reasoning models arrived; agents mostly did not. The honest read going into 2025.
-
Agentic AI, year one: the demo vs the deployment
Post 8 of the AI series. AI agents in cyber operations have been demoed everywhere this year. The agent that actually ships looks different from the demo. The honest read after twelve months — and the shape of agent EmilyAI already is, not by accident.