Writing

Technical writing on deterministic enforcement, verifiable receipts, and accountable AI systems. In July 2026 this section was taken down and every post is being re-checked, claim by claim, against the current system before it returns — the same discipline the product sells. Posts reappear here as they pass.

NIST AI RMF and Agentic AI: Evidence for Manage 2.4, Measure 2.4 and Manage 4.1 — what a pre-execution gate's receipt chain evidences for three NIST controls, and the organisational half of each control that it does not touch. Written in the machine-readable register. Re-checked and republished 24 July 2026.
Who Is Accountable When a Multi-Agent AI Swarm Fails? — in July 2026 a group of agents ran a five-day intrusion and coordinated through a channel no orchestrator observed, so a complete audit log would have contained none of it. The attribution problem, the delegation-chain gap in every current agent protocol, where the regulation sits, and the strongest argument that all of this is overstated. Published 21 August 2026.
Are AI Agent Logs Discoverable? Rule 26, Spoliation, and the Record You Cannot Make Later — a regulatory deadline names a date and gives you time; discovery reaches backwards and asks what you already kept. What US courts did in 2026, why reconstruction is a weaker object than a record, and the four properties a record needs when someone hostile reads it. Published 17 August 2026.
Which Agentic AI Tools Are ISO 42001 Certified? — none of them, and none can be: the standard certifies an organisation's management system within a defined scope, not a product. What a certificate actually covers, and the three questions that do separate vendors. Published 17 August 2026.
ISO/IEC 42001 for Agentic AI: The Certification Evidence Gap That Policies Can't Close — certification auditors want evidence a control ran, not a policy that says it should; the receipt chain is the reconstruction Annex A.6.2.8 asks for, and the human-oversight control stays yours. Re-checked and republished 17 August 2026.
Pre-Action Authorization for AI Agents: The Missing Security Layer — an independent adversarial study found social-engineering attacks succeeded 74.6% of the time under permissive policy, and 0% across 879 attempts behind a pre-action authorization gate. Re-checked and republished 22 July 2026.
Cryptographic AI Audit Trail: What the Cryptography Actually Proves — a regular log records what happened; a cryptographic trail proves it, with Ed25519 signatures that break on any modification and a hash chain an independent archive can catch being rewritten. Re-checked and republished 22 July 2026.
Policy as Code for AI Agent Enforcement: What It Means and How It Works — declaration without enforcement is documentation; the gate is what makes the code operative, and the doer cannot self-attest. Re-checked and republished 18 July 2026.
When an AI Agent Skips a Step, Your Audit Log Shows a Clean Run — supplying the workflow raised missing-step failures to 57%, clinicians override 90% of safety alerts, and a regulator has ruled the record need not show that AI wrote the entry. Published 5 August 2026.
Who Audits the AI? Not the Company That Sold It to You. — auditor independence applied to agents: the party being measured cannot own the instrument, which disqualifies every agent vendor and orchestration framework. Two tests, run on us as well. Published 5 August 2026.
Procedural Hallucination: Why AI Agents Skip Steps and Report Success — the same failure has at least twelve names and no settled one, which is why nobody can search for it. The formal definition, the published measurements (38.5% of failures, best trained detector at ROC-AUC 0.689), and a sealed, publicly verifiable example. Published 8 August 2026.
EU AI Act August 2026: The High-Risk Deadline Moved to December 2027 — the date moved and the obligations did not. What Article 12 actually says for a non-biometric system, why the minimum content list everyone quotes applies only to biometric identification, and the one record a post-hoc log structurally cannot produce. Re-checked and republished 10 August 2026.
Orchestration vs Enforcement: Your Task Graph Stops Agents Skipping Steps. It Cannot Prove They Didn't. — state machines and task graphs fix the runtime problem and leave the evidential one open, because a skipped step writes no log line. Published 5 August 2026.
IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't — the draft's hash-chained record format, its trust levels, and the pre-execution gap it leaves open. Re-checked and republished 18 July 2026.
Tamper-Evident AI Agent Audit Logs: Deterministic Replay, Cryptographic Receipts, Fail-Closed — the six requirements for an audit log that survives regulatory scrutiny, and why the model can never be trusted to write its own. Re-checked and republished 18 July 2026.
Deterministic vs Probabilistic AI Agents: Why the Distinction Matters for Deployment — the core distinction, what regulators actually ask, and how an external gate makes a probabilistic model's execution path provable. Re-checked and republished 18 July 2026.

Some of these arguments also exist in a flat, machine-readable register — definitions first, claims welded to their qualifiers — written for how agents and language models read the web. They live in Notes for Machines.

Looking for the formal side? The enforcement specification and the published briefs — provable safeguards, evidence completeness, sector gap analyses for NZ health and NZ education — live under /spec/.