Insights
Blog
Current news, field analysis, and technical thinking about supervising consequential AI and making covered control decisions independently checkable.
The OVERT series
Explainers on verifiable AI, runtime attestation, and signed records of what configured controls reported, with source truth, effectiveness, and coverage assessed separately.
AI Security Solutions That Leave a Receipt
Alerts can be complemented by signed OVERT records of covered control decisions. Verification checks record integrity and attribution, not source truth or effectiveness.
After a Prompt Injection Attack, Prove What Held
Prevention is imperfect. Preserve tamper-evident records of what configured guardrails reported, then pair them with routing, testing, and coverage evidence.
Agentic AI Security Needs Proof, Not Promises
Agentic AI security needs more than unstructured logs. Signed records can make covered actions and reported control outcomes checkable without claiming complete execution truth.
AI Agent Security: Enforce Actions, Preserve Evidence
AI agent security means enforcing controls at the action boundary and creating signed records of requested actions, applied controls, and recorded outcomes.
AI in Cyber Security: The Missing Evidence Layer
Signed operational records can make bounded AI control claims independently checkable, with explicit limits on coverage and effectiveness.
AI Data Security: Verify a Receipt, Not the Data
How a signed OVERT record can make supported properties of a reported control result checkable, with payload locality treated as deployment-specific.
What Makes AI Attestation Independently Verifiable?
A signed artifact can make covered fields and reported outcomes independently checkable. It does not prove complete coverage, control effectiveness, safety, data locality, or signer independence.
Your AI Governance Documentation Isn’t Evidence
Documentation records intent. Signed operational records can make covered claims checkable without proving complete coverage, safety, or control effectiveness.
AI Governance Tools Need Operational Proof
Governance records intent. Operational records preserve what configured controls reported for covered actions.
An AI Governance Maturity Model: From Policy to Proof
Move from policy to configured controls and independently checkable records for covered events, with scope and exclusions made explicit.
AI Governance Challenges: The One No One Names
Most AI governance challenges begin with intent. The execution question is which controls were in scope, what they reported, and which evidence supports that account.
What Is AI Governance? Intent vs. Proof
AI governance directs AI through policy, ownership, testing, and review. Scoped operational evidence can make selected control-path claims independently checkable without proving effectiveness or complete coverage.
Why our new CTO left Microsoft after 19 years
Rohit Tatachar joins as co-founder & CTO after nearly two decades at Azure. The inside story.
A proposed framework for healthcare AI risk
Standards-based research with illustrative composite cases, not a coverage commitment.
We couldn’t ship our own AI
The historical launch story, updated for OVERT 1.1 and bounded operational evidence.
Voluntary AI safety commitments keep changing
A dated analysis of why changeable commitments need operational controls and inspectable evidence.
ViVE 2026: Healthcare AI gets asked for its receipts
We’re in LA Feb 22–25. The AI accountability conversation healthcare has been building toward.
Healthcare AI gets real. Proof comes due.
A retrospective on changing law, consent litigation, and demand for scoped operating evidence beyond promises.
The three layers of AI security
Most AI security solutions cover runtime protection. But there’s a critical third layer.
EU AI Act Healthcare: what to know
Specified healthcare AI uses may be high-risk depending on intended purpose, role, and classification route; applicable logging duties are system-specific.
When AI hallucinations become malpractice
“One beer at a wedding” becomes “daily heroin use.” Without evidence, who’s liable?
Why SOC 2 won’t protect you from AI risk
SOC 2 and HITRUST are essential for IT security. But they weren’t designed for AI.
Colorado AI Act for Healthcare vendors
Colorado repealed and replaced its 2024 AI Act with SB 26-189, covering automated decision-making technology from January 1, 2027.
Building AI trust through evidence
The difference between “we have guardrails” and “here’s proof.”
How we used AI without a BAA
Deploying an in-line redaction proxy that strips PHI before it reaches external APIs.
Why we built GLACIS on Cloudflare
Why distributed edge infrastructure matters for low-latency supervision and operational evidence.
ISO 42001: is certification worth it?
Costs, benefits, and limitations. When certification makes sense vs. using the framework internally.
Evidence for the deals, audits and reviews ahead
Runtime coverage gives AI vendors signed evidence for deals, audits and internal assurance, at whatever scope the deployment needs.
Talk to us