Writing

Technical writing on deterministic enforcement, verifiable receipts, and accountable AI systems. In July 2026 this section was taken down and every post is being re-checked, claim by claim, against the current system before it returns — the same discipline the product sells. Posts reappear here as they pass.

Policy as Code for AI Agent Enforcement: What It Means and How It Works — declaration without enforcement is documentation; the gate is what makes the code operative, and the doer cannot self-attest. Re-checked and republished 18 July 2026.
IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't — the draft's hash-chained record format, its trust levels, and the pre-execution gap it leaves open. Re-checked and republished 18 July 2026.
Tamper-Evident AI Agent Audit Logs: Deterministic Replay, Cryptographic Receipts, Fail-Closed — the six requirements for an audit log that survives regulatory scrutiny, and why the model can never be trusted to write its own. Re-checked and republished 18 July 2026.
Deterministic vs Probabilistic AI Agents: Why the Distinction Matters for Deployment — the core distinction, what regulators actually ask, and how an external gate makes a probabilistic model's execution path provable. Re-checked and republished 18 July 2026.

Looking for the formal side? The enforcement specification and the published briefs — provable safeguards, evidence completeness, sector gap analyses for NZ health and NZ education — live under /spec/.