The precautionary case — what happens when AI architecture gets it wrong, and the thinking behind why we build the way we do.
Mixing instructions with data — the original sin of computing — is now scaling to catastrophic levels with autonomous AI agents. Here's why prompt injection is the foundational vulnerability of the age.
Read publicationThe fix for prompt injection already exists — we built it once, in the telephone network, and then destroyed it ourselves for commercial reasons. It's called channel separation.
Read publicationUC Berkeley's StruQ paper (USENIX Security 2025) implements channel separation for LLMs, reducing prompt injection success to near zero — while maintaining utility.
Read publicationThree words, three different ways AI can go wrong. They're not synonyms — confusing them will cost you dearly. A framework for telling them apart.
Read publicationWhy AI safety has to be structural, not trained in — the unabridged version of the argument summarized on the About page.
Read publicationWhy AI alignment requires architectural decentralization: centralized LLMs concentrate risk and eventually collapse under their own synthetic feedback loops.
Read publicationHuman-generated text is nearly exhausted, and synthetic data causes model collapse. How spiking neural networks generate grounded knowledge instead of just consuming it.
Read publicationThe convergence nobody asked for: what happens the first time an autonomous AI agent takes a consequential action in the world — and who's actually responsible.
Read publicationThe boiling-frog story is a myth, but the complacency it describes isn't. On the temptation to keep turning up the heat on systems that seem fine — right up until they aren't.
Read publicationAI is about to make your résumé irrelevant. That's not a threat — it's an opportunity, if you know what to do with it.
Read publication