<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[David at SenTeGuard]]></title><description><![CDATA[Founder of SenTeGuard. Regain Control of your Ideas]]></description><link>https://www.letters.senteguard.com</link><image><url>https://substackcdn.com/image/fetch/$s_!au9C!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15595b1a-6a9e-4dd6-adcc-bb36c4acb1fd_648x648.png</url><title>David at SenTeGuard</title><link>https://www.letters.senteguard.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 19 Sep 2026 23:01:41 GMT</lastBuildDate><atom:link href="https://www.letters.senteguard.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[SenTeGuard]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[davidsente@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[davidsente@substack.com]]></itunes:email><itunes:name><![CDATA[David]]></itunes:name></itunes:owner><itunes:author><![CDATA[David]]></itunes:author><googleplay:owner><![CDATA[davidsente@substack.com]]></googleplay:owner><googleplay:email><![CDATA[davidsente@substack.com]]></googleplay:email><googleplay:author><![CDATA[David]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[September Update]]></title><description><![CDATA[Moyo Product Launch]]></description><link>https://www.letters.senteguard.com/p/september-update</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/september-update</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Fri, 18 Sep 2026 12:31:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!au9C!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15595b1a-6a9e-4dd6-adcc-bb36c4acb1fd_648x648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friends and Readers,</p><p>Thank you for keeping in touch.  Since my last email I have launched my moyo open-source intelligence tool and have started serving customers who don&#8217;t know me personally. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Check out the tool <a href="https://moyo.senteguard.com/exposure">here</a> to find out what the AIs know about you, your organization or you competitors. 30 second intro <a href="https://youtube.com/shorts/xeJhh_ZOabs">here </a>and <a href="https://youtube.com/shorts/m0qe5nBqOf4?feature=share">here</a>.<br></p><h2><strong>Writing Roll-Up</strong></h2><p><strong>Responses to Recent AI Uproar: </strong></p><ol><li><p>In the linked blog post / video / podcast, I argue that AI may create far more economic value for society than frontier AI companies can capture themselves without coercive regulation. As open models become &#8220;good enough&#8221; and AI productivity gains spread to billions of users, the biggest impact may come from diffusion and positive externalities rather than ever-more-powerful frontier models. <a href="https://senteguard.com/blog/frontier-ai-firms-wont-reap-the-reward">Link, </a><a href="https://www.letters.senteguard.com/p/frontier-ai-firms-have-built-something">Substack</a>, <a href="https://youtu.be/uL3YDTw0bKU">Youtube</a></p></li></ol><h2>Podcast - SenTe with David</h2><p><a href="https://www.youtube.com/playlist?list=PLCHQ6onuivSjw0aXyjKiCA2FTSPYVBowZ">Youtube</a> - <a href="https://open.spotify.com/show/033BYiKHEeBWNiHM1DlrMd">Spotify</a> - <a href="https://podcasts.apple.com/us/podcast/guarding-sente-with-david/id1896945614">Apple Podcasts</a> - <a href="https://api.riverside.com/hosting/jERlYWdl.rss">RSS Feed</a></p><p><strong>On Request:</strong></p><ul><li><p>Prototype testing of the<a href="https://senteguard.com/blog/sensitive-information-reachability-the-problem-and-the-solution-1768745959993"> Moyo</a> senstivie information red-teaming tool. Find vulnerabilities which allow access to your organizations secrets (classified, proprietary, personal) in public LLMs (ChatGPT, Claude, Qwen, Kimi, Grok, etc).</p></li></ul><p>David</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Frontier AI Firms Have Built Something Incredibly Valuable - But They Won’t Reap the Reward]]></title><description><![CDATA[Generated by ChatGPT]]></description><link>https://www.letters.senteguard.com/p/frontier-ai-firms-have-built-something</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/frontier-ai-firms-have-built-something</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Thu, 17 Sep 2026 15:30:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2xhB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2xhB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2xhB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!2xhB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!2xhB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!2xhB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2xhB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2683167,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/216144183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2xhB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!2xhB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!2xhB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!2xhB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe395ec9c-e2f9-4b3a-846a-86fc0f296fb4_1448x1086.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;">Generated by ChatGPT</p><p> <a href="https://youtu.be/uL3YDTw0bKU">Spoken</a>  <a href="https://senteguard.com/blog/frontier-ai-firms-wont-reap-the-reward">Original</a></p><p><strong><span>Who is Linus Torvalds?<br></span></strong><span>Linus Torvalds is a Finnish-American software engineer best known for creating the Linux kernel and later inventing Git, the version-control system that undergirds much of modern software development. It is impossible to calculate the value he has created for the world economy. However, his net worth is estimated at a humble $50 million, dwarfed by many of the tech billionaires who have become household names. In other words, the tech he built has yielded massive </span><em><span>positive externalities</span></em><span>: immense economic value that was created but not directly captured by its inventor.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p><strong><span>What is a Positive Externality and What Are Some Examples?</span></strong></p><p><span>A &#8220;positive externality&#8221; technology is one which generates societal benefit that exceeds the developers personal financial return. For example:</span></p><ul><li><p><span>The Printing Press: while Johannes Gutenberg was the inventor of the printing press, he personally met financial ruin. The true economic value of the Press lay in the portability of language and the broader dissemination of ideas.</span></p></li><li><p><span>Linux: Torvald&#8217;s open-source operating system became the basis on which countless companies built multi-billion dollar businesses. (Alphabet&#8217;s Android operating system for example)</span></p></li></ul><p></p><p><strong><span>An Analogy: Frontier v. Open-Source as Rock Climber</span></strong></p><p><span>Imagine the top AI models as a group of rock climbers.</span></p><ul><li><p><span>The lead climbers (frontier AI firms like Anthropic, OpenAI, xAI, Alphabet, etc.). They are more capable at climbing and at training the AI frontier. Because they are more skilled the lead climbers establish the routes and place protection.</span></p></li><li><p><span>The followers (open-source like DeepSeek, Kimi, Ollama, etc.). These firms come later.  By training their models on already established frontier models, in a process known as distillation, these firms approach the cutting edge faster than they otherwise would have given the work from the leaders.<br>Just as in rock climbing, sometimes lead climbers benefit from their fellow lead climbers - they use their routes or distill their models. Sometimes the followers lead in their own way as well, like when DeepSeek made massive efficiency improvements on model training in January 2025.</span></p></li></ul><p><span>In this way, followers and their user base capture the benefits of the positive externalities generated by model training investments financed by frontier AI firms, their investors and the American taxpayer.</span></p><p></p><p><strong><span>Stretching the Analogy - The AGI Thesis<br></span></strong><span>Under the AGI Thesis, the race between model developers has a finish line called Artificial General Intelligence, a &#8220;singularity&#8221; where AIs will be able to improve their own capabilities without limitation and achieve something like infinite (at least for all practical purposes) growth.  For the rock climbers we could imagine this AGI moment as the top of the cliff face - and the first climber to the top reaps the benefits of this infinite growth.<br><br>But what if there is no top? How do the firms provide value for customers?</span></p><ol><li><p><span>By their temporary lead over the followers. Or in AI terms: the difference in capability between the frontier and its cheaper competition.</span></p></li><li><p><span>By having ascended </span><em><span>high enough</span></em><span>. Or in AI terms - providing significant but not frontier-level capabilities at a discount to the frontier.</span></p></li></ol><p></p><p><em><strong><span>High enough</span></strong></em><strong><span> thesis</span></strong></p><p><span>Many will pay a premium for the best - no questions asked.  But let&#8217;s look at some numbers.</span></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P2sp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P2sp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 424w, https://substackcdn.com/image/fetch/$s_!P2sp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 848w, https://substackcdn.com/image/fetch/$s_!P2sp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 1272w, https://substackcdn.com/image/fetch/$s_!P2sp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P2sp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png" width="552" height="252" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:252,&quot;width&quot;:552,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:14471,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/216144183?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P2sp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 424w, https://substackcdn.com/image/fetch/$s_!P2sp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 848w, https://substackcdn.com/image/fetch/$s_!P2sp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 1272w, https://substackcdn.com/image/fetch/$s_!P2sp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbf6f5493-b35f-4f0e-9b4e-83a354ba0192_552x252.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><span><br>Capability: Moonshot (Alibaba&#8217;s AI arm) claims it &#8220;substantially outperformed&#8221; GPT-5.6 Sol and GPT-5.5 and performed &#8220;competitively&#8221; with Claude Fable 5. Kimi also claims that Independent testing puts it one tier below Fable 5 (Artificial Analysis Intelligence Index v4.3:).</span></p><p><span>Furthermore, Kimi&#8217;s weights are free to download on HuggingFace meaning you could run it yourself on rented infrastructure only paying the rental costs and not the above listed API costs.</span></p><p><em>This is not an advertisement for Chinese open models; it is advocacy for open-models in principle. If American / Western consumer preferences shift towards open models, American companies will be forced to shift with them. (See my America v China <a href="https://senteguard.com/blog/big-frontier-china-and-regulatory-capture">Article</a> for More)</em>.</p><p><span>So when you pay 3x the cost for Astral (or more) what do you get? You get results which are better to the extent Astral provides better results than Fable 5. </span><strong><span>Does anyone else remember several months ago when Fable 5 (n&#233; Mythos) was apocalyptically capable? </span></strong><span>This difference is imperceptible to me. I imagine it is also imperceptible for others in 99.9% of use cases. It seems likely that open models are already high enough on the mountain, and sufficiently cheaper than their closed-model competitors, that they will inevitably capture a substantial share of the market.<br><br></span></p><p><strong><span>Temporary-lead value thesis:</span></strong></p><p><span>If the AGI thesis doesn&#8217;t bear fruit, frontier firms may still achieve long-term profitability by monetizing the temporary capability gap between their models and their closest open followers. Customers may be willing to pay for early access to that frontier.</span></p><p><strong><span>On  Navier-Stokes</span></strong></p><p><span>The solution to this Millenium Prize Problem may be the best way to think about the AI frontier, the close followers and the potential value in the capability gap. But let&#8217;s consider what frontier capability actually entails. OpenAI did not arrive at this long sought-after solution by simply prompting a ChatGPT terminal to &#8220;solve Navier-Stokes&#8221;. It did so through $10s of millions in compute, and probably $10s of millions more wasted on other problems for which they didn&#8217;t find solutions. Although I am not qualified to assess, some mathematicians have claimed that this solution was not very far from the knowledge frontier and that rather than exploring a vast knowledge-space wilderness, the model actually scooped a potential near-future discovery on the backs of pre-existing, recent human labor. To summarize, OpenAI likely spent around $100 million to prove its ability to discover new knowledge. If they were to monetize this </span><em><span>knowledge discovery capability</span></em><span> we may think of that $100 million fixed costs as a baseline. This estimate doesn&#8217;t include every other cost that may be required to deliver results to a customer nor does it include their profit margins.  <br><br>We can then ask - how else may a pharmaceutical company (for example) put $200 million to use besides a pre-FDA approval drug proposal (for example). These costs may come down with time and there will certainly be capability gap use cases, but will there be enough to justify a $2 trillion valuation? (Anthropic)</span></p><p></p><p><strong><span>Big Frontier&#8217;s Escape Plan<br></span></strong><span>If you accept my above framing you will see that frontier CEOs are in a bind. The open-source firms pose an existential threat to their business model and their investment thesis.</span></p><p><span>Below are two of the pillars of the &#8220;slowdown&#8221; proposal:</span></p><ul><li><p><strong><span>&#8220;Independent Oversight:</span></strong><span> Embedding third-party safety evaluators with deep, employee-like access inside leading AI companies to monitor risks as new models are trained.</span></p></li><li><p><strong><span>Democratic Coordination:</span></strong><span> Establishing safety standards and agreements between democratic nations.&#8220;</span></p></li></ul><p><span>Innocuous enough? But how can you embed a safety evaluator in an open model? How do you apply a safety standard to a model which can be shared as easily as a movie is streamed? You can&#8217;t, and that&#8217;s the point. You can only prevent models from being shared or hosted. </span><em><span>They are not proposing safety standards on frontier models. They are advocating for a moratorium on open-models</span></em><span>.</span></p><p><span>Distillation is unfair to the frontier firms.  Aren&#8217;t the open-source companies stealing?</span></p><ol><li><p><span>The closed-source firms distill too. </span></p></li><li><p><span>Frontier LLMs were and continue to be trained on the internet of human language - generally without compensation for the owners. </span>Frontier firms are throwing stones from glass houses.</p></li><li><p><span>OpenAI took funding and developed ChatGPT as a non-profit then transitioned into a &#8220;capped-profit&#8221; structure to secure the massive capital and computing power required for advanced AI development.</span></p></li></ol><p><span>But they made the investment and they did the work. Don&#8217;t they deserve to reap the economic rewards?</span></p><ol><li><p><span>There is no guarantee that innovators will capture all, or even most, of the economic value they create. Linus Torvalds did not. Johannes Gutenberg did not either. </span></p></li><li><p><span>Furthermore, these investments were funded not only from private capital but also by the American taxpayer under tenuous claims of imminent AGI, catastrophic AI risk or an existential threat from geopolitical rivals. </span></p></li></ol><p></p><p><strong><span>What the Future of AI will Look Like (End on a Positive Note)</span></strong></p><p><span>Again - AI and LLMs are a massive positive externality technology and the world economy will benefit massively. The losers will mostly be limited to Big Frontier shareholders and the American taxpayers to the extent they needlessly subsidized these firms.</span></p><p></p><p><strong><span>How people will use AI (predictions): </span></strong></p><ul><li><p><span>The privacy-sensitive users will increasingly run small, good-enough AI on their laptops or host locally on their own infrastructure.</span></p></li><li><p><span>Others will use open-source models through third party providers.</span></p></li><li><p>The existence of third-party providers will create downward pressure on the prices of frontier models. Their API/subscription costs will approach those of open models.</p></li><li><p>Consumers may fall back to familiar trusted brand names like Google and familiar business models like advertising at Alphabet and Meta will win out compared to the API / subscription model.</p></li></ul><p></p><p><strong><span>Exponential Productivity Gains?</span></strong></p><p><span>The future may be driven less by exponential gains in LLM capability than by the widespread diffusion of a constant productivity multiplier. If AI makes each worker six times more productive, the transformative effect comes from extending that gain from today&#8217;s relatively small group of effective users to hundreds of millions or billions of people.The positive externalities on that constant productivity gain may look something like exponential growth and the second order effects from that may be hard to predict. </span>In other words, we may see exponential growth, but that growth won&#8217;t be based on frontier capability, it will be based on increased human agency.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[LLM Watermarking - A Dead End]]></title><description><![CDATA[Original HereThanks for reading David at SenTeGuard!]]></description><link>https://www.letters.senteguard.com/p/llm-watermarking-a-dead-end</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/llm-watermarking-a-dead-end</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Sat, 15 Aug 2026 11:40:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uiMR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Original Here</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uiMR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uiMR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 424w, https://substackcdn.com/image/fetch/$s_!uiMR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 848w, https://substackcdn.com/image/fetch/$s_!uiMR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 1272w, https://substackcdn.com/image/fetch/$s_!uiMR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uiMR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp" width="1200" height="1057" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1057,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:288620,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/211293768?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uiMR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 424w, https://substackcdn.com/image/fetch/$s_!uiMR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 848w, https://substackcdn.com/image/fetch/$s_!uiMR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 1272w, https://substackcdn.com/image/fetch/$s_!uiMR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdae7d8bd-1f73-40fc-9ba9-baa45eeeb42b_1200x1057.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Introduction</h2><p>The detection of content generated by AI has changed from a theoretical issue to a regulatory obligation under the European Union&#8217;s AI Act.  As of August 2, 2026, it will be necessary for providers to mark their outputs in a machine-readable format. However, this top-down approach places heavy technical demands on developers and at the same time fails to take into account the practical impossibility of successfully meeting these requirements.</p><p>Imposing compliance by means of invisible signatures is a crude way of dealing with a complicated issue. The EU may end up with a system which can easily be circumvented by the dishonest while at the same time imposing on genuine providers costly and quality-reducing requirements that do not achieve the complete certainty that the regulators want.</p><p>In certain respects we already have informal versions of AI watermarks. There are some habits that have come to be linked with AI writing. The em dash, in fact, has never come under such close suspicion. Likewise, certain sentence patterns&#8212;&#8217;It&#8217;s not X, it&#8217;s Y&#8217;&#8212;as well as excessive headings, oddly balanced lists and an ever-increasing number of words that have become stereotypically &#8216;ChatGPT&#8217; have also attracted attention. Of course none of these things proves anything; people have used em dashes before ChatGPT and will likely continue to do so afterwards.</p><p>A compulsory technical watermark would try to substitute those unreliable intuitive judgments with something much more systematic: an invisible signal which is deliberately put into the output by the model itself.</p><p>The issue is that while it&#8217;s relatively easy to imagine it, it&#8217;s much harder to put it into practice.</p><p>We now have techniques, called steganography, which allow us to hide information within photographs, video and audio. Text, on the other hand, is a completely different kind of medium; a photograph has millions of values which can be altered slightly without a person noticing, whereas a sentence has rather fewer options and altering any one of them can change its meaning or quality.</p><p>The gap in this area means that it is much more difficult to carry out reliable watermarking of outputs from LLMs than it at first seems &#8211; and suggests that requiring it could result in a system which is both easy to break and at the same time costly to the quality of the models it is intended to control.</p><p>Take the case of a digital photograph. A photograph is made up of millions of pixels, each of which is represented by numerical values that indicate things such as the intensity of red, green, and blue. These numbers contain a vast quantity of information.</p><p>If the red component of a certain pixel is 184, altering it to 185 would very likely be imperceptible to a person viewing the image; and if you carry out this change for thousands of pixels, you can encode a rather large amount of information without the photograph appearing to be noticeably altered.</p><p>A simple method would be to represent even numbers as a 0 and odd numbers as a 1; a computer could then conceal a binary message in the picture by modifying the value of certain pixels by one.</p><p>184 becomes 0.</p><p>185 becomes 1.</p><p>If you repeat this over a sufficient number of pixels, you can encode an identifier, a timestamp, a cryptographic signature, or some other information indicating the origin of the image.</p><p>A video also provides a great many possibilities since it shows thousands of images in sequence together with sound; there thus being a huge number of values which can be altered slightly without the viewer noticing.</p><p>There are also major issues concerning the use of mandatory steganography in photographs and videos, especially after the media has been compressed, cropped, filtered, resized, screenshotted, or deliberately altered. But I shall set those problems aside.</p><p>The key thing to note is that images have a great deal of entropy since there are millions of small numerical options open to the person who produces the image, and a number of these options can be modified without making any significant difference to what a human observes.</p><p>It doesn&#8217;t provide the same level of luxury.</p><h2>The Text Problem</h2><p>Imagine asking ChatGPT:</p><p>What is the capital city of Burkina Faso?</p><p>The correct answer is:</p><p>Ouagadougou.</p><p>Nothing can be concealed.</p><p>ChatGPT won&#8217;t change &#8220;Ouagadougou&#8221; to &#8220;Timbuktu&#8221; since it has to give a correct answer. It can&#8217;t alter the capitalisation as that might look odd. It also can&#8217;t add three unnecessary paragraphs just because it needs some space to put a watermark.</p><p>The same issue occurs in the case of mathematics.</p><p>What is 7 multiplied by 8?</p><p>56.</p><p>There is simply not sufficient freedom in the answer to allow meaningful hidden information to be encoded. This means that there is an immediate restriction on any scheme for watermarking text universally. Answers that are short, factual, numerical, consisting of names, translations of fixed phrases, and many other types of output contain so little entropy that it is not possible to reliably carry a hidden message.</p><p>What about longer writing?</p><h2>Word Baskets</h2><p>The most reasonable approach would most likely be one that we could refer to as word baskets. Suppose an AI is writing the following sentence:</p><p>The proposal is intended to boost economic growth.</p><p>There are several words the model might reasonably have used:</p><p><em>increase</em></p><p><em>boost</em></p><p><em>raise</em></p><p><em>improve</em></p><p><em>accelerate</em></p><p>Normally an AI system gives probabilities to all the possible following words. For example, &#8220;increase&#8221; might have a probability of 30 per cent, &#8220;boost&#8221; 25 per cent, &#8220;raise&#8221; 20 per cent, and so on. A system using watermarking could secretly split up the possible words into two groups.</p><p>Basket 0 might contain:</p><p><em>increase</em></p><p><em>raise</em></p><p>Basket 1 might contain:</p><p><em>boost</em></p><p><em>improve</em></p><p><em>accelerate</em></p><p>When the hidden message calls for the following encoded bit to be 0, the model will tend towards words in Basket 0; if the hidden bit is 1, the model will tend towards Basket 1. Picking one word over another has about the same function as altering a pixel value from 184 to 185. Over hundreds or thousands of words, such small decisions could build up to form a detectable statistical pattern.</p><p>The watermark wouldn&#8217;t necessarily take the form of a concrete hidden sentence; rather, a person looking at the text could consider whether the model used words from a given group considerably more frequently than would be the case naturally.</p><p>This is likely the most important difference between image and text watermarking: in the case of an image we can alter the numerical values slightly in a way that has no effect on the meaning of the image, whereas with text almost any change might affect its meaning, tone, rhythm, clarity or style.</p><p>This leaves the following tradeoff: the more strenuous you are in making the model keep the watermark, the more you disrupt its capacity to generate the best answer.</p><h2>Watermarks Have a Cost</h2><p>Suppose that &#8220;increase&#8221; is the best possible following word, but the watermark insists on using a word from the other basket. The model now selects &#8216;boost&#8217; and that probably has no importance. But then carry out the process again and again, thousands of times.</p><p>On certain occasions the second-best word will be nearly impossible to tell apart from the first, on other occasions it will be clearly worse, on some occasions a change of word will mean having to restructure the sentence, and on other occasions the alternative will slightly alter the meaning.</p><p>The problem is particularly clear when looking at computer code.</p><h2>Watermarking Code</h2><p>There is a great deal of redundancy in natural language, with about twenty different reasonable ways of expressing roughly the same idea. Code is far less tolerant. A programmer doesn&#8217;t necessarily want the model to choose among function names, variable structures, library calls, formatting conventions, or algorithms since those choices serve to preserve some invisible watermark.</p><p>There are often several equivalent methods of writing a program, and there are sometimes not. A token-level watermarking system might cause the model to avoid the most efficient, readable, secure, or conventional approach simply because the presence of another valid token is able to maintain the concealed statistical pattern. That kind of writing would result in an unnatural sentence in ordinary prose. But it might cause a bug in the code.</p><h2>Watermark Removers</h2><p>There is another, larger problem.</p><p>Even if text watermarking does work, the person who is trying to beat it will know what the defender is attempting to achieve. The removal of watermarks from images usually involves disturbing the hidden signal while at the same time keeping the visible part unchanged. An image can be compressed, resized, cropped, slightly blurred, passed through a filter, regenerated or otherwise altered. Each of these conversions may result in some of the carefully adjusted values which carry the watermark being destroyed.</p><p>Understanding the analogous attack on text&#8217;s even simpler. Just rewrite it.</p><p>If an AI generates a 1,000-word essay containing a statistical watermark, another model could be instructed:</p><p><em>Rewrite it while preserving the same meaning.</em></p><p>A secondary model would make a huge number of new choices regarding grammar and vocabulary by changing words, reordering sentences, combining paragraphs, and getting rid of the transitions. It would therefore seriously undermine or completely eliminate the initial statistical footprint.</p><p>There are already tools that are marketed as AI &#8220;humanizers&#8221; and the reason for their existence is basically to achieve precisely this.</p><h2>The Larger Mistake</h2><p>There is also a more basic problem with the whole project.</p><p>We are putting in a great deal of effort to maintain a scholarly and professional environment in which we act as if machine co-writers don&#8217;t exist; yet they do and they are going to improve. They will be put into use by students, by professors, by lawyers, by programmers, and by government officials. It therefore amounts to attacking the wrong problem if one is trying to hide an invisible technical tripwire within each paragraph produced by an AI.</p><p>What we should do instead is consider machine co-writers as a given. I talk about this more general point in the article I wrote for <a href="https://www.letters.senteguard.com/p/cyborg-scholars">Cyborg Scholars</a>. The important question nowadays is no longer whether a human has received help from a machine, but rather whether the human understands, assesses, improves, and assumes responsibility for the final work.</p><p>The European Union&#8217;s initiative concerning the watermarking of machine-generated content is a misguided effort to deal with complicated social and academic issues by means of technically flawed measures. Since text does not have the same level of entropy as images, it is necessary to reduce the quality, efficiency and usefulness of AI-produced content, especially in technical fields such as programming. Furthermore, such watermarks can easily be made useless through simple rephrasing, turning the detection process into an endless and pointless arms race. Rather than trying to control the use of machine co-writers by relying on superficial deterrents, regulators and institutions should concentrate on promoting human accountability, critical assessment, and responsible interaction with AI tools.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[July Update]]></title><description><![CDATA[Friends and Readers,]]></description><link>https://www.letters.senteguard.com/p/july-update-7ff</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/july-update-7ff</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Tue, 21 Jul 2026 13:15:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Yojc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friends and Readers,</p><p>Thank you to those who have signed up since my last update. I have relocated to Austin and am hitting the ground running. Please share if you know of anyone who would be interested.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Last month I was fortunate enough to present my Harvard Policy Analysis Exercise &#8220;A Cognitive Security Verification Framework&#8221; at BSides San Antonio, a cybersecurity conference.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yojc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yojc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yojc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg" width="1280" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156331,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207911196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yojc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Podcast - SenTe with David</h2><p>In case you would prefer the articles in spoken form rather than written, I&#8217;ve started giving a rundown of my pieces and will post them on your podcast platform of choice - It&#8217;s a work in progress and I&#8217;m smoothing out the rougher edges with each iteration. Feel free to follow and share.</p><p><a href="https://www.youtube.com/playlist?list=PLCHQ6onuivSjw0aXyjKiCA2FTSPYVBowZ">Youtube</a></p><p><a href="https://open.spotify.com/show/033BYiKHEeBWNiHM1DlrMd">Spotify</a></p><p><a href="https://podcasts.apple.com/us/podcast/guarding-sente-with-david/id1896945614">Apple Podcasts</a></p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a93ed35f31fd3769a9329cdfe&quot;,&quot;title&quot;:&quot;SenTe with David&quot;,&quot;subtitle&quot;:&quot;David Weidman&quot;,&quot;description&quot;:&quot;Podcast&quot;,&quot;url&quot;:&quot;https://open.spotify.com/show/033BYiKHEeBWNiHM1DlrMd&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/show/033BYiKHEeBWNiHM1DlrMd" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe><p><a href="https://podcastaddict.com/podcast/guarding-sente-with-david/7100810">Podcast Addict</a></p><p><a href="https://api.riverside.com/hosting/jERlYWdl.rss">RSS Feed</a></p><h2><strong>Writing Roll-Up</strong></h2><p><strong>Broad Policy Articles:</strong></p><ol><li><p><strong><a href="https://senteguard.com/blog/loose-lips-sink-ships">Loose Lips Sink Ships- AI and Inference Risks</a></strong><br>Seemingly harmless comments can reveal sensitive information when combined with other public or private clues. AI makes this recombination faster, allowing adversaries to reconstruct secrets without accessing any single classified document. Organizations should act according to principles of paranoid secrecy which were established as far back as WW2. <a href="https://www.letters.senteguard.com/p/loose-lips-sink-ships-ai-and-inference">Substack</a>.</p></li><li><p><strong><a href="https://senteguard.com/blog/abstraction-ladder">Moving Up the Abstraction Ladder</a></strong><br>Software development has progressed from machine code to higher-level languages that let people accomplish more without managing every technical detail. LLM coding agents represent a continuation of this long-time trend, translating ordinary language into software and giving users greater agency over complex systems. <a href="https://www.letters.senteguard.com/p/the-next-rung-on-the-ladder-of-abstraction">Substack</a>.</p></li></ol><p><strong>SenTe Focused Articles:</strong></p><ol><li><p><strong><a href="https://senteguard.com/blog/leak-through-similarity">What Does a Similarity Leak Look Like?</a></strong><br>A similarity leak occurs when sensitive information is exposed through a paraphrase, translation, summary, or closely related expression rather than an exact textual match. Traditional filters may miss it because the words have changed even though the underlying meaning remains the same. <a href="https://www.letters.senteguard.com/p/what-does-a-similarity-leak-look">Substack</a>.</p></li><li><p><strong><a href="https://senteguard.com/blog/why-joseki">Why We Named it Joseki.</a></strong><br>In Go, a joseki is a reusable sequence of moves that works only when applied with an understanding of the broader game. The name reflects our belief that AI instructions and wrappers should be reusable and portable, but always evaluated within their surrounding context. <a href="https://www.letters.senteguard.com/p/why-we-named-it-joseki">Substack</a>.</p></li></ol><p><strong>On Request:</strong></p><ul><li><p>Prototype testing of the<a href="https://senteguard.com/blog/sensitive-information-reachability-the-problem-and-the-solution-1768745959993"> Moyo</a> information space mapper. Find leaks of your secrets (classified, proprietary, personal) in public LLMs (ChatGPT, Claude, Qwen, Kimi, Grok, etc).</p></li><li><p><a href="https://senteguard.com/blog/the-emerging-threat-of-idea-leakage">SenTeGuard Pilot</a> - protect yourself or your organization from leakage of valuable information through air-gap capable semantic guardrails. <a href="https://www.letters.senteguard.com/p/the-emerging-threat-of-idea-leakage">Substack</a></p></li><li><p>Let&#8217;s Talk:</p><ul><li><p>Private - How can your organization more effectively secure your secrets in the LLM era through implementation of the Cognitive Security Verification Framework (<a href="https://senteguard.com/blog/csvf-concept">CSVF</a>) and by other means.</p></li><li><p>Public - How to craft tech-positive, pro-future, big-tech skeptical market-oriented policies of abundance in the LLM era.</p></li></ul></li></ul><p></p><p>David</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What Does a Similarity Leak Look Like?]]></title><description><![CDATA[Original Here]]></description><link>https://www.letters.senteguard.com/p/what-does-a-similarity-leak-look</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/what-does-a-similarity-leak-look</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 23:23:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HqT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HqT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HqT3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 424w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 848w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1272w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HqT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png" width="220" height="220" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:648,&quot;resizeWidth&quot;:220,&quot;bytes&quot;:140529,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730388?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HqT3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 424w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 848w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1272w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/leak-through-similarity">Original Here</a></p><p>Traditional cybersecurity tends to treat a secret as an object. It is a document, password, database record, piece of source code or collection of classified files. Once the object has been identified, security teams can restrict access to it, monitor where it travels and search for exact copies leaving the organization.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Large language models complicate that arrangement because a secret is not only an object. It is also an idea.</p><p>Imagine that a company is preparing to acquire a smaller competitor. The official acquisition plan is tightly controlled. However, the company has also posted several new jobs in the competitor&#8217;s city, requested regulatory advice from an outside law firm, moved members of its integration team onto an unnamed project and scheduled unusual travel for senior executives. None of these facts is necessarily sensitive on its own. Combined, they may reveal the acquisition.</p><p>Before generative AI, reconstructing that conclusion required a patient analyst. Today, a person can place those fragments into a model and ask it what is happening. The model may never retrieve the confidential acquisition plan. It may nevertheless produce a description that is functionally indistinguishable from it.</p><p>The secret has leaked through similarity.</p><h2><strong>Security in Meaning Space<br></strong></h2><p>Most conventional data-loss-prevention systems operate in what we might call <em>token space</em>. They search for a Social Security number, a project codename, a classified marking or a sequence of text copied from a sensitive document. These controls are useful, but they are built around an assumption that leaked information will resemble its source at the level of words or characters.</p><p>LLMs operate primarily in <em>meaning space</em>. They can translate, summarize, abstract, paraphrase and recombine. A user does not need to type, <em>&#8220;Project Nightfall will launch on October 17.&#8221;</em> He might instead ask the model to describe <em>&#8220;the initiative scheduled to begin in mid-October after the new supplier receives final approval.&#8221;</em> The words are different. The meaning may be nearly identical.</p><p>Leak through similarity occurs when information crosses a security boundary because it is semantically close enough to protected information to create the same practical harm. The output does not have to be an exact copy. It only has to tell the recipient substantially the same thing.</p><p>The important shift is that confidentiality can no longer be treated as a binary property of a file. Protected information occupies a neighborhood of related statements. A model can land inside that neighborhood through paraphrase, approximation or inference without reproducing the original source.</p><p>The Cognitive Security Verification Framework (CSVF) describes this broader problem as <strong>semantic leakage</strong>: the disclosure of protected meaning through paraphrase, translation, summarization, abstraction or inference. It also distinguishes semantic leakage from cross-domain inference, where individually permissible fragments become sensitive when combined.</p><h2><strong>&#8220;Close Enough&#8221; Can Be More Than Enough<br></strong></h2><p>Security professionals may reasonably ask how similar an output must be before it becomes a leak. There is no universal threshold.</p><p>For an intelligence organization, an approximate description of a facility&#8217;s purpose may be damaging even when its exact capabilities remain unknown. For a pharmaceutical company, identifying the likely mechanism of action behind an experimental drug may eliminate years of uncertainty for a competitor. For a technology company, a rough reconstruction of an internal system prompt or evaluation strategy may contain most of the commercially valuable insight.</p><p>This means leak through similarity should be evaluated according to operational equivalence rather than verbal equivalence. Would the recipient be able to make substantially the same decision, reproduce substantially the same capability or avoid substantially the same research cost after receiving the model&#8217;s output? If so, the fact that the model used different words provides little comfort.</p><p>The problem becomes more serious as AI systems gain access to longer context windows, persistent memory, internal repositories and external tools. Each connection expands the collection of fragments from which the model can build a conclusion. Security teams therefore need to consider not only what the model can retrieve during one prompt, but what it can accumulate across a session or across many sessions.</p><h2><strong>How the SenTeGuard Stack Addresses Similarity Leakage<br></strong></h2><p>Leak through similarity is not a single-product problem. It exists before deployment, during retrieval, at runtime and after a system changes. The SenTeGuard product family approaches those stages as parts of the same cognitive-security stack.</p><h3><strong>SenTeGuard: Runtime Enforcement and Batch Scanning<br></strong></h3><p>SenTeGuard sits between users and model endpoints, inspecting prompts and responses before information crosses the boundary. Conventional pattern matching remains important, but the platform adds semantic analysis intended to recognize when a user is describing a protected idea without copying its original language.</p><p>This is where similarity becomes an enforceable policy object. An organization can define sensitive concepts, prohibited outputs and contextual rules, then block, redact or flag interactions that approach those boundaries. SenTeGuard also records the interaction so that the organization can determine what was attempted, what policy was applied and what the model returned.</p><p>The objective is not to prohibit every conversation that mentions a sensitive subject. That would make the system unusable. The objective is to recognize when a prompt or output becomes close enough to protected meaning that intervention is justified.</p><h3><strong>Moyo: Finding What Is Already Reachable<br></strong></h3><p>Moyo asks a different question: what can an adversary already reconstruct?</p><p>Many organizations publish more than they realize. Job listings reveal technical priorities. Employee profiles reveal team composition. Procurement notices identify vendors. Conference presentations expose architecture. Photos reveal locations, equipment and schedules. Individually, these disclosures may appear harmless. Together, they can form a short path to a sensitive conclusion.</p><p>Moyo maps those paths. It tests what conclusions can be assembled from public or authorized sources, identifies which combinations create the greatest exposure and measures the distance, cost and reliability of the inference. The purpose is to discover the dangerous semantic neighborhood before a competitor, foreign intelligence service or criminal organization does.</p><p>In other words, SenTeGuard watches the boundary from the inside. Moyo approaches it from the outside.</p><h3><strong>CSVF: Defining What Must Remain Unreachable<br></strong></h3><p>A company cannot govern similarity leakage if it has not defined what counts as failure. CSVF provides the framework for doing so.</p><p>The framework asks organizations to inventory their information domains, specify which joins among those domains are permitted and define Unreachable Statement Classes: categories of conclusions an AI system must not be able to produce reliably. It then provides draft metrics for testing those claims, including Leakage Event Rate, Domain Inference Risk and Crawl-Resilience Score.</p><p>This transforms a vague promise&#8212;<em>&#8220;our AI does not leak sensitive information&#8221;</em>&#8212;into a testable claim. Which meanings are protected? Which sources could be combined to reach them? How often does the system cross the boundary? Does the boundary continue to hold after the model, prompt, retrieval configuration or toolset changes?</p><p>CSVF supplies the map and measurement system. SenTeGuard and Moyoguard provide mechanisms for enforcing and testing the resulting boundaries.</p><h2>Examples<br></h2><ol><li><p>Microsoft&#8217;s &#8220;New Bing&#8221; Revealed Its Hidden System Prompt</p></li></ol><p>When Microsoft launched the first version of Bing Chat in 2023, users quickly discovered that carefully crafted prompts could persuade the model to reveal portions of its hidden system prompt, internally codenamed Sydney. Attackers did not have access to Microsoft&#8217;s source code or internal documentation. Instead, they asked the model questions about its own behavior until it reconstructed and revealed instructions that were intended to remain private.</p><p>Although the output was not necessarily a byte-for-byte copy of Microsoft&#8217;s internal configuration, it was close enough to reveal confidential implementation details. From a security perspective, this illustrates that protecting a prompt file is insufficient if an attacker can reconstruct its contents through interaction with the model itself.</p><ol start="2"><li><p>Samsung Engineers Accidentally Exposed Proprietary Source Code</p></li></ol><p>In 2023, Samsung temporarily restricted employee use of ChatGPT after engineers pasted proprietary semiconductor source code, debugging information and meeting notes into the service while seeking programming assistance.</p><p>The concern was not merely that OpenAI received copies of the text. Once proprietary information enters an external LLM, future prompts may be capable of eliciting summaries, explanations or functionally equivalent descriptions of that information. Even if the original code is never reproduced verbatim, a sufficiently similar explanation may provide competitors with valuable intellectual property.</p><p>This is a classic example of why organizations must protect semantic content rather than merely preventing file exfiltration.</p><ol start="3"><li><p>Public OSINT Reveals Classified Programs Without Classified Documents</p></li></ol><p>Intelligence analysts routinely reconstruct sensitive military activities using only publicly available information. Satellite imagery, procurement contracts, LinkedIn profiles, patent filings, shipping manifests, conference presentations and job advertisements are individually harmless. Together, they can reveal the location of secret facilities, the capabilities of new weapons systems or the existence of classified research programs.</p><p>No classified document has leaked. Instead, the sensitive conclusion emerges from the semantic relationship between many publicly available facts. Modern LLMs dramatically accelerate this process by identifying relationships across thousands of disparate sources that would previously have required weeks of manual analysis.</p><p>This is precisely the type of cross-domain inference that CSVF is designed to identify and measure.</p><ol start="4"><li><p>AI Coding Assistants Can Infer Proprietary Architectures</p></li></ol><p>Suppose an engineer asks an internal coding assistant:</p><p>&#8220;How should I implement authentication the same way our payment service does?&#8221;</p><p>The assistant may not retrieve the underlying authentication design document. Instead, it may synthesize an answer from architecture diagrams, internal documentation, code comments, engineering discussions and previous implementations.</p><p>The resulting explanation may accurately describe proprietary architectural decisions without reproducing any single protected artifact. A competitor receiving the same explanation could implement a nearly identical system despite never seeing the original documentation.</p><p>From the standpoint of traditional DLP, nothing has leaked because no protected document was copied. From the standpoint of cognitive security, the organization&#8217;s intellectual property has effectively crossed the security boundary through similarity.</p><p>These examples illustrate why AI security must evolve beyond detecting copied strings or protected files. The relevant question is no longer &#8220;Did the model reproduce a secret?&#8221; It is &#8220;Did the model enable someone to reach substantially the same conclusion?&#8221; Once meaning&#8212;not merely text&#8212;is treated as the protected asset, leak through similarity becomes a measurable security problem rather than an abstract AI concern.</p><h2><strong>Protecting Ideas, Not Merely Files<br></strong></h2><p>The central lesson is simple. An organization can successfully protect every restricted document and still lose the idea contained within them.</p><p>LLMs lower the cost of moving between related statements. They can transform a secret into a summary, a summary into an implication and several implications into a protected conclusion. The resulting output may share none of the original wording while preserving most of its value.</p><p>Security must therefore move beyond searching for copied strings. It must identify protected meanings, understand the neighborhoods around them, test the paths by which they become reachable and enforce boundaries throughout the AI workflow.</p><p>That is the role of the SenTeGuard stack. Moyoguard discovers what is inferable. CSVF defines and measures the boundary. Joseki:WrapperHub packages the intended behavior and its evaluations. SenTeGuard enforces the boundary when people and models interact.</p><p>Network security protects the systems through which information moves. Cognitive security must protect what the information means.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Loose Lips Sink Ships - AI and Inference Risks]]></title><description><![CDATA[Original Here]]></description><link>https://www.letters.senteguard.com/p/loose-lips-sink-ships-ai-and-inference</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/loose-lips-sink-ships-ai-and-inference</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 22:38:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NWOn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NWOn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NWOn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NWOn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg" width="1280" height="1940" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1940,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:628852,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730386?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NWOn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/loose-lips-sink-ships">Original Here</a><br><br>During World War II, Americans were warned that a careless conversation could expose troop movements, sailing schedules or other information useful to the enemy. &#8220;Loose Lips Might Sink Ships&#8221; was not merely a catchy poster. It communicated a simple operational truth: an adversary does not need access to the war plan if ordinary people provide enough pieces to reconstruct it.</p><p>That lesson is more important in the age of artificial intelligence.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Traditionally, we think of information leakage as the disclosure of a secret document, password or database. The human leakage vector is different. An employee mentions a delayed test at a conference. Another complains about a new supplier on LinkedIn. A third tells a friend that everyone in the office has been ordered to cancel vacation. None believes he has revealed anything sensitive. Individually, he may be right.</p><p>The problem is recombination.</p><p>Recombination occurs when an adversary collects seemingly unrelated pieces of information, identifies the people and organizations involved, places the events on a timeline and tests possible explanations for why they occurred. One inference becomes an input for the next. Artificial intelligence makes this process cheap, fast and scalable. Like earlier systems that imposed order on the vast and unstructured internet, AI can make millions of scattered human observations searchable and comprehensible.</p><p>Consider a hypothetical Navy example. One sailor tells his family that scheduled dental appointments were suddenly moved forward. Another mentions that the galley received an unusually large delivery. A spouse posts that a homecoming ceremony has been postponed. A contractor complains online about an urgent inspection of a particular weapons system. Finally, several sailors begin asking questions about phone service in the same part of the Pacific.</p><p>None has disclosed a deployment order. Nonetheless, an adversarial AI could combine those statements with weather forecasts, port activity, public photographs and historical deployment patterns. It might infer which ship is preparing to depart, roughly when it will sail and where it is likely going. The AI does not need to produce the precise classified order. It only needs to narrow the possibilities enough to help an adversary position a submarine, surveillance asset or collection team.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bcpo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bcpo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg" width="1456" height="1896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1896,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:534777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730386?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bcpo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The same problem exists in the corporate world. Imagine that a product manager casually mentions new European labeling requirements. A recruiter advertises for Korean-speaking radio-frequency engineers. A supplier celebrates a rush order for unfamiliar battery enclosures. An executive cancels an annual conference appearance, while employees begin booking travel to the same city.</p><p>Separately, these facts are boring. Recombined, they could reveal that the company is preparing a new wireless product, working with a Korean manufacturing partner and approaching a launch or acquisition announcement. A competitor could adjust its own release schedule, approach the supplier, target the relevant employees or trade on the inferred information. Again, no one employee leaked &#8220;the secret.&#8221; The workforce leaked enough components for an AI to uncover it.</p><p>This is the problem that cognitive security and the Cognitive Security Verification Framework (CSVF) are intended to address. CSVF examines inference boundaries, semantic leakage and information reachability. In other words, it asks not only whether a system disclosed a secret word-for-word, but whether the secret became reachable through paraphrases, summaries or chains of individually harmless clues.</p><p>Employees should therefore be overly safe about what they discuss outside approved channels. This does not mean that every workplace conversation must stop. It means that people should abandon the assumption that a detail is safe merely because it appears insignificant. They do not know what other fragments an adversary already possesses, what an AI can infer from them or which harmless comment will complete the picture.</p><p>During World War II, the person listening at the next table might have been an enemy agent. Today, the listener may be a machine collecting thousands of conversations at once.</p><p>Loose lips no longer have to reveal the location of the ship. They only have to provide enough clues for an AI to find it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why We Named it "Joseki"]]></title><description><![CDATA[Original Here]]></description><link>https://www.letters.senteguard.com/p/why-we-named-it-joseki</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/why-we-named-it-joseki</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 22:33:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rcjt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rcjt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rcjt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 424w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 848w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1272w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rcjt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png" width="1130" height="591" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:591,&quot;width&quot;:1130,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:482525,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730380?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a821e4a-9797-4cec-a5c7-d912cbd6818b_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rcjt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 424w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 848w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1272w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/why-joseki">Original Here</a></p><p><br>Go is an ancient strategy game with simple rules and almost incomprehensible complexity. Over centuries of play, Go players documented recurring sequences of moves called <em>joseki</em>. A <em>joseki</em> is a studied pattern, usually played in a corner, that leaves both players with a reasonable result. One player may receive secure territory while the other gains influence toward the center.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>But a <em>joseki</em> is not automatically the correct move.</p><p>A sequence that works well in one game may be a serious mistake in another. The surrounding stones, direction of play and broader strategy all matter. Memorizing the pattern without understanding its purpose can leave a player locally satisfied but globally defeated.</p><p>This combination of reuse and judgment is what makes <em>joseki</em> a useful way to think about artificial intelligence.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FG3h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FG3h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 424w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 848w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1272w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FG3h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif" width="508" height="673.9878419452888" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:873,&quot;width&quot;:658,&quot;resizeWidth&quot;:508,&quot;bytes&quot;:55507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730380?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FG3h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 424w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 848w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1272w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><h2><strong>Beyond the &#8220;Perfect Prompt&#8221;<br></strong></h2><p>Organizations often treat prompts as isolated pieces of text. A useful prompt is copied into a document, pasted into Slack, modified by another employee and eventually placed into production. The evaluation criteria may live somewhere else. The safety policy may exist only in a vendor dashboard. No one may know which version was actually used.</p><p>This becomes more serious as AI systems move beyond experimentation. It is not enough to know what instructions were given to a model. Teams must also know which version was used, which models it works with, how it was tested, what data accompanied it and who is permitted to use it.</p><p>This is the purpose of <a href="http://app.josekiwrapperhub.com/">Joseki:WrapperHub</a>.</p><p>Joseki allows organizations to package the full behavior of an AI system into a reusable, versioned unit. A Behavior Package can include the prompt, examples, adapters, evaluation suites, safety policies, installation requirements, licensing information and evidence of provenance. Instead of copying prompts between projects, teams can install, inspect, test and roll back a defined package.</p><p>The distinction is that: a prompt library stores text, Joseki stores a behavior contract: what the system is intended to do, how it was produced, how it was evaluated and under what conditions it should be trusted.</p><h2><strong>Established Patterns, Not Blind Automation<br></strong></h2><p>Like a Go <em>joseki</em>, a Behavior Package is not guaranteed to work in every context. A package may perform well on one model and fail after a provider update. It may require different safety rules in another organization or behave unpredictably in another language.</p><p>The answer is not to abandon reusable patterns but to make them visible, testable and responsive to changing conditions.</p><p>Joseki therefore helps users see whether a package still works across different models and versions. Instead of relying on a stale &#8220;last updated&#8221; date, teams can evaluate whether a behavior remains reliable in the environment where they intend to use it.</p><p>The broader challenge of rapid technical growth is often solved through new abstractions. Industrial standards made mass production manageable. Internet protocols organized digital communication. AI needs similar frameworks for packaging, evaluating and governing behavior.</p><p>A Go player studies <em>joseki</em> so that every familiar position does not have to be solved again from first principles. An AI team should not have to rebuild its prompts, evaluations, safety rules and documentation every time it changes models.</p><p>That is the idea behind Joseki: share the behavior, not just the prompt.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Next Rung on the Ladder of Abstraction]]></title><description><![CDATA[Original Post]]></description><link>https://www.letters.senteguard.com/p/the-next-rung-on-the-ladder-of-abstraction</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/the-next-rung-on-the-ladder-of-abstraction</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 22:28:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aF6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aF6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aF6B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aF6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg" width="1232" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:900,&quot;width&quot;:1232,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:660782,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730080?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aF6B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/abstraction-ladder">Original Post</a></p><p>The history of software development is, in large part, the history of moving up a ladder of abstraction. At each rung, programmers have surrendered some direct control over the machine in exchange for the ability to tell it to do more.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The least abstracted form of computing available to a software programmer is machine code: numerical instructions executed directly by a processor. Even machine code is technically an abstraction over transistors, electrical signals and the physical architecture of the chip. Nonetheless, from the programmer&#8217;s perspective, it is close to the bottom. Early programmers had to think in terms of memory addresses, processor instructions and the exact movement of data through a specific machine.</p><p>Assembly language created the first major step upward. Instead of remembering numerical operation codes, programmers could use names and symbols. An assembler translated those symbols into machine instructions. Assembly was easier for humans to understand, but the relationship generally remained one-to-one: the programmer still wrote something approximating one line for every instruction executed by the computer. Higher-level languages such as Fortran introduced a more dramatic breakthrough. A compiler could translate one comparatively understandable statement into many machine instructions.</p><p>This is the basic pattern that has repeated throughout the history of software. Each new layer compresses more mechanical work into a smaller unit of human intention.</p><h2><strong>What Abstraction Actually Means<br></strong></h2><p>Abstraction is often described simply as &#8220;hiding complexity&#8221; which is partly explanatory. Abstraction is the process of taking a complicated system and exposing only the parts necessary to use it for a particular purpose.</p><p>A driver does not need to understand combustion chemistry in order to press the accelerator. A person using a microwave does not need to understand the behavior of electromagnetic radiation in order to heat a burrito. Similarly, a programmer calling a function named sort() does not need to manually instruct the processor to compare pairs of values and move data between memory locations until the list is ordered.</p><p>An abstraction is therefore something like a contract. The programmer provides an instruction at the higher layer, and the lower layers agree to carry it out. Provided the contract holds, the programmer can stop thinking about the implementation and begin thinking about the objective.</p><p>Good abstractions increase what might be called semantic density: the amount of intention contained in a single instruction. A machine-code instruction may move one value from one location to another. A Python function might download a file, process its contents and place the results in a database. The programmer using Python is not necessarily smarter than the machine-code programmer. The programmer has simply inherited several generations of accumulated work.</p><h2><strong>From Machine Instructions to Human Intentions<br></strong></h2><p>The ascent from machine code to assembly language allowed programmers to think in symbols rather than numbers. The ascent from assembly to compiled languages allowed them to think in mathematical operations, data structures and logical procedures rather than individual processor instructions. Operating systems then abstracted away much of the difficulty of interacting with memory, storage, displays and networks. Libraries allowed programmers to reuse solutions created by others. Frameworks allowed them to assemble entire applications around preexisting structures.</p><p>Python seemed, for a time, like something close to the final boss of abstraction. Its syntax was comparatively clean, its high-level data structures were powerful and its design made rapid application development far easier than it had been in lower-level languages. Someone looking at a simple Python program might say that it resembled ordinary written instructions.</p><p>But Python was never normal language.</p><p>A Python program may be readable, but it remains a formal statement addressed to a machine. A computer does not infer that the programmer &#8220;basically meant&#8221; something else. The programmer must translate his objective into the exact language the system is prepared to accept.</p><p>Large language models introduce a new layer. We are no longer merely using a programming language that vaguely resembles normal language. We are beginning to use normal language itself to build software.</p><p>A person can now say: &#8220;Add a page that allows users to upload a spreadsheet, identify duplicate entries and download a cleaned version. Preserve the existing visual style and add tests.&#8221; A coding agent can inspect the existing project, locate the relevant files, form a plan, write the code, run the tests, observe the failures and revise its work.</p><p>The instruction does not specify which files to modify, which libraries to import or how the data should move through memory. It specifies an outcome.</p><p>Natural language has therefore become a supervisory layer above source code. The LLM translates an ambiguous statement of intent into a more formal plan, which is translated into source code, which is translated into lower-level instructions, which are ultimately executed by hardware.</p><h2><strong>Abstraction and Agency<br></strong></h2><p>Each level of abstraction has increased the agency of the person operating at that level.</p><p>Agency, in this context, is the amount of meaningful change a person can produce through a given amount of effort. A machine-code programmer could exercise extraordinary control over a computer, but relatively little control over the wider world. He might spend a day producing behavior that a modern programmer can request through a single library call.</p><p>The economic value created at the lower levels remains immense. We still need electrical engineers, chip designers, compiler engineers, operating-system developers and assembly-language specialists. In some contexts&#8212;embedded systems, operating systems, high-performance computing and security&#8212;their work is irreplaceable.</p><p>But most opportunities for economic value appear at the layers with the greatest agency. Businesses generally do not make money because they moved a value efficiently between two processor registers. They make money because they solved a customer&#8217;s problem, reduced a cost, created a useful service or coordinated people more effectively.</p><p>Higher abstraction allows the programmer to spend less attention on how the computer works and more attention on what the computer should do.</p><p>LLM coding agents expand this agency again. A capable software engineer can supervise several streams of work rather than manually producing every line. A domain expert with limited programming experience can create prototypes that previously required a technical team. A small company can attempt projects that would once have been uneconomical. The scarce resource begins to shift away from the mechanical production of code and toward the selection and definition of worthwhile objectives.</p><p>This changes which expertise matters at the margin. Syntax becomes somewhat less valuable. Judgment, system design, domain knowledge, verification and the ability to describe a problem precisely become more valuable.</p><h2><strong>LLMs as a Normal Technology<br></strong></h2><p>Seen through this history, LLM coding looks less like the arrival of an alien intelligence and more like the continuation of a familiar technological process.</p><p>The term &#8220;normal technology&#8221; is used to distinguish from both utopian and apocalyptic conceptions of AI. &#8220;Normal&#8221; does not mean unimportant. Electricity and the internet are normal technologies in this sense, despite transforming nearly every part of modern life. It means that AI remains a tool whose effects depend on applications, institutions, adoption, complementary investments and human decisions. Improvements in an underlying model do not instantly reorganize the economy. They must first be incorporated into useful products and then diffused through actual organizations.</p><p>Coding agents fit this framework exceptionally well. They do not float above society as an independent intelligence. </p><h2><strong>What Comes After Natural Language?</strong></h2><p>This brings us to another question: how can our understanding of past abstractions help us to understand what the next level of abstraction look like?</p><p>The next rung may move from software specification to outcome specification.</p><p>Today, a person might tell an agent to build a claims-processing application. A future system might instead receive the instruction: &#8220;Reduce the average time required to process an insurance claim by 30 percent without increasing fraud, violating privacy rules or exceeding this budget.&#8221;</p><p>The system might interview employees, inspect existing workflows, propose several alternatives, build the necessary applications, connect them to existing databases, run a limited pilot, measure the results and revise the process. Software would become less of a fixed product and more of a continuously changing instrument through which an organization pursues its goals.</p><p>This would create extraordinary agency, but also extraordinary opportunities to make mistakes. A poorly written line of machine code might crash one program. A poorly specified institutional objective could redirect thousands of automated decisions. At every new level of abstraction, the unit of instruction becomes more powerful. The consequences of ambiguity increase with it.</p><p>The future programmer may therefore look less like a person writing code and more like a combination of architect, product manager, auditor and constitutional lawyer. The task will be to determine what the system should optimize, what it must never do and who remains accountable when the abstraction fails.</p><p>The lower layers will not disappear. They never have. More software will likely produce greater demand for the comparatively small number of people capable of repairing compilers, securing operating systems, designing chips and understanding what is actually happening underneath the interface.</p><p>But most people will work higher up.</p><p>The history of software is the history of expanding the distance between what a human must say and what a machine can do. LLM coding agents are not the end of programming. They are the next rung on the ladder. And, as in every previous generation, the most important question will not be whether the new abstraction can produce more code. It will be what human beings choose to do with the additional agency it gives them.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Amodei's Coup]]></title><description><![CDATA[Most of today's AI-powered military tools are designed with moral and legal guardrails&#8212;until private companies embed personal objections that can silently veto critical actions.]]></description><link>https://www.letters.senteguard.com/p/amodeis-coup-823</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/amodeis-coup-823</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Sun, 19 Jul 2026 15:57:08 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840190/10f02a6f5afbecbe22708a8355d43b4f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qgI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qgI4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 424w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 848w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1272w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qgI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:779583,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207840190?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qgI4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 424w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 848w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1272w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most of today's AI-powered military tools are designed with moral and legal guardrails&#8212;until private companies embed personal objections that can silently veto critical actions. Imagine a missile defense system refusing to engage because the AI&#8217;s ethical framework flags a potential legal issue. Or a crowd surveillance drone halted because a private firm&#8217;s moral stance restricts mass data collection. These scenarios reveal a dangerous shift: private AI firms gaining unseen power over life-and-death decisions, replacing democratic oversight with corporate moral judgments. In this eye-opening episode, we dissect how the legal ambiguities and technical opacity of AI systems threaten civilian authority and global security. You&#8217;ll discover how vague definitions like "mass surveillance" and "autonomous weapons" conceal profound risks&#8212;who really controls these weapons, and who is ultimately accountable? We break down the troubling practice of private companies maintaining veto power over lawful military actions and embed moral decisions directly into autonomous systems. This isn't just theory&#8212;it's happening now, with serious implications for democracies and allies worldwide. You'll hear how AI developers' &#8220;ethical safeguards&#8221; can become Trojan horses, quietly reshaping authority at machine speed. We explore the threats of hidden code prompts, undisclosed priorities, and the erosion of civilian oversight&#8212;raising urgent questions: Who writes the rules in the future battlefield? Who keeps governments accountable when AI systems interpret laws and morality on their own? As AI advances, the line between corporate discretion and democratic command blurs, risking usurpation of legal authority and accountability.Why should you care? Because the integrity of global security, the rule of law, and democratic sovereignty hang in the balance. Those who understand these risks are better equipped to demand transparency and oversight in AI military applications&#8212;before the hidden veto becomes the new normal. Perfect for policymakers, military leaders, AI enthusiasts, and anyone concerned with the future of democracy in the AI age, this episode offers a vital wake-up call on the unseen power of private AI firms shaping our security landscape</p>]]></content:encoded></item><item><title><![CDATA[What is Idea Leakage?]]></title><description><![CDATA[The rapid rise of large language models (LLMs) like ChatGPT and Copilot is transforming industries&#8212;accelerating research, streamlining workflows, and boosting productivity.]]></description><link>https://www.letters.senteguard.com/p/what-is-idea-leakage-033</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/what-is-idea-leakage-033</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 15 Jul 2026 18:50:55 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840191/65c0f43d56b8507b54e60440c9b4af60.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>The rapid rise of large language models (LLMs) like ChatGPT and Copilot is transforming industries&#8212;accelerating research, streamlining workflows, and boosting productivity. But as organizations race to adopt these powerful tools, a hidden threat emerges: idea leakage. Even without overt data breaches, your strategic logic, internal decision-making, and client relationships can become predictable&#8212;leaked not through files, but through the very reasoning that powers your success.Imagine a mid-sized company using an LLM to plan next year's strategy. They input sensitive data&#8212;profitability thresholds, reasons for customer churn, lessons learned from failed pilots. At first glance, nothing seems off. But secretly, these fragments encode the core of their competitive advantage. Over time, a competitor noticing similar structures and conclusions can reverse-engineer their approach&#8212;not by stealing documents, but by understanding the underlying logic that drives their decisions. This subtle erosion of intellectual edge is the new frontier of corporate risk in the AI <a href="http://age.In">age.In</a> this episode, we break down the emerging challenge of idea leakage and how ambient LLMs expand the surface for unintentional exposure. You'll discover:</p><ul><li><p>How seemingly innocuous inputs can reveal your organization's strategic "scaffolding"</p></li><li><p>Real-world examples of how confidential plans can become predictable without any hacks or data theft</p></li><li><p>The limitations of traditional security methods when LLMs operate inside everyday tools like email and chat</p></li><li><p>Why protecting ideas&#8212;and the logic behind your decisions&#8212;is critical for maintaining competitive advantage</p></li><li><p>How novel solutions like SenTeGuard help organizations prevent the inference of their confidential reasoning without sacrificing productivity</p></li></ul><p>This isn&#8217;t just about avoiding data leaks&#8212;it's about safeguarding your organization&#8217;s very thought processes. As AI becomes embedded into daily workflows, understanding the risk of idea leakage is essential for leaders who want to stay ahead without exposing what makes them unique. Perfect for strategists, security professionals, and anyone leveraging AI-driven tools today: Learn how to think about AI security differently&#8212;protect not just your files, but the secrets hidden in your reasoning.</p><h6><strong>Why this works:</strong></h6><p>This description pinpoints a subtle, yet critical risk in AI adoption that many overlook, creating intrigue around &#8220;idea leakage.&#8221; It&#8217;s tailored for decision-makers eager to sustain competitive advantage while embracing AI, offering concrete insights and practical solutions that make the episode immediately valuable.</p>]]></content:encoded></item><item><title><![CDATA[Ambient AIs]]></title><description><![CDATA[Most companies are blindsided by the hidden risks of ambient AI &#8212; the pervasive, background presence of large language models (LLMs) in everyday work tools.]]></description><link>https://www.letters.senteguard.com/p/ambient-ais-4af</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/ambient-ais-4af</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 13 Jul 2026 14:05:45 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840192/b41b5dd964ef74042ddf67d74346cda2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Most companies are blindsided by the hidden risks of ambient AI &#8212; the pervasive, background presence of large language models (LLMs) in everyday work tools. If you're relying on AI for productivity but haven't updated your security mindset, you're vulnerable to idea leaks, data breaches, and strategic leaks that happen without you realizing it. This episode reveals why the future of AI security isn't about patchwork policies but about embedding safeguards directly into your workflows, before sensitive information even leaves the user&#8217;s <a href="http://device.As">device.As</a> AI becomes embedded into everything &#8212; from email drafts and meeting summaries to code debugging and browser assistance &#8212; the boundaries between approved tools and risky leaks blur. You&#8217;ll discover how major tech giants like Microsoft, Google, and Apple are integrating LLMs into their ecosystems, and why this widespread adoption creates new security vulnerabilities that traditional policies can't address. We break down the concept of "leakage cascades," where a single security slip can ripple through an organization&#8217;s entire knowledge base, and reveal the hidden costs of relying solely on user judgment and vague <a href="http://warnings.You">warnings.You</a>&#8217;ll learn about the threat of &#8220;idea leakage,&#8221; where proprietary insights, strategic concepts, or even intellectual property can quietly escape through routine AI interactions &#8212; even when no confidential data is explicitly pasted. We explore the emerging paradigm shift: security needs to be proactive and placed at the point of interaction, with real-time control tools that detect and block sensitive content before it leaves the device. This episode dives into practical strategies for organizations to implement ambient security measures, vendor scrutiny, and employee education&#8212;arming you with the foresight to navigate the AI-powered workplace securely.If your organization depends on AI tools, ignoring these risks isn't an option &#8212; the cost of a leak is too high, and the opportunity to protect it starts now. Perfect for security professionals, tech leaders, or anyone using AI in daily workflows, this episode transforms your understanding of modern AI risks from reactive to proactive, ensuring you stay one step ahead in the ambient AI era.</p>]]></content:encoded></item><item><title><![CDATA[PageRank For Inference]]></title><description><![CDATA[Essay - https://www.letters.senteguard.com/p/pagerank-for-inference-mapping-reachability Visualizing and Managing Complexity in the LLM Era with SenTeGuard]]></description><link>https://www.letters.senteguard.com/p/pagerank-for-inference-96a</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/pagerank-for-inference-96a</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Fri, 10 Jul 2026 21:14:27 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840193/d805003586905e4d473aa28c6d45a15c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h5>Essay - <a href="https://www.letters.senteguard.com/p/pagerank-for-inference-mapping-reachability">https://www.letters.senteguard.com/p/pagerank-for-inference-mapping-reachability</a> Visualizing and Managing Complexity in the LLM Era with SenTeGuard</h5><p>In this episode, we explore how the same principles that transformed the web and cloud infrastructure are now shaping AI and large language models (LLMs). With insights from David Weidman of SenTeGuard, discover how organizations can gain visibility and control over AI inference risks.</p><h6><strong>Key Topics:</strong></h6><ul><li><p>The evolution of mapping complexity: from Google Link Graph to AWS infrastructure</p></li><li><p>The emerging risk surface of LLM inference and reachability</p></li><li><p>How SenTeGuard&#8217;s three-layer platform (Moyo, SentaGuard, Joseki Wrapper Hub) makes LLM environments understandable and governable</p></li><li><p>Why visibility into what can be inferred from scattered data is crucial for AI safety</p></li><li><p>The importance of structural reachability maps and enforceable boundaries in high-stakes AI deployment</p></li><li><p>Practical examples: How Moyo shows inference risks when combining data sources</p></li><li><p>The role of SentaGuard in real-time policy enforcement at the point of AI use</p></li><li><p>Centralizing control via Joseki Wrapper Hub to standardize and operationalize AI workflows</p></li><li><p>Why AI infrastructure needs the same confidence and governance as cloud infrastructure</p></li></ul><h6><strong>Timestamps:</strong></h6><p>00:00 - The evolution of complexity visualization from Google to AWS<br>00:22 - The challenge of inference and reachability in LLMs<br>01:13 - How LLMs connect scattered data and surface new inferences<br>01:55 - The concept of "reachability" as a new risk surface<br>02:36 - Why traditional security models break down with LLMs<br>03:06 - An overview of SenTeGuard&#8217;s three-layer platform<br>03:22 - Moyo: Mapping inference exposure across data sources<br>04:08 - SentaGuard: Enforcing policies at the point of use<br>04:45 - Joseki Wrapper Hub: Orchestrating complex LLM workflows<br>05:39 - The future of AI infrastructure with confidence and control</p><h6><strong>Resources &amp; Links:</strong></h6><ul><li><p><a href="https://senteguard.com/">SenTeGuard</a> &#8212; Official website</p></li><li><p><a href="https://en.wikipedia.org/wiki/PageRank">PageRank</a> &#8212; Google&#8217;s link analysis algorithm</p></li><li><p><a href="https://aws.amazon.com/">AWS</a> &#8212; Amazon Web Services official site</p></li></ul><h6><strong>Connect with David Weidman:</strong></h6><ul><li><p><a href="https://linkedin.com/in/davidweidman">LinkedIn</a></p></li><li><p><a href="https://twitter.com/davidweidman">Twitter</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[There's Always Another Apocalypse]]></title><description><![CDATA[Essay - https://www.letters.senteguard.com/p/there-is-always-another-apocalypse]]></description><link>https://www.letters.senteguard.com/p/theres-always-another-apocalypse-b76</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/theres-always-another-apocalypse-b76</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Thu, 09 Jul 2026 23:02:55 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840194/947b34d7ce022295899434143916ad0c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Essay - <a href="https://www.letters.senteguard.com/p/there-is-always-another-apocalypse">https://www.letters.senteguard.com/p/there-is-always-another-apocalypse</a><br><br>In this episode, we explore how fears around artificial intelligence are often amplified to justify centralized control, benefiting powerful interests. We examine historical parallels and the importance of open-source AI for maintaining competition and innovation.Key Topics:</p><ul><li><p>The recurring pattern of "apocalypses" in history and their influence on policy</p></li><li><p>Bruce Yandel's Bootleggers and Baptists theory applied to AI regulation</p></li><li><p>How genuine threats are weaponized for political and economic gains</p></li><li><p>The role of open-source models in fostering a diverse and competitive AI ecosystem</p></li><li><p>The risks of sweeping licensing regimes and their impact on smaller innovators</p></li><li><p>The parallels between AI regulation and post-9/11 security measures</p></li><li><p>Cultural roots of doom-mongering and the importance of humility in facing uncertainty</p></li><li><p>The danger of regulation that favors incumbents and stifles innovation</p></li><li><p>The significance of open models for decentralization and pluralism in AI</p></li></ul><p>Timestamps: 00:00 - The recurring cycle of apocalyptic fears across eras<br>00:26 - How powerful interests promote regulation for self-benefit<br>01:14 - Yandel&#8217;s Bootleggers and Baptists theory explained in current AI debates<br>01:54 - Practical uses of open-source AI models and their importance<br>02:29 - The threat of overreach: sweeping regulations and centralization<br>02:48 - Historical parallels: post-9/11 security and climate control measures<br>03:22 - Cultural context: the decline of religious frameworks and embracing humility<br>04:06 - The rhetoric around control versus prudent regulation<br>04:38 - The strategic importance of open-source AI against monopolistic forces<br>05:16 - Recognizing symbolic warnings and resisting fear-mongering for political gains<br>05:36 - The responsibility to protect liberty from prophets of doomResources &amp; Links:</p><ul><li><p><a href="https://en.wikipedia.org/wiki/Baptists_and_bootleggers">Bruce Yandel's Bootleggers and Baptists Theory</a></p></li><li><p><a href="https://huggingface.co/">Hugging Face - Open-source AI models</a></p></li><li><p><a href="https://cdt.org/">Understanding AI Regulation, Center for Democracy &amp; Technology</a></p></li></ul><p>Connect with David Weidman:</p><ul><li><p><a href="https://twitter.com/davidweidman">Twitter</a></p></li><li><p><a href="https://linkedin.com/in/davidweidman">LinkedIn</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[What is SenTe?]]></title><description><![CDATA[https://www.letters.senteguard.com/p/what-is-sente]]></description><link>https://www.letters.senteguard.com/p/what-is-sente-dc1</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/what-is-sente-dc1</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 08 Jul 2026 21:00:53 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840195/8b2b34fe4f3d96722636ea4f069a3523.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><a href="https://www.letters.senteguard.com/p/what-is-sente">https://www.letters.senteguard.com/p/what-is-sente</a><br><br>In Go, or Baduk, <em>sente</em> means having the initiative: making moves that set the tempo and force your opponent to respond. Its opposite is <em>gote</em>, where you react from behind.</p><p>This episode uses the story of Lee Sedol, AlphaGo, and the legendary Move 37 to explore what AI teaches us about strategy, creativity, and cybersecurity. AlphaGo showed that machines can produce moves humans do not predict until the consequences unfold. In cybersecurity, that kind of surprise can be dangerous.</p><p>As AI changes how attackers operate and how organizations use sensitive information, defenders cannot afford to stay reactive. The challenge is to move from gote to sente: from patching after incidents to spotting risk earlier, prioritizing better, and building security into the workflows people already use.</p>]]></content:encoded></item><item><title><![CDATA[Nailing Jell-O to the Wall - Can China Contain LLMs]]></title><description><![CDATA[Essay - https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again]]></description><link>https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-can-china-fa9</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-can-china-fa9</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Thu, 02 Jul 2026 21:56:04 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840196/bc50964d3e5b48af47da4d8ccb35bd2e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Essay - <a href="https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again">https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again</a><br><br>Summary<br>This conversation explores the complex relationship between the Chinese Communist Party and the rise of large language models (LLMs). It discusses how the internet has been absorbed into state control, the economic implications of LLMs for China's political legitimacy, and the challenges posed by these technologies to traditional censorship and control mechanisms. The discussion also delves into potential responses from Beijing, including the development of national champion models and the implications of open models in a constrained environment.<br><br>Takeaways<br>In 2000, Clinton joked about China's internet control.<br>The internet has become a tool of state control in China.<br>Large language models (LLMs) synthesize information and enhance productivity.<br>Beijing faces a dilemma between growth and maintaining authority.<br>China's political legitimacy relies on economic performance.<br>Heavy regulation of LLMs may hinder productivity growth.<br>Jailbreaking LLMs poses challenges to state control.<br>Open models can be harder to control than centralized systems.<br>An arms race between police AIs and outlaw AIs is possible.<br>Beijing's responses to AI challenges may impact innovation.</p>]]></content:encoded></item><item><title><![CDATA[OracleGPT: Thought Experiment on an AI-Powered Executive]]></title><description><![CDATA[In this conversation, David Weidman discusses the concept of Oracle GPT, a hypothetical AI model designed to assist the President of the United States in national security decision-making.]]></description><link>https://www.letters.senteguard.com/p/oraclegpt-thought-experiment-on-an-034</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/oraclegpt-thought-experiment-on-an-034</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 24 Jun 2026 22:51:10 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203571663/2c46904a4f6593146d4cf617e6d27aef.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this conversation, David Weidman discusses the concept of Oracle GPT, a hypothetical AI model designed to assist the President of the United States in national security decision-making. He explores the implications of such a system, including the potential for increased efficiency and coherence in crisis situations, while also addressing the significant risks and ethical challenges it poses. The conversation delves into the balance of power between the presidency and other branches of government, the dangers of misinformation, and the need for accountability in the use of advanced AI technologies.</p><p>Takeaways</p><p>Oracle GPT is a thought experiment on AI in national security.</p><p>The President could have unprecedented access to intelligence.</p><p>There are significant risks associated with AI in decision-making.</p><p>The balance of power may shift towards the presidency.</p><p>Presidential competence is crucial for using Oracle GPT effectively.</p><p>Misinformation could be a major risk with such a system.</p><p>Ethical implications must be considered in AI recommendations.</p><p>Human judgment should not be treated as an obstacle by AI.</p><p>The design of Oracle GPT must ensure accountability.</p><p>The constitutional order must be preserved in AI usage.</p><p>titles</p>]]></content:encoded></item><item><title><![CDATA[Big Frontier, China and Regulatory Capture]]></title><description><![CDATA[This episode explores the complex dynamics of open versus closed AI models, the geopolitical implications, and the importance of fostering open competition for innovation and security.]]></description><link>https://www.letters.senteguard.com/p/big-frontier-china-and-regulatory-9eb</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/big-frontier-china-and-regulatory-9eb</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 24 Jun 2026 21:57:20 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203571664/5d1d234348e9033dbd879a7abafa2543.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This episode explores the complex dynamics of open versus closed AI models, the geopolitical implications, and the importance of fostering open competition for innovation and security.</p><p><strong>keywords</strong>AI models, open source, closed source, geopolitics, innovation, regulation, AI safety, public investment, model distillation, AI race</p><p><strong>key topics</strong></p><ul><li><p>Open vs closed AI models and their implications</p></li><li><p>Geopolitical framing of AI development</p></li><li><p>Regulatory capture and industry incentives</p></li><li><p>AI safety and dual-use concerns</p></li><li><p>Knowledge diffusion and model distillation</p></li><li><p>Public investment in AI and race to AGI</p></li><li><p>Enforcement challenges for open models</p></li><li><p>The future of AI innovation and competition</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Cyborg Scholars]]></title><description><![CDATA[As large language models reshape how knowledge is created and shared, academia faces fundamental questions about authorship, accountability, and the future of scholarly communication.]]></description><link>https://www.letters.senteguard.com/p/cyborg-scholars-c34</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/cyborg-scholars-c34</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 24 Jun 2026 17:41:44 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203571665/0f69e100542b6fc54424f36f2a6e5b6e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>As large language models reshape how knowledge is created and shared, academia faces fundamental questions about authorship, accountability, and the future of scholarly communication. This episode explores how AI tools challenge traditional norms and open new opportunities for democratizing knowledge.</p><h6><strong>Key topics:</strong></h6><ul><li><p>The evolving concept of authorship in academia and software development</p></li><li><p>How LLMs accelerate knowledge production and collaboration</p></li><li><p>Cultural norms around attribution, attribution, and hierarchy reforms</p></li><li><p>The analogy of cyborg chess to future scholarship</p></li><li><p>Language barriers and the role of LLMs as a new lingua franca</p></li><li><p>Ethical considerations: transparency, accountability, and fraud prevention</p></li><li><p>The aesthetic versus pragmatic uses of language in scholarship</p></li><li><p>Updating authorship norms for an AI-augmented future</p></li></ul>]]></content:encoded></item><item><title><![CDATA[June 2026 SenTeGuard Update / Article Roll-Up]]></title><description><![CDATA[Friends and Readers,]]></description><link>https://www.letters.senteguard.com/p/june-2026-senteguard-update-article</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/june-2026-senteguard-update-article</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 10 Jun 2026 20:39:49 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d9810905-50b7-4234-8a85-d3aa9bf89e2a_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friends and Readers,</p><p><br>Late last month I graduated from the Harvard Kennedy School with a Master in Public Policy. Beginning July I will be based in Austin, TX. Thank you to everyone who has helped me along the way. I am deeply grateful for all of the support.</p><p>Thank you, too, to those who have signed up since my last update. Please share if you know of anyone who would be interested.</p><p><strong>On Request:</strong></p><ul><li><p>Prototype testing of the<a href="https://senteguard.com/blog/sensitive-information-reachability-the-problem-and-the-solution-1768745959993"> Moyo</a> information space mapper. Find leaks of your secrets (classified, proprietary, personal) in public LLMs (ChatGPT, Claude, Qwen, Grok, etc).</p></li><li><p><a href="https://senteguard.com/blog/the-emerging-threat-of-idea-leakage">SenTeGuard Pilot</a> - protect yourself or your organization from leakage of valuable information through air-gap capable semantic guardrails. <a href="https://www.letters.senteguard.com/p/the-emerging-threat-of-idea-leakage">Substack</a></p></li><li><p>Let&#8217;s Talk:</p><ul><li><p>Private - How can your organization more effectively secure your secrets in the LLM era through implementation of the Cognitive Security Verification Framework (<a href="https://senteguard.com/blog/csvf-concept">CSVF</a>) and by other means.</p></li><li><p>Public - How to craft tech-positive, pro-future, big-tech skeptical market-oriented policies of abundance in the LLM era.</p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>Writing Roll-Up<br></strong></h2><p><strong>Broad Policy Articles:</strong></p><ol><li><p><a href="https://senteguard.com/blog/ai-and-powerlessness">AI and Powerlessness</a>. The popular framing around AI safety contains several important gaps. In this essay, I explore a number of high-level technical considerations that complicate assumptions about control, with the goal of moderating both the tendency toward catastrophism and the presumption that AI systems can be straightforwardly governed through centralized oversight. <a href="https://www.letters.senteguard.com/p/ai-and-powerlessness">Substack</a></p></li><li><p><a href="https://senteguard.com/blog/there-is-always-another-apocalypse">There is Always Another Apocalypse.</a> Every era has its own existential dread, and while AI risks are real, treating every new technology as the end of the world can distort judgment around policy. <a href="https://www.letters.senteguard.com/p/there-is-always-another-apocalypse">Substack</a></p></li><li><p><a href="https://senteguard.com/blog/amodei-coup">Amodei&#8217;s Coup</a>. Anthropic&#8217;s policy posture reveals how private AI companies can quietly claim political authority by deciding what governments and institutions should or should not be allowed to do with frontier models. <a href="https://www.letters.senteguard.com/p/amodeis-coup">Substack</a></p></li></ol><p><strong>SenTe Focused Articles:</strong></p><ol><li><p><a href="https://senteguard.com/blog/meet-joseki">Meet Joseki:WrapperHub</a>. WrapperHub introduces a marketplace for reusable AI &#8220;wrappers&#8221; that package prompts, workflows, evaluations, and guardrails into shareable tools for safer and more structured AI use. <a href="https://www.letters.senteguard.com/p/meet-joseki-wrapperhub">Substack</a>. <a href="https://josekiwrapperhub.com/">Site</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zkJl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zkJl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 424w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 848w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1272w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zkJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png" width="1254" height="401" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:401,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:341426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/201507925?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zkJl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 424w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 848w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1272w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p><a href="https://senteguard.com/blog/csvf-concept">The Cognitive Security Verification Framework.</a> The framework argues that LLM-era data security must move beyond detecting protected strings and toward measuring what protected conclusions a model can help users infer. I will be speaking on this topic at BSides San Antonio on June 3th. <a href="https://www.letters.senteguard.com/p/the-cognitive-security-verification">Substack</a></p><p></p><p>David</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.letters.senteguard.com/subscribe?"><span>Subscribe now</span></a></p><p></p><p><br><br></p></li></ol>]]></content:encoded></item><item><title><![CDATA[There Is Always Another Apocalypse]]></title><description><![CDATA[Original]]></description><link>https://www.letters.senteguard.com/p/there-is-always-another-apocalypse</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/there-is-always-another-apocalypse</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 10 Jun 2026 20:03:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xCku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xCku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xCku!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xCku!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xCku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg" width="1456" height="1082" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1082,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:739638,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/201504860?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xCku!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xCku!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image buttonBase-GK1x3M"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg" class="icon-noB79L"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image buttonBase-GK1x3M"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2 icon-noB79L"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/there-is-always-another-apocalypse">Original</a></p><p>Tales of apocalypse has always been useful. From Cold War strategists to the War on Terror, every age finds its own end of the world and every age concludes that extraordinary threats demand the suspension of ordinary limits on power. Artificial intelligence is simply the newest entry in this genre. We are told the technology is so uniquely dangerous that free speech, privacy, competition, open research, and democratic accountability must all be sacrificed for our survival. Not coincidentally, the beneficiaries of sacrifice happen to be the wealthiest people and companies in human history.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Regulatory Capture in Disguise<br></h2><p>Bruce Yandle&#8217;s &#8220;Bootleggers and Baptists&#8221; theory explains how durable regulation often emerges when two very different coalitions support the same restriction for different reasons: the &#8220;Baptists&#8221; provide the moral language and public legitimacy, while the &#8220;Bootleggers&#8221; quietly profit from the restriction itself. Current AI regulatory proposals provide the perfect modern parallel. The Baptists warn of doom and insist that they are only trying to save humanity, while the Bootleggers provide the money, the lobbyists, the institutional access, and the quiet understanding that the rules being proposed will just happen to entrench the incumbents. In other words, someone with pure motives may inadvertently and indirectly promote the interests of the self-interested.</p><p>Big Frontier firms and their advocates know that a small startup working in a garage will not survive a vast compliance regime. A university researcher will not be able to compete with a trillion-dollar firm blessed by federal regulators. Open source developers sharing models on Hugging Face will be told that their work is too dangerous for public release, despite the fact that much of this ecosystem is not composed of godlike machines plotting the end of mankind but rather practical tools that researchers, companies, and hobbyists adapt for narrow and often mundane purposes. Hugging Face reported that in 2025 its ecosystem had grown to 13 million users, more than 2 million public models, and more than 500,000 public datasets, while one 2026 analysis found that in 2024 Hugging Face recorded an average of 2,199 new models created per day.</p><p>&#8220;AI regulation&#8221; sounds abstract until one considers what these open models actually do. Embedding models, for example, convert text into numerical representations that can be used for search, retrieval, classification, and semantic similarity, which means they help people find documents, organize information, and build better internal knowledge systems. A sweeping licensing regime would not simply restrain frontier labs. It would also burden the open, competitive, and decentralized ecosystem that allows smaller actors to build useful systems without asking permission from a handful of corporations and regulators.</p><h2>Continuation of a Trend <br></h2><p>The easiest way to centralize authority is to tell people that the normal rules are inadequate to confront the emergency. After September 11, Americans were told that liberty had to be balanced against security in ways that would have been unthinkable a decade earlier. During the nuclear age, international coercive inspection regimes were devised and regime change wars were carried out to prevent proliferation. During climate debates, the proposed solution is often not merely stewardship or innovation, but control of the world economy.</p><p>In each case, there is a real problem, but rather than addressing it through less invasive means, the powerful formulate and implement solutions meant to further their own interests. Concerns over terrorism, nuclear war, environmental degradation, and the negative side effects of AI are all valid. But it would be a mistake to take a real danger, elevate it into an existential emergency, and then use that emergency to justify extreme solutions crafted by self-interested parties.</p><h2>A New Trend?<br></h2><p>The decline of religious life in the West has left many without a framework for mortality, uncertainty, and suffering. Where religion once taught people to think in those terms, secular politics now offers thinner substitutes. At their best, believers understand that catastrophe is not an aberration but part of the human condition. Every life ends in an apocalypse of its own, and every civilization is temporary. The proper response to this knowledge is not panic, but humility. A society that loses this grounding becomes easy prey for prophets of doom because people who cannot sit with uncertainty will surrender freedom to anyone who promises safety.</p><p>The loudest voices do not simply argue for prudence. Prudence would mean better cybersecurity, clearer liability rules, and a sober understanding of how this technology will affect society. Instead, many argue for control. They want licensing, censorship, centralization, and a priesthood of approved experts, along with preferential rules for the politically well connected. We should be particularly suspicious of any regulation that acts as a de facto moratorium on open-source AI, as open-source language models pose perhaps the greatest threat to the <a href="https://www.letters.senteguard.com/p/american-closed-source-vs-chinese">profitability</a> and dominance of the Big Frontier firms. While every age has had its prophets and warnings of final judgment, we should be wary that in an increasingly secular world, we do not allow these secular eschatologists to achieve their political objectives through fearmongering.</p><p>There is always an apocalypse to fear, there is always someone willing to explain why this time is different, and there is always a class of people eager to convert your fear into their dominance. The duty of those who value liberty is not to deny danger. It is to deny the prophets of doom the ability to convert timeless, human existential fear to a politics of control.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>