Skip to content
IC

Blog

Field notes on AI governance, written by a practitioner.

Long-form writing for risk, security, and board readers. Framework-anchored, regulator-literate, and informed by what actually happens in mid-market deployments.

AI research

The state of AGI: what the evidence supports, and what it does not

A sober read of the AGI evidence in 2026: what frontier systems can measurably do, what expert forecasts actually say, how seriously to take the existential question, and what the research shows about humans and AI working together.

12 September 2026 · 10 min read · Mathew Sayed
Read the full piece

AI research

The state of AGI: what the evidence supports, and what it does not

A sober read of the AGI evidence in 2026: what frontier systems can measurably do, what expert forecasts actually say, how seriously to take the existential question, and what the research shows about humans and AI working together.

12 September 2026 · 10 min

AI governance

The AI register: the audit artefact every framework now assumes you have

Auditors, regulators, and insurers now open with the same request: show me the list of your AI systems. What an AI register is, what ISO 42001, NIST AI RMF, the EU AI Act, and Australian government policy expect it to contain, and how to keep one alive.

12 September 2026 · 9 min

Security leadership

Fractional CISO services in Australia: cost, scope, and when the model works

What a fractional CISO actually does, what the role costs in Australia, the failure modes nobody advertises, and where the always-on digital CISO fits next. A straight guide for mid-market boards weighing their security leadership options.

3 September 2026 · 10 min

AI · Supply chain

AI supply chain security: four ways code now enters your estate without a vendor review

Model weights, agent skills, MCP servers and packages your coding assistant invented all execute in your environment, and none of them trigger a vendor assessment. The documented incidents, the measured scale, and the controls that close the gap before CPS 230 makes it an audit finding.

30 August 2026 · 19 min

AI · Security operations

The agentic SOC is real, and your logs are now prompts: how AI security monitoring actually works, and where it breaks

Microsoft, Google and CrowdStrike now ship autonomous agents that triage alerts in real time with no analyst in the loop. What agentic SOC tooling actually does, the research showing attackers can prompt-inject it through ordinary log fields, and the control set that holds under APRA scrutiny.

30 August 2026 · 29 min

Cryptography

Managing cryptography in the post-quantum era: what businesses need to do now, and the attacks already hitting encryption

The post-quantum standards are finalised and ASD's Information Security Manual stops approving RSA and elliptic-curve cryptography after the end of 2030, ahead of most of the world. The operational playbook: the attacks on encryption happening now, the honest quantum timeline, and how to run the migration.

3 August 2026 · 12 min

Stay informed

Get new posts by email.

One email a fortnight. Long-form content only, no promotional sequences. Unsubscribe at any time.

Get started

Bring AI risk under board oversight in two weeks.

A thirty-minute discovery call costs nothing. We confirm fit, scope, and timing, then issue a fixed-fee statement of work within two business days.