What human psychology can teach us about AI agent drift

I recently gave a presentation on the Behavioural Analysis for Multi-Agent Systems. The idea at its centre is simple. AI agents drift from their intended goals in much the same way people drift from security policy, and psychology has spent decades learning to read that kind of behaviour. I explore some key themes in this blog.

More

Unprompted: at the intersection of state-of-the-art AI and cybersecurity research

It was great to learn more about the state-of-the-art research in cybersecurity applications of AI, both from the attacker and defender’s perspectives at the Unprompted conference in Sydney today.

The talks from engineers at OpenAI, Google, Microsoft, TikTok, Slack and many others demonstrated the practical use cases for threat hunting, vulnerability discovery, detection and response to speed up and automate workflows.

Safety, cost management and scale were the top themes for me – you don’t always need the latest model for every task, deterministic scripts can complement your agentic AI pipelines, guardrails and alignment are still key. Best results live at the intersection of system automation and human judgment.

And, of course, it’s the people who make events like this so worthwhile – it was good to catch-up with old friends (and make some new ones) and exchange ideas and research. AI and cybersecurity is a team sport. Reach out if I can help.

I look forward to experimenting and applying technical insights at work.

Securing critical national infrastructure

I had a great time talking to Peter Davidoff from the Australian Government about the evolving approach to security.

We touched on the challenges and opportunities of securing critical national infrastructure, the increasing role of AI and practical examples of developing a defence-in-depth approach to security architecture.

A big thanks to the audience for great questions!

The intersection of AI and Cyber

It was great to share my thoughts on the intersection of AI and Cyber.

I kept it practical and worked through three key dimensions: how AI is changing the defender’s day-to-day, how we secure AI itself and how we defend when AI becomes the threat.

It was particularly relevant given the latest frontier model releases, like Anthropic’s Fable / Mythos (and OpenAI’s GPT-5.5-Cyber) and their applications to cybersecurity.

If attackers and defenders now have the same AI capabilities, your advantage comes not from the tools but from your people, your data and how well you’ve done the fundamentals.

Grateful to the panel and to everyone who put their hand up and got stuck into the discussion.

AWS Summit 2026: AI is moving fast, security is catching up

There is a shift happening in how the industry talks about agentic AI security. A year ago the conversation was speculative – what might go wrong, what we might do about it. Now it is specific. The platforms, primitives and patterns for operating agents safely exist as named things you can point at on a slide. The vocabulary is converging across vendors. The reference architectures are documented.

In this blog I explore the themes that mattered most, and what they mean for security teams.

More

AI-enabled security at the speed of business

Today, organisations are caught between two opposing forces. On one side is the drive for operational efficiency through digital transformation and AI adoption. On the other is an asymmetric cyber threat landscape.

As adversaries leverage AI to increase the scale and sophistication of attacks overwhelming already stretched cyber teams, defenders must do the same by using AI to strengthen security.

The traditional security model is reactive. When a threat is detected, a human must review, validate and remediate. In the time it takes an analyst to finish their first coffee, an AI-driven adversary can exfiltrate sensitive data.

For organisations that depend on customer trust and regulatory compliance, “responding as fast as we can” is no longer within risk appetite. Humans cannot scale to match the speed of automated code.

AI is becoming central to the future of cyber defence. While much of the industry focuses on automating security operations triage, the true power of AI lies in automating complex, proactive security and compliance functions that previously required thousands of human hours.

More

Governing AI – where should we draw the line?

As AI adoption accelerates, leaders face the challenge of setting clear boundaries, not only around what AI should and shouldn’t do, but also around who holds responsibility for its oversight.

It was great to share my thoughts and answer audience questions during this panel discussion.

Governance must be cross-functional: security, risk, data and the business share accountability. I also reinforced the importance of guardrails, particularly forAgentic AI: automate low-risk work, but keep humans in the loop for decisions that affect safety, rights or reputation. Classify models and agents by impact and apply controls accordingly.

Governing AI Agents

Introduction to Agents (Google)

As organisations accelerate AI adoption, a familiar pattern is emerging: security teams – often the CISO – are increasingly asked to own or coordinate AI governance. That outcome is not an accident. Security leaders already operate across departmental boundaries, manage data inventories, run cross-functional programs and are trusted by executives and boards to solve hard, systemic problems. AI initiatives are inherently cross-disciplinary, data-centric and integrated into product and vendor ecosystems, so responsibility naturally flows toward teams that already do that work. This operational reality creates an opportunity: security can (and should) move from firefighting to shaping safe adoption practices that preserve value and reduce harm.

In this blog I outline key strategies on how to be successfully in leading AI governance initiatives in your organisation.

More

AI Agents and Security

We are entering the agentic era – an inflection point defined by AI systems that can reason, plan and take action autonomously. This shift may be among the most consequential technological transformations of our generation, and it carries an equally significant obligation: to ensure these systems are designed, governed and deployed in ways that earn and sustain trust.

I completed a 5-Day AI Agents Intensive Course where we dove deep in Google’s open source Agent Development Toolkit. In this blog, I’ll share key takeaways and practical suggestions so you can navigate this shift and learn to build AI agents of your own.

More

FinTech, AI and Cyber

I recently took the stage to talk about one of the most consequential inflection points facing FinTech: the rapid arrival of agentic AI – systems that plan, decide and act autonomously – and what it means for risk, reputation, regulation and customer trust. Below is a distillation of the talk: what agentic AI actually is, why FinTechs are racing to adopt it, the real cyber threats it brings, and a pragmatic playbook leaders can use today.

More