Prompt Injection Is a Data Problem: A Threat Model You Can Ship Against
Prompt injection can't be filtered away: the model can't reliably tell instructions from data. Here's the actual threat model and the controls that hold up.
Read →Working notes on shipping AI in production: what breaks between demo and deployment, what's worth buying instead of building, and how we test the parts that matter.
Prompt injection can't be filtered away: the model can't reliably tell instructions from data. Here's the actual threat model and the controls that hold up.
Read →An agent that nails the demo stalls in production because reliability compounds across steps. Here's the math, the real failure modes, and how to ship one anyway.
Read →A modeled, reproducible benchmark of cost-per-successful-outcome across four common AI workloads, with every token assumption, price, and overhead multiplier shown.
Read →Models change under you every few months: price, quality, and capability. Here's why we never hardcode a single provider into a client's feature.
Read →Retrieval that looks flawless on ten clean PDFs falls apart on a real corpus. Here's why, and what evaluating retrieval quality actually requires.
Read →Token costs that look trivial in a demo compound fast at scale. Here's how to make cost a first-class metric instead of a surprise on the invoice.
Read →Shipping an AI feature without an eval suite in CI means every prompt tweak is a guess. Here's what an eval suite actually needs to cover.
Read →A technically honest framework for deciding whether an AI initiative should be built in-house, bought off the shelf, or skipped entirely this year.
Read →The gap between a working AI demo and a production feature is auth, latency, cost and fallbacks. Here's how we close it without a rewrite.
Read →No insights match that filter yet.