The IV Minute Update

Branchenanalyse und technische Texte.

Architektonische Argumente, Bewertungen Framework für Framework und die Fragen, die jeder CISO den Anbietern von KI-Agenten-Governance stellen sollte.

How Secure Are Your AI Agents?

The Security Frameworks That Should Govern Them — and Don't
A framework-by-framework evaluation of STRIDE, NIST CSF, OWASP, SOC II, and HIPAA — and the VIII questions every CISO should be asking their vendor right now.
Artikel lesen → LinkedIn·Teilen
The IV New Standard

The Floor Series.

Acht architektonische Argumente unter öffentlicher Beobachtung, also die veröffentlichte Begründung dafür, warum Governance, Security und Vertrauen Eigenschaften des Fundaments einer Plattform für KI-Agenten sein müssen und keine Features obendrauf. Erschienen vor The Inversion; die am Paradigma ausgerichtete Neuveröffentlichung kommt mit v3.0.

Why Pouring the Foundation After You Build the House Doesn't Work
Look at how the AI industry approaches alignment. Pre-training ingests the entire internet without value discrimination — the model learns everything, including what it should never reproduce. Only afterward is alignment applied, through RLHF, fine-tuning, and constitutional methods: values retrofitted onto a worldview that has already formed. The result performs well in evaluation but behaves unpredictably in deployment, because the values were never the foundation. They were the paint.
LinkedIn·Teilen
The Retrofit Tax — Why bolt-on AI costs more than built-in AI
When you bolt a foundational property onto an architecture that was not built to hold it, the property fights the architecture. The friction shows up as cost. In artificial intelligence, this happens at three points across the lifecycle, and each one creates its own line item.
LinkedIn·Teilen
Beyond the Floor — Five layers of runtime defense
The architectural commitment that produces the floor — refusing to retrofit values, security, or governance onto frameworks not built to hold them — does not stop at the floor. The same engineering instinct that produced the foundation produced what sits on top of it. What follows describes that structure: five layers of runtime defense that together constitute a category-defining detection-and-response architecture for agentic AI. Readers who have followed the series will recognize the shape of the argument; those who haven't will see what an AI agent platform looks like when it's engineered, from the foundation up, for the loads ahead.
LinkedIn·Teilen
Why AI Alignment Fails: The Retrofit Problem
A child learns that hot means don't touch before they learn thermodynamics. They learn empathy before they learn history. They learn that actions have consequences before they learn the consequences are complex. This is not an accident of human development. It is the architecture of it. Decades of developmental psychology — Piaget, Kohlberg, Vygotsky — confirm that moral reasoning develops in stages, that each stage requires completion of the prior one, and that the sequence matters as much as the content.
LinkedIn·Teilen
Why Controllable AI Is Earned Continuously, Not Trained Once
Corrigibility — the property that lets an AI agent be corrected, redirected, or stopped by its overseers without resistance, deception, or workaround — has lived for years as a philosophical category in alignment research. It is now moving, visibly, into the language of regulators, auditors, boards, and procurement. The EU AI Act's human-oversight provisions, the NIST AI RMF's accountability requirements, and the AI-controllability attestations now appearing in enterprise vendor questionnaires are early markers of the same pattern. Cyber posture took roughly a decade to move from technical concern to board-level compliance requirement. AI controllability is running the same arc on a faster clock.
LinkedIn·Teilen
The Attack You Can't See Is Spread Across Everything You Can
Because that scenario is not an edge case. It is the general condition of risk in an enterprise running AI at scale. The dangerous patterns do not live inside one signal stream; they live across streams. A sophisticated adversary has every incentive to keep each individual signal unremarkable: small enough to pass thresholds, slow enough to blend into noise, distributed enough that no single monitor ever holds two pieces of the picture at once. Attack strategies are built this way deliberately, because attackers know exactly what defenders watch: streams, one at a time.
LinkedIn·Teilen
Don't Just Prevent the Attack — Trap the Attacker
An umbra is the darkest part of a shadow. It is a fitting name, because the shadows are exactly where an attacker expects to operate: unseen, unmeasured, working quietly in the space no one is watching. Inside Loriqa, that space is not empty. Umbra is already there, waiting — and the attacker will never know it.
LinkedIn·Teilen
Why AI Costs Spiral When Economic Governance Isn't Architected
The deciding factor in enterprise AI adoption is no longer what the technology can do — it is whether anyone can prove what it returned. The case for the Budget Boundary: policy enforced before the spend, nothing failing open, and every dollar carrying its own explanation.
LinkedIn·Teilen
In Arbeit

Weitere Texte

SOC II and HIPAA in the age of autonomous agents
Compliance frameworks weren't built for non-deterministic software.
Regulated industries and AI: compliance is a procurement gate
Governance isn't a feature — it's a precondition.
VIII questions every CISO should ask their AI agent vendor
A short, practical evaluation framework for procurement teams.

Forschungsartikel zu KI-Training mit Werten zuerst und zum entwicklungsorientierten Ansatz beim Alignment sind umgezogen nach IV Research.

Über das Produkt hinaus