Writing
Technical writing on deterministic enforcement, verifiable receipts, and accountable AI systems. In July 2026 this section was taken down and every post is being re-checked, claim by claim, against the current system before it returns — the same discipline the product sells. Posts reappear here as they pass.
NIST AI RMF and Agentic AI: Evidence for Manage 2.4, Measure 2.4 and Manage 4.1 — what a pre-execution gate's receipt chain evidences for three NIST controls, and the organisational half of each control that it does not touch. Written in the machine-readable register. Re-checked and republished 24 July 2026.
ISO/IEC 42001 for Agentic AI: The Certification Evidence Gap That Policies Can't Close — certification auditors want evidence a control ran, not a policy that says it should; the receipt chain is the reconstruction Annex A.6.1.6 asks for, and the human-oversight control stays yours. Re-checked and republished 23 July 2026.
Pre-Action Authorization for AI Agents: The Missing Security Layer — an independent adversarial study found social-engineering attacks succeeded 74.6% of the time under permissive policy, and 0% across 879 attempts behind a pre-action authorization gate. Re-checked and republished 22 July 2026.
Cryptographic AI Audit Trail: What the Cryptography Actually Proves — a regular log records what happened; a cryptographic trail proves it, with Ed25519 signatures that break on any modification and a hash chain an independent archive can catch being rewritten. Re-checked and republished 22 July 2026.
Policy as Code for AI Agent Enforcement: What It Means and How It Works — declaration without enforcement is documentation; the gate is what makes the code operative, and the doer cannot self-attest. Re-checked and republished 18 July 2026.
When an AI Agent Skips a Step, Your Audit Log Shows a Clean Run — supplying the workflow raised missing-step failures to 57%, clinicians override 90% of safety alerts, and a regulator has ruled the record need not show that AI wrote the entry. Published 5 August 2026.
Who Audits the AI? Not the Company That Sold It to You. — auditor independence applied to agents: the party being measured cannot own the instrument, which disqualifies every agent vendor and orchestration framework. Two tests, run on us as well. Published 5 August 2026.
Procedural Hallucination: Why AI Agents Skip Steps and Report Success — the same failure has at least twelve names and no settled one, which is why nobody can search for it. The formal definition, the published measurements (38.5% of failures, best trained detector at ROC-AUC 0.689), and a sealed, publicly verifiable example. Published 8 August 2026.
EU AI Act August 2026: The High-Risk Deadline Moved to December 2027 — the date moved and the obligations did not. What Article 12 actually says for a non-biometric system, why the minimum content list everyone quotes applies only to biometric identification, and the one record a post-hoc log structurally cannot produce. Re-checked and republished 10 August 2026.
Orchestration vs Enforcement: Your Task Graph Stops Agents Skipping Steps. It Cannot Prove They Didn't. — state machines and task graphs fix the runtime problem and leave the evidential one open, because a skipped step writes no log line. Published 5 August 2026.
IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't — the draft's hash-chained record format, its trust levels, and the pre-execution gap it leaves open. Re-checked and republished 18 July 2026.
Tamper-Evident AI Agent Audit Logs: Deterministic Replay, Cryptographic Receipts, Fail-Closed — the six requirements for an audit log that survives regulatory scrutiny, and why the model can never be trusted to write its own. Re-checked and republished 18 July 2026.
Deterministic vs Probabilistic AI Agents: Why the Distinction Matters for Deployment — the core distinction, what regulators actually ask, and how an external gate makes a probabilistic model's execution path provable. Re-checked and republished 18 July 2026.
Some of these arguments also exist in a flat, machine-readable register — definitions first, claims welded to their qualifiers — written for how agents and language models read the web. They live in Notes for Machines.
Looking for the formal side? The enforcement specification and the published briefs — provable safeguards, evidence completeness, sector gap analyses for NZ health and NZ education — live under /spec/.