peter bassill · operator

AI — writing by Peter Bassill

peter@hardened:~$ ls -t writing/ai/

AI · page 2 of 2

AI in defence, AI as a risk, and the governance in between. 23 articles

  • AI

    AI-powered threats — and the usage policy you actually need

    AI is making phishing better and deepfake fraud cheaper. It is also a real risk when your own staff paste customer data into ChatGPT. Both sides of the AI coin, and a simple policy that handles both.

    • 6 min read
  • AI

    Reasoning models: what o1 changes for SOC work

    Post 7 of the AI series. OpenAI's o1 launched in September with a different model shape — *think longer, reason step by step*. What this means for the SOC, where the gains are real, and where EmilyAI's purpose-specific architecture continues to win.

    • 7 min read
  • AI

    Open-source models and the on-prem option

    Post 5 of the AI series. Llama 3, Mistral, Mixtral. The serious open-source LLM era arrived in 2024. What it means for security teams who do not want to send data to a hyperscaler, and how the on-prem path reads against EmilyAI's single-tin posture.

    • 7 min read
  • AI

    The hexagonal lesson: vendor agnosticism as structure

    Post 4 of the AI series. Most security AI products are anchored to one vendor's platform. EmilyAI was built in 2018 with a hexagonal architecture that decouples the analyst from the SIEM matrix. Six years on, the choice is paying back in a way I did not anticipate.

    • 7 min read
  • AI

    The Copilot-for-security wave: what they actually do

    Post 3 of the AI series. Microsoft Security Copilot, CrowdStrike Charlotte, SentinelOne Purple, Google Sec-PaLM — the wave of LLM-powered security assistants. What they actually do well, what they do less well, and how the framing reads against EmilyAI.

    • 8 min read
  • AI

    Deterministic inference: the property the market is losing

    Post 2 of the AI series. Same input, same output, every time. A property that used to be table stakes in production systems and that LLM-based security tooling has quietly let go of. Why it matters and how EmilyAI is built to preserve it.

    • 7 min read
  • AI

    AI in cyber: the long view from 2018

    Start of a six-weekly series tracking how AI in cyber security is developing through 2024 and beyond — and how each development reads against EmilyAI, the SOC analyst I have been running in production at Hedgehog since 2018.

    • 6 min read
  • AI

    INT8 quantisation, in numbers — and why INT16 is the boring choice

    What "INT8-quantised inference" actually means once you do the arithmetic, why dropping from FP32 to INT8 is a cliff and dropping to INT16 isn't, and why every interesting question about putting an ML model on real silicon ends up here.

    • 11 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…