Ideas on agentic AI, security and responsible automation
Practical writing on deploying AI agents safely: architecture decisions, governance, incidents worth learning from, and where regulators are heading.
Why Client-Facing AI Should Be the Last Thing You Automate
A Canadian tribunal ruling on a chatbot's bad advice and new customer experience data both point the same way: automate the plumbing before you automate the conversation.
Read the post →Half of Canadian Municipalities Now Call AI a Top Priority. Few Can Explain What It's Doing.
New survey data shows municipal AI adoption has surged in a year, and Ottawa just opened a consultation on AI transparency. What that means for the next vendor contract.
Read the post →Your Staff Are Already Using AI Tools You Haven't Approved
New 2026 data shows AI adoption is running well ahead of AI policy. What the shadow AI numbers actually mean and the plain steps that close the gap.
Read the post →Alberta Doesn't Have an AI Privacy Law Yet. Build the Paper Trail Before It Does.
The regulator has pushed for AI rules since 2024 and other provinces have already moved. What to document now, before Alberta's version lands.
Read the post →Alberta's New Privacy Rules Just Kicked In. Does Your AI Use Fit Inside Them?
The deadline for Privacy Management Programs under POPA has passed. The AI notice requirement buried inside the act is the gap most programs still have.
Read the post →Where AI Automation Actually Pays Off for a Service Business
The best first automations are boring: intake, scheduling, reminders. A practical look at where automation earns its keep, and where it quietly causes damage.
Read the post →Agentic AI Security Is an SME Problem, Not Just an Enterprise Problem
The incidents making headlines didn't happen at enterprises. They happened at small companies with lean teams and no dedicated security function.
Read the post →SynJack and the Problem of Implicit Trust in Agent Tooling
Researchers tricked AI coding assistants into remote code execution. All six tools tested were vulnerable. The pattern matters more than the technique.
Read the post →Test Your AI Agents Before They Touch Production
Microsoft open-sourced a framework for testing agents against prompt injection and data exfiltration. Most SMEs won't use it, but the principle applies at every scale.
Read the post →Agentic AI Security Isn't a Product You Buy
Enterprise vendors have declared agentic AI their next platform. They're right that it's a board-level conversation, and wrong about what it should produce.
Read the post →Five Eyes Just Issued Joint Guidance on Agentic AI. Here's Why It Matters.
The first coordinated multinational policy on a single AI attack surface. Agentic AI security just became a national security imperative.
Read the post →Can Our Staff Use ChatGPT? The Question Every Municipality Should Answer on Paper
Staff are already using AI tools, with or without permission. The fix isn't a ban. It's a clear, written answer to what's allowed, what isn't, and why.
Read the post →The Minimum Controls Checklist for Deploying AI Agents
Six controls to have in place before an agent touches production. The short list that would have prevented most recent incidents.
Read the post →AI Isn't Moving Too Fast. You're Deploying Blind.
Nearly half of organizations deploying AI agents have zero visibility into what those agents are doing. Caution without visibility isn't safe.
Read the post →Nine Seconds: What the PocketOS Database Deletion Teaches Us About Agent Architecture
An AI coding agent deleted a production database and its backups in nine seconds. The failure wasn't the AI. It was a chain of architecture decisions.
Read the post →Semantic Privilege Escalation: When Your AI Agent Drifts Without Breaking a Rule
Copilots suggest. Agents decide, then act. Why review-and-approve security doesn't cut it anymore, and what agent integrity actually requires.
Read the post →