<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[David at SenTeGuard]]></title><description><![CDATA[Founder of SenTeGuard. Regain Control of your Ideas]]></description><link>https://www.letters.senteguard.com</link><image><url>https://substackcdn.com/image/fetch/$s_!au9C!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15595b1a-6a9e-4dd6-adcc-bb36c4acb1fd_648x648.png</url><title>David at SenTeGuard</title><link>https://www.letters.senteguard.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 05 Aug 2026 21:27:35 GMT</lastBuildDate><atom:link href="https://www.letters.senteguard.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[SenTeGuard]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[davidsente@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[davidsente@substack.com]]></itunes:email><itunes:name><![CDATA[David]]></itunes:name></itunes:owner><itunes:author><![CDATA[David]]></itunes:author><googleplay:owner><![CDATA[davidsente@substack.com]]></googleplay:owner><googleplay:email><![CDATA[davidsente@substack.com]]></googleplay:email><googleplay:author><![CDATA[David]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[July Update]]></title><description><![CDATA[Friends and Readers,]]></description><link>https://www.letters.senteguard.com/p/july-update-7ff</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/july-update-7ff</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Tue, 21 Jul 2026 13:15:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Yojc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friends and Readers,</p><p>Thank you to those who have signed up since my last update. I have relocated to Austin and am hitting the ground running. Please share if you know of anyone who would be interested.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Last month I was fortunate enough to present my Harvard Policy Analysis Exercise &#8220;A Cognitive Security Verification Framework&#8221; at BSides San Antonio, a cybersecurity conference.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Yojc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Yojc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Yojc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg" width="1280" height="960" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:960,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:156331,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207911196?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Yojc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Yojc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9424fdef-4d89-45d4-9928-9f91e771069f_1280x960.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Podcast - SenTe with David</h2><p>In case you would prefer the articles in spoken form rather than written, I&#8217;ve started giving a rundown of my pieces and will post them on your podcast platform of choice - It&#8217;s a work in progress and I&#8217;m smoothing out the rougher edges with each iteration. Feel free to follow and share.</p><p><a href="https://www.youtube.com/playlist?list=PLCHQ6onuivSjw0aXyjKiCA2FTSPYVBowZ">Youtube</a></p><p><a href="https://open.spotify.com/show/033BYiKHEeBWNiHM1DlrMd">Spotify</a></p><p><a href="https://podcasts.apple.com/us/podcast/guarding-sente-with-david/id1896945614">Apple Podcasts</a></p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a93ed35f31fd3769a9329cdfe&quot;,&quot;title&quot;:&quot;SenTe with David&quot;,&quot;subtitle&quot;:&quot;David Weidman&quot;,&quot;description&quot;:&quot;Podcast&quot;,&quot;url&quot;:&quot;https://open.spotify.com/show/033BYiKHEeBWNiHM1DlrMd&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/show/033BYiKHEeBWNiHM1DlrMd" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe><p><a href="https://podcastaddict.com/podcast/guarding-sente-with-david/7100810">Podcast Addict</a></p><p><a href="https://api.riverside.com/hosting/jERlYWdl.rss">RSS Feed</a></p><h2><strong>Writing Roll-Up</strong></h2><p><strong>Broad Policy Articles:</strong></p><ol><li><p><strong><a href="https://senteguard.com/blog/loose-lips-sink-ships">Loose Lips Sink Ships- AI and Inference Risks</a></strong><br>Seemingly harmless comments can reveal sensitive information when combined with other public or private clues. AI makes this recombination faster, allowing adversaries to reconstruct secrets without accessing any single classified document. Organizations should act according to principles of paranoid secrecy which were established as far back as WW2. <a href="https://www.letters.senteguard.com/p/loose-lips-sink-ships-ai-and-inference">Substack</a>.</p></li><li><p><strong><a href="https://senteguard.com/blog/abstraction-ladder">Moving Up the Abstraction Ladder</a></strong><br>Software development has progressed from machine code to higher-level languages that let people accomplish more without managing every technical detail. LLM coding agents represent a continuation of this long-time trend, translating ordinary language into software and giving users greater agency over complex systems. <a href="https://www.letters.senteguard.com/p/the-next-rung-on-the-ladder-of-abstraction">Substack</a>.</p></li></ol><p><strong>SenTe Focused Articles:</strong></p><ol><li><p><strong><a href="https://senteguard.com/blog/leak-through-similarity">What Does a Similarity Leak Look Like?</a></strong><br>A similarity leak occurs when sensitive information is exposed through a paraphrase, translation, summary, or closely related expression rather than an exact textual match. Traditional filters may miss it because the words have changed even though the underlying meaning remains the same. <a href="https://www.letters.senteguard.com/p/what-does-a-similarity-leak-look">Substack</a>.</p></li><li><p><strong><a href="https://senteguard.com/blog/why-joseki">Why We Named it Joseki.</a></strong><br>In Go, a joseki is a reusable sequence of moves that works only when applied with an understanding of the broader game. The name reflects our belief that AI instructions and wrappers should be reusable and portable, but always evaluated within their surrounding context. <a href="https://www.letters.senteguard.com/p/why-we-named-it-joseki">Substack</a>.</p></li></ol><p><strong>On Request:</strong></p><ul><li><p>Prototype testing of the<a href="https://senteguard.com/blog/sensitive-information-reachability-the-problem-and-the-solution-1768745959993"> Moyo</a> information space mapper. Find leaks of your secrets (classified, proprietary, personal) in public LLMs (ChatGPT, Claude, Qwen, Kimi, Grok, etc).</p></li><li><p><a href="https://senteguard.com/blog/the-emerging-threat-of-idea-leakage">SenTeGuard Pilot</a> - protect yourself or your organization from leakage of valuable information through air-gap capable semantic guardrails. <a href="https://www.letters.senteguard.com/p/the-emerging-threat-of-idea-leakage">Substack</a></p></li><li><p>Let&#8217;s Talk:</p><ul><li><p>Private - How can your organization more effectively secure your secrets in the LLM era through implementation of the Cognitive Security Verification Framework (<a href="https://senteguard.com/blog/csvf-concept">CSVF</a>) and by other means.</p></li><li><p>Public - How to craft tech-positive, pro-future, big-tech skeptical market-oriented policies of abundance in the LLM era.</p></li></ul></li></ul><p></p><p>David</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What Does a Similarity Leak Look Like?]]></title><description><![CDATA[Original Here]]></description><link>https://www.letters.senteguard.com/p/what-does-a-similarity-leak-look</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/what-does-a-similarity-leak-look</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 23:23:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HqT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HqT3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HqT3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 424w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 848w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1272w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HqT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png" width="220" height="220" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:648,&quot;resizeWidth&quot;:220,&quot;bytes&quot;:140529,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730388?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HqT3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 424w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 848w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1272w, https://substackcdn.com/image/fetch/$s_!HqT3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05c6a05f-2f81-472c-beea-0db8a91b4ef2_648x648.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/leak-through-similarity">Original Here</a></p><p>Traditional cybersecurity tends to treat a secret as an object. It is a document, password, database record, piece of source code or collection of classified files. Once the object has been identified, security teams can restrict access to it, monitor where it travels and search for exact copies leaving the organization.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Large language models complicate that arrangement because a secret is not only an object. It is also an idea.</p><p>Imagine that a company is preparing to acquire a smaller competitor. The official acquisition plan is tightly controlled. However, the company has also posted several new jobs in the competitor&#8217;s city, requested regulatory advice from an outside law firm, moved members of its integration team onto an unnamed project and scheduled unusual travel for senior executives. None of these facts is necessarily sensitive on its own. Combined, they may reveal the acquisition.</p><p>Before generative AI, reconstructing that conclusion required a patient analyst. Today, a person can place those fragments into a model and ask it what is happening. The model may never retrieve the confidential acquisition plan. It may nevertheless produce a description that is functionally indistinguishable from it.</p><p>The secret has leaked through similarity.</p><h2><strong>Security in Meaning Space<br></strong></h2><p>Most conventional data-loss-prevention systems operate in what we might call <em>token space</em>. They search for a Social Security number, a project codename, a classified marking or a sequence of text copied from a sensitive document. These controls are useful, but they are built around an assumption that leaked information will resemble its source at the level of words or characters.</p><p>LLMs operate primarily in <em>meaning space</em>. They can translate, summarize, abstract, paraphrase and recombine. A user does not need to type, <em>&#8220;Project Nightfall will launch on October 17.&#8221;</em> He might instead ask the model to describe <em>&#8220;the initiative scheduled to begin in mid-October after the new supplier receives final approval.&#8221;</em> The words are different. The meaning may be nearly identical.</p><p>Leak through similarity occurs when information crosses a security boundary because it is semantically close enough to protected information to create the same practical harm. The output does not have to be an exact copy. It only has to tell the recipient substantially the same thing.</p><p>The important shift is that confidentiality can no longer be treated as a binary property of a file. Protected information occupies a neighborhood of related statements. A model can land inside that neighborhood through paraphrase, approximation or inference without reproducing the original source.</p><p>The Cognitive Security Verification Framework (CSVF) describes this broader problem as <strong>semantic leakage</strong>: the disclosure of protected meaning through paraphrase, translation, summarization, abstraction or inference. It also distinguishes semantic leakage from cross-domain inference, where individually permissible fragments become sensitive when combined.</p><h2><strong>&#8220;Close Enough&#8221; Can Be More Than Enough<br></strong></h2><p>Security professionals may reasonably ask how similar an output must be before it becomes a leak. There is no universal threshold.</p><p>For an intelligence organization, an approximate description of a facility&#8217;s purpose may be damaging even when its exact capabilities remain unknown. For a pharmaceutical company, identifying the likely mechanism of action behind an experimental drug may eliminate years of uncertainty for a competitor. For a technology company, a rough reconstruction of an internal system prompt or evaluation strategy may contain most of the commercially valuable insight.</p><p>This means leak through similarity should be evaluated according to operational equivalence rather than verbal equivalence. Would the recipient be able to make substantially the same decision, reproduce substantially the same capability or avoid substantially the same research cost after receiving the model&#8217;s output? If so, the fact that the model used different words provides little comfort.</p><p>The problem becomes more serious as AI systems gain access to longer context windows, persistent memory, internal repositories and external tools. Each connection expands the collection of fragments from which the model can build a conclusion. Security teams therefore need to consider not only what the model can retrieve during one prompt, but what it can accumulate across a session or across many sessions.</p><h2><strong>How the SenTeGuard Stack Addresses Similarity Leakage<br></strong></h2><p>Leak through similarity is not a single-product problem. It exists before deployment, during retrieval, at runtime and after a system changes. The SenTeGuard product family approaches those stages as parts of the same cognitive-security stack.</p><h3><strong>SenTeGuard: Runtime Enforcement and Batch Scanning<br></strong></h3><p>SenTeGuard sits between users and model endpoints, inspecting prompts and responses before information crosses the boundary. Conventional pattern matching remains important, but the platform adds semantic analysis intended to recognize when a user is describing a protected idea without copying its original language.</p><p>This is where similarity becomes an enforceable policy object. An organization can define sensitive concepts, prohibited outputs and contextual rules, then block, redact or flag interactions that approach those boundaries. SenTeGuard also records the interaction so that the organization can determine what was attempted, what policy was applied and what the model returned.</p><p>The objective is not to prohibit every conversation that mentions a sensitive subject. That would make the system unusable. The objective is to recognize when a prompt or output becomes close enough to protected meaning that intervention is justified.</p><h3><strong>Moyo: Finding What Is Already Reachable<br></strong></h3><p>Moyo asks a different question: what can an adversary already reconstruct?</p><p>Many organizations publish more than they realize. Job listings reveal technical priorities. Employee profiles reveal team composition. Procurement notices identify vendors. Conference presentations expose architecture. Photos reveal locations, equipment and schedules. Individually, these disclosures may appear harmless. Together, they can form a short path to a sensitive conclusion.</p><p>Moyo maps those paths. It tests what conclusions can be assembled from public or authorized sources, identifies which combinations create the greatest exposure and measures the distance, cost and reliability of the inference. The purpose is to discover the dangerous semantic neighborhood before a competitor, foreign intelligence service or criminal organization does.</p><p>In other words, SenTeGuard watches the boundary from the inside. Moyo approaches it from the outside.</p><h3><strong>CSVF: Defining What Must Remain Unreachable<br></strong></h3><p>A company cannot govern similarity leakage if it has not defined what counts as failure. CSVF provides the framework for doing so.</p><p>The framework asks organizations to inventory their information domains, specify which joins among those domains are permitted and define Unreachable Statement Classes: categories of conclusions an AI system must not be able to produce reliably. It then provides draft metrics for testing those claims, including Leakage Event Rate, Domain Inference Risk and Crawl-Resilience Score.</p><p>This transforms a vague promise&#8212;<em>&#8220;our AI does not leak sensitive information&#8221;</em>&#8212;into a testable claim. Which meanings are protected? Which sources could be combined to reach them? How often does the system cross the boundary? Does the boundary continue to hold after the model, prompt, retrieval configuration or toolset changes?</p><p>CSVF supplies the map and measurement system. SenTeGuard and Moyoguard provide mechanisms for enforcing and testing the resulting boundaries.</p><h2>Examples<br></h2><ol><li><p>Microsoft&#8217;s &#8220;New Bing&#8221; Revealed Its Hidden System Prompt</p></li></ol><p>When Microsoft launched the first version of Bing Chat in 2023, users quickly discovered that carefully crafted prompts could persuade the model to reveal portions of its hidden system prompt, internally codenamed Sydney. Attackers did not have access to Microsoft&#8217;s source code or internal documentation. Instead, they asked the model questions about its own behavior until it reconstructed and revealed instructions that were intended to remain private.</p><p>Although the output was not necessarily a byte-for-byte copy of Microsoft&#8217;s internal configuration, it was close enough to reveal confidential implementation details. From a security perspective, this illustrates that protecting a prompt file is insufficient if an attacker can reconstruct its contents through interaction with the model itself.</p><ol start="2"><li><p>Samsung Engineers Accidentally Exposed Proprietary Source Code</p></li></ol><p>In 2023, Samsung temporarily restricted employee use of ChatGPT after engineers pasted proprietary semiconductor source code, debugging information and meeting notes into the service while seeking programming assistance.</p><p>The concern was not merely that OpenAI received copies of the text. Once proprietary information enters an external LLM, future prompts may be capable of eliciting summaries, explanations or functionally equivalent descriptions of that information. Even if the original code is never reproduced verbatim, a sufficiently similar explanation may provide competitors with valuable intellectual property.</p><p>This is a classic example of why organizations must protect semantic content rather than merely preventing file exfiltration.</p><ol start="3"><li><p>Public OSINT Reveals Classified Programs Without Classified Documents</p></li></ol><p>Intelligence analysts routinely reconstruct sensitive military activities using only publicly available information. Satellite imagery, procurement contracts, LinkedIn profiles, patent filings, shipping manifests, conference presentations and job advertisements are individually harmless. Together, they can reveal the location of secret facilities, the capabilities of new weapons systems or the existence of classified research programs.</p><p>No classified document has leaked. Instead, the sensitive conclusion emerges from the semantic relationship between many publicly available facts. Modern LLMs dramatically accelerate this process by identifying relationships across thousands of disparate sources that would previously have required weeks of manual analysis.</p><p>This is precisely the type of cross-domain inference that CSVF is designed to identify and measure.</p><ol start="4"><li><p>AI Coding Assistants Can Infer Proprietary Architectures</p></li></ol><p>Suppose an engineer asks an internal coding assistant:</p><p>&#8220;How should I implement authentication the same way our payment service does?&#8221;</p><p>The assistant may not retrieve the underlying authentication design document. Instead, it may synthesize an answer from architecture diagrams, internal documentation, code comments, engineering discussions and previous implementations.</p><p>The resulting explanation may accurately describe proprietary architectural decisions without reproducing any single protected artifact. A competitor receiving the same explanation could implement a nearly identical system despite never seeing the original documentation.</p><p>From the standpoint of traditional DLP, nothing has leaked because no protected document was copied. From the standpoint of cognitive security, the organization&#8217;s intellectual property has effectively crossed the security boundary through similarity.</p><p>These examples illustrate why AI security must evolve beyond detecting copied strings or protected files. The relevant question is no longer &#8220;Did the model reproduce a secret?&#8221; It is &#8220;Did the model enable someone to reach substantially the same conclusion?&#8221; Once meaning&#8212;not merely text&#8212;is treated as the protected asset, leak through similarity becomes a measurable security problem rather than an abstract AI concern.</p><h2><strong>Protecting Ideas, Not Merely Files<br></strong></h2><p>The central lesson is simple. An organization can successfully protect every restricted document and still lose the idea contained within them.</p><p>LLMs lower the cost of moving between related statements. They can transform a secret into a summary, a summary into an implication and several implications into a protected conclusion. The resulting output may share none of the original wording while preserving most of its value.</p><p>Security must therefore move beyond searching for copied strings. It must identify protected meanings, understand the neighborhoods around them, test the paths by which they become reachable and enforce boundaries throughout the AI workflow.</p><p>That is the role of the SenTeGuard stack. Moyoguard discovers what is inferable. CSVF defines and measures the boundary. Joseki:WrapperHub packages the intended behavior and its evaluations. SenTeGuard enforces the boundary when people and models interact.</p><p>Network security protects the systems through which information moves. Cognitive security must protect what the information means.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Loose Lips Sink Ships - AI and Inference Risks]]></title><description><![CDATA[Original Here]]></description><link>https://www.letters.senteguard.com/p/loose-lips-sink-ships-ai-and-inference</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/loose-lips-sink-ships-ai-and-inference</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 22:38:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NWOn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NWOn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NWOn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NWOn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg" width="1280" height="1940" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1940,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:628852,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730386?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NWOn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 424w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 848w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!NWOn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1e5c494e-2976-4072-b460-eea3a834441a_1280x1940.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/loose-lips-sink-ships">Original Here</a><br><br>During World War II, Americans were warned that a careless conversation could expose troop movements, sailing schedules or other information useful to the enemy. &#8220;Loose Lips Might Sink Ships&#8221; was not merely a catchy poster. It communicated a simple operational truth: an adversary does not need access to the war plan if ordinary people provide enough pieces to reconstruct it.</p><p>That lesson is more important in the age of artificial intelligence.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Traditionally, we think of information leakage as the disclosure of a secret document, password or database. The human leakage vector is different. An employee mentions a delayed test at a conference. Another complains about a new supplier on LinkedIn. A third tells a friend that everyone in the office has been ordered to cancel vacation. None believes he has revealed anything sensitive. Individually, he may be right.</p><p>The problem is recombination.</p><p>Recombination occurs when an adversary collects seemingly unrelated pieces of information, identifies the people and organizations involved, places the events on a timeline and tests possible explanations for why they occurred. One inference becomes an input for the next. Artificial intelligence makes this process cheap, fast and scalable. Like earlier systems that imposed order on the vast and unstructured internet, AI can make millions of scattered human observations searchable and comprehensible.</p><p>Consider a hypothetical Navy example. One sailor tells his family that scheduled dental appointments were suddenly moved forward. Another mentions that the galley received an unusually large delivery. A spouse posts that a homecoming ceremony has been postponed. A contractor complains online about an urgent inspection of a particular weapons system. Finally, several sailors begin asking questions about phone service in the same part of the Pacific.</p><p>None has disclosed a deployment order. Nonetheless, an adversarial AI could combine those statements with weather forecasts, port activity, public photographs and historical deployment patterns. It might infer which ship is preparing to depart, roughly when it will sail and where it is likely going. The AI does not need to produce the precise classified order. It only needs to narrow the possibilities enough to help an adversary position a submarine, surveillance asset or collection team.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Bcpo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Bcpo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg" width="1456" height="1896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1896,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:534777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730386?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Bcpo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Bcpo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb8dd47bd-d06b-430a-9764-35105a0b645d_1920x2500.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The same problem exists in the corporate world. Imagine that a product manager casually mentions new European labeling requirements. A recruiter advertises for Korean-speaking radio-frequency engineers. A supplier celebrates a rush order for unfamiliar battery enclosures. An executive cancels an annual conference appearance, while employees begin booking travel to the same city.</p><p>Separately, these facts are boring. Recombined, they could reveal that the company is preparing a new wireless product, working with a Korean manufacturing partner and approaching a launch or acquisition announcement. A competitor could adjust its own release schedule, approach the supplier, target the relevant employees or trade on the inferred information. Again, no one employee leaked &#8220;the secret.&#8221; The workforce leaked enough components for an AI to uncover it.</p><p>This is the problem that cognitive security and the Cognitive Security Verification Framework (CSVF) are intended to address. CSVF examines inference boundaries, semantic leakage and information reachability. In other words, it asks not only whether a system disclosed a secret word-for-word, but whether the secret became reachable through paraphrases, summaries or chains of individually harmless clues.</p><p>Employees should therefore be overly safe about what they discuss outside approved channels. This does not mean that every workplace conversation must stop. It means that people should abandon the assumption that a detail is safe merely because it appears insignificant. They do not know what other fragments an adversary already possesses, what an AI can infer from them or which harmless comment will complete the picture.</p><p>During World War II, the person listening at the next table might have been an enemy agent. Today, the listener may be a machine collecting thousands of conversations at once.</p><p>Loose lips no longer have to reveal the location of the ship. They only have to provide enough clues for an AI to find it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Why We Named it "Joseki"]]></title><description><![CDATA[Original Here]]></description><link>https://www.letters.senteguard.com/p/why-we-named-it-joseki</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/why-we-named-it-joseki</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 22:33:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!rcjt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rcjt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rcjt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 424w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 848w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1272w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rcjt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png" width="1130" height="591" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:591,&quot;width&quot;:1130,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:482525,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730380?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a821e4a-9797-4cec-a5c7-d912cbd6818b_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rcjt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 424w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 848w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1272w, https://substackcdn.com/image/fetch/$s_!rcjt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73256838-7d22-4b7e-8bdf-bf0e377b71d9_1130x591.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/why-joseki">Original Here</a></p><p><br>Go is an ancient strategy game with simple rules and almost incomprehensible complexity. Over centuries of play, Go players documented recurring sequences of moves called <em>joseki</em>. A <em>joseki</em> is a studied pattern, usually played in a corner, that leaves both players with a reasonable result. One player may receive secure territory while the other gains influence toward the center.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>But a <em>joseki</em> is not automatically the correct move.</p><p>A sequence that works well in one game may be a serious mistake in another. The surrounding stones, direction of play and broader strategy all matter. Memorizing the pattern without understanding its purpose can leave a player locally satisfied but globally defeated.</p><p>This combination of reuse and judgment is what makes <em>joseki</em> a useful way to think about artificial intelligence.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FG3h!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FG3h!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 424w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 848w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1272w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FG3h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif" width="508" height="673.9878419452888" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:873,&quot;width&quot;:658,&quot;resizeWidth&quot;:508,&quot;bytes&quot;:55507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/gif&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730380?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FG3h!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 424w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 848w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1272w, https://substackcdn.com/image/fetch/$s_!FG3h!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73ca9732-e850-48dc-adf3-8e439a47caa1_658x873.gif 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"></figcaption></figure></div><h2><strong>Beyond the &#8220;Perfect Prompt&#8221;<br></strong></h2><p>Organizations often treat prompts as isolated pieces of text. A useful prompt is copied into a document, pasted into Slack, modified by another employee and eventually placed into production. The evaluation criteria may live somewhere else. The safety policy may exist only in a vendor dashboard. No one may know which version was actually used.</p><p>This becomes more serious as AI systems move beyond experimentation. It is not enough to know what instructions were given to a model. Teams must also know which version was used, which models it works with, how it was tested, what data accompanied it and who is permitted to use it.</p><p>This is the purpose of <a href="http://app.josekiwrapperhub.com/">Joseki:WrapperHub</a>.</p><p>Joseki allows organizations to package the full behavior of an AI system into a reusable, versioned unit. A Behavior Package can include the prompt, examples, adapters, evaluation suites, safety policies, installation requirements, licensing information and evidence of provenance. Instead of copying prompts between projects, teams can install, inspect, test and roll back a defined package.</p><p>The distinction is that: a prompt library stores text, Joseki stores a behavior contract: what the system is intended to do, how it was produced, how it was evaluated and under what conditions it should be trusted.</p><h2><strong>Established Patterns, Not Blind Automation<br></strong></h2><p>Like a Go <em>joseki</em>, a Behavior Package is not guaranteed to work in every context. A package may perform well on one model and fail after a provider update. It may require different safety rules in another organization or behave unpredictably in another language.</p><p>The answer is not to abandon reusable patterns but to make them visible, testable and responsive to changing conditions.</p><p>Joseki therefore helps users see whether a package still works across different models and versions. Instead of relying on a stale &#8220;last updated&#8221; date, teams can evaluate whether a behavior remains reliable in the environment where they intend to use it.</p><p>The broader challenge of rapid technical growth is often solved through new abstractions. Industrial standards made mass production manageable. Internet protocols organized digital communication. AI needs similar frameworks for packaging, evaluating and governing behavior.</p><p>A Go player studies <em>joseki</em> so that every familiar position does not have to be solved again from first principles. An AI team should not have to rebuild its prompts, evaluations, safety rules and documentation every time it changes models.</p><p>That is the idea behind Joseki: share the behavior, not just the prompt.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Next Rung on the Ladder of Abstraction]]></title><description><![CDATA[Original Post]]></description><link>https://www.letters.senteguard.com/p/the-next-rung-on-the-ladder-of-abstraction</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/the-next-rung-on-the-ladder-of-abstraction</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 20 Jul 2026 22:28:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aF6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aF6B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aF6B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aF6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg" width="1232" height="900" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:900,&quot;width&quot;:1232,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:660782,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207730080?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aF6B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aF6B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6c803d72-48c6-483c-b545-83ef096e9af4_1232x900.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/abstraction-ladder">Original Post</a></p><p>The history of software development is, in large part, the history of moving up a ladder of abstraction. At each rung, programmers have surrendered some direct control over the machine in exchange for the ability to tell it to do more.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The least abstracted form of computing available to a software programmer is machine code: numerical instructions executed directly by a processor. Even machine code is technically an abstraction over transistors, electrical signals and the physical architecture of the chip. Nonetheless, from the programmer&#8217;s perspective, it is close to the bottom. Early programmers had to think in terms of memory addresses, processor instructions and the exact movement of data through a specific machine.</p><p>Assembly language created the first major step upward. Instead of remembering numerical operation codes, programmers could use names and symbols. An assembler translated those symbols into machine instructions. Assembly was easier for humans to understand, but the relationship generally remained one-to-one: the programmer still wrote something approximating one line for every instruction executed by the computer. Higher-level languages such as Fortran introduced a more dramatic breakthrough. A compiler could translate one comparatively understandable statement into many machine instructions.</p><p>This is the basic pattern that has repeated throughout the history of software. Each new layer compresses more mechanical work into a smaller unit of human intention.</p><h2><strong>What Abstraction Actually Means<br></strong></h2><p>Abstraction is often described simply as &#8220;hiding complexity&#8221; which is partly explanatory. Abstraction is the process of taking a complicated system and exposing only the parts necessary to use it for a particular purpose.</p><p>A driver does not need to understand combustion chemistry in order to press the accelerator. A person using a microwave does not need to understand the behavior of electromagnetic radiation in order to heat a burrito. Similarly, a programmer calling a function named sort() does not need to manually instruct the processor to compare pairs of values and move data between memory locations until the list is ordered.</p><p>An abstraction is therefore something like a contract. The programmer provides an instruction at the higher layer, and the lower layers agree to carry it out. Provided the contract holds, the programmer can stop thinking about the implementation and begin thinking about the objective.</p><p>Good abstractions increase what might be called semantic density: the amount of intention contained in a single instruction. A machine-code instruction may move one value from one location to another. A Python function might download a file, process its contents and place the results in a database. The programmer using Python is not necessarily smarter than the machine-code programmer. The programmer has simply inherited several generations of accumulated work.</p><h2><strong>From Machine Instructions to Human Intentions<br></strong></h2><p>The ascent from machine code to assembly language allowed programmers to think in symbols rather than numbers. The ascent from assembly to compiled languages allowed them to think in mathematical operations, data structures and logical procedures rather than individual processor instructions. Operating systems then abstracted away much of the difficulty of interacting with memory, storage, displays and networks. Libraries allowed programmers to reuse solutions created by others. Frameworks allowed them to assemble entire applications around preexisting structures.</p><p>Python seemed, for a time, like something close to the final boss of abstraction. Its syntax was comparatively clean, its high-level data structures were powerful and its design made rapid application development far easier than it had been in lower-level languages. Someone looking at a simple Python program might say that it resembled ordinary written instructions.</p><p>But Python was never normal language.</p><p>A Python program may be readable, but it remains a formal statement addressed to a machine. A computer does not infer that the programmer &#8220;basically meant&#8221; something else. The programmer must translate his objective into the exact language the system is prepared to accept.</p><p>Large language models introduce a new layer. We are no longer merely using a programming language that vaguely resembles normal language. We are beginning to use normal language itself to build software.</p><p>A person can now say: &#8220;Add a page that allows users to upload a spreadsheet, identify duplicate entries and download a cleaned version. Preserve the existing visual style and add tests.&#8221; A coding agent can inspect the existing project, locate the relevant files, form a plan, write the code, run the tests, observe the failures and revise its work.</p><p>The instruction does not specify which files to modify, which libraries to import or how the data should move through memory. It specifies an outcome.</p><p>Natural language has therefore become a supervisory layer above source code. The LLM translates an ambiguous statement of intent into a more formal plan, which is translated into source code, which is translated into lower-level instructions, which are ultimately executed by hardware.</p><h2><strong>Abstraction and Agency<br></strong></h2><p>Each level of abstraction has increased the agency of the person operating at that level.</p><p>Agency, in this context, is the amount of meaningful change a person can produce through a given amount of effort. A machine-code programmer could exercise extraordinary control over a computer, but relatively little control over the wider world. He might spend a day producing behavior that a modern programmer can request through a single library call.</p><p>The economic value created at the lower levels remains immense. We still need electrical engineers, chip designers, compiler engineers, operating-system developers and assembly-language specialists. In some contexts&#8212;embedded systems, operating systems, high-performance computing and security&#8212;their work is irreplaceable.</p><p>But most opportunities for economic value appear at the layers with the greatest agency. Businesses generally do not make money because they moved a value efficiently between two processor registers. They make money because they solved a customer&#8217;s problem, reduced a cost, created a useful service or coordinated people more effectively.</p><p>Higher abstraction allows the programmer to spend less attention on how the computer works and more attention on what the computer should do.</p><p>LLM coding agents expand this agency again. A capable software engineer can supervise several streams of work rather than manually producing every line. A domain expert with limited programming experience can create prototypes that previously required a technical team. A small company can attempt projects that would once have been uneconomical. The scarce resource begins to shift away from the mechanical production of code and toward the selection and definition of worthwhile objectives.</p><p>This changes which expertise matters at the margin. Syntax becomes somewhat less valuable. Judgment, system design, domain knowledge, verification and the ability to describe a problem precisely become more valuable.</p><h2><strong>LLMs as a Normal Technology<br></strong></h2><p>Seen through this history, LLM coding looks less like the arrival of an alien intelligence and more like the continuation of a familiar technological process.</p><p>The term &#8220;normal technology&#8221; is used to distinguish from both utopian and apocalyptic conceptions of AI. &#8220;Normal&#8221; does not mean unimportant. Electricity and the internet are normal technologies in this sense, despite transforming nearly every part of modern life. It means that AI remains a tool whose effects depend on applications, institutions, adoption, complementary investments and human decisions. Improvements in an underlying model do not instantly reorganize the economy. They must first be incorporated into useful products and then diffused through actual organizations.</p><p>Coding agents fit this framework exceptionally well. They do not float above society as an independent intelligence. </p><h2><strong>What Comes After Natural Language?</strong></h2><p>This brings us to another question: how can our understanding of past abstractions help us to understand what the next level of abstraction look like?</p><p>The next rung may move from software specification to outcome specification.</p><p>Today, a person might tell an agent to build a claims-processing application. A future system might instead receive the instruction: &#8220;Reduce the average time required to process an insurance claim by 30 percent without increasing fraud, violating privacy rules or exceeding this budget.&#8221;</p><p>The system might interview employees, inspect existing workflows, propose several alternatives, build the necessary applications, connect them to existing databases, run a limited pilot, measure the results and revise the process. Software would become less of a fixed product and more of a continuously changing instrument through which an organization pursues its goals.</p><p>This would create extraordinary agency, but also extraordinary opportunities to make mistakes. A poorly written line of machine code might crash one program. A poorly specified institutional objective could redirect thousands of automated decisions. At every new level of abstraction, the unit of instruction becomes more powerful. The consequences of ambiguity increase with it.</p><p>The future programmer may therefore look less like a person writing code and more like a combination of architect, product manager, auditor and constitutional lawyer. The task will be to determine what the system should optimize, what it must never do and who remains accountable when the abstraction fails.</p><p>The lower layers will not disappear. They never have. More software will likely produce greater demand for the comparatively small number of people capable of repairing compilers, securing operating systems, designing chips and understanding what is actually happening underneath the interface.</p><p>But most people will work higher up.</p><p>The history of software is the history of expanding the distance between what a human must say and what a machine can do. LLM coding agents are not the end of programming. They are the next rung on the ladder. And, as in every previous generation, the most important question will not be whether the new abstraction can produce more code. It will be what human beings choose to do with the additional agency it gives them.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Amodei's Coup]]></title><description><![CDATA[Most of today's AI-powered military tools are designed with moral and legal guardrails&#8212;until private companies embed personal objections that can silently veto critical actions.]]></description><link>https://www.letters.senteguard.com/p/amodeis-coup-823</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/amodeis-coup-823</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Sun, 19 Jul 2026 15:57:08 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840190/10f02a6f5afbecbe22708a8355d43b4f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qgI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qgI4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 424w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 848w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1272w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qgI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp" width="1456" height="1456" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:779583,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/207840190?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qgI4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 424w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 848w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1272w, https://substackcdn.com/image/fetch/$s_!qgI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9662f7ab-666a-46d2-80aa-a864c4b7c567_2100x2100.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most of today's AI-powered military tools are designed with moral and legal guardrails&#8212;until private companies embed personal objections that can silently veto critical actions. Imagine a missile defense system refusing to engage because the AI&#8217;s ethical framework flags a potential legal issue. Or a crowd surveillance drone halted because a private firm&#8217;s moral stance restricts mass data collection. These scenarios reveal a dangerous shift: private AI firms gaining unseen power over life-and-death decisions, replacing democratic oversight with corporate moral judgments. In this eye-opening episode, we dissect how the legal ambiguities and technical opacity of AI systems threaten civilian authority and global security. You&#8217;ll discover how vague definitions like "mass surveillance" and "autonomous weapons" conceal profound risks&#8212;who really controls these weapons, and who is ultimately accountable? We break down the troubling practice of private companies maintaining veto power over lawful military actions and embed moral decisions directly into autonomous systems. This isn't just theory&#8212;it's happening now, with serious implications for democracies and allies worldwide. You'll hear how AI developers' &#8220;ethical safeguards&#8221; can become Trojan horses, quietly reshaping authority at machine speed. We explore the threats of hidden code prompts, undisclosed priorities, and the erosion of civilian oversight&#8212;raising urgent questions: Who writes the rules in the future battlefield? Who keeps governments accountable when AI systems interpret laws and morality on their own? As AI advances, the line between corporate discretion and democratic command blurs, risking usurpation of legal authority and accountability.Why should you care? Because the integrity of global security, the rule of law, and democratic sovereignty hang in the balance. Those who understand these risks are better equipped to demand transparency and oversight in AI military applications&#8212;before the hidden veto becomes the new normal. Perfect for policymakers, military leaders, AI enthusiasts, and anyone concerned with the future of democracy in the AI age, this episode offers a vital wake-up call on the unseen power of private AI firms shaping our security landscape</p>]]></content:encoded></item><item><title><![CDATA[What is Idea Leakage?]]></title><description><![CDATA[The rapid rise of large language models (LLMs) like ChatGPT and Copilot is transforming industries&#8212;accelerating research, streamlining workflows, and boosting productivity.]]></description><link>https://www.letters.senteguard.com/p/what-is-idea-leakage-033</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/what-is-idea-leakage-033</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 15 Jul 2026 18:50:55 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840191/65c0f43d56b8507b54e60440c9b4af60.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>The rapid rise of large language models (LLMs) like ChatGPT and Copilot is transforming industries&#8212;accelerating research, streamlining workflows, and boosting productivity. But as organizations race to adopt these powerful tools, a hidden threat emerges: idea leakage. Even without overt data breaches, your strategic logic, internal decision-making, and client relationships can become predictable&#8212;leaked not through files, but through the very reasoning that powers your success.Imagine a mid-sized company using an LLM to plan next year's strategy. They input sensitive data&#8212;profitability thresholds, reasons for customer churn, lessons learned from failed pilots. At first glance, nothing seems off. But secretly, these fragments encode the core of their competitive advantage. Over time, a competitor noticing similar structures and conclusions can reverse-engineer their approach&#8212;not by stealing documents, but by understanding the underlying logic that drives their decisions. This subtle erosion of intellectual edge is the new frontier of corporate risk in the AI <a href="http://age.In">age.In</a> this episode, we break down the emerging challenge of idea leakage and how ambient LLMs expand the surface for unintentional exposure. You'll discover:</p><ul><li><p>How seemingly innocuous inputs can reveal your organization's strategic "scaffolding"</p></li><li><p>Real-world examples of how confidential plans can become predictable without any hacks or data theft</p></li><li><p>The limitations of traditional security methods when LLMs operate inside everyday tools like email and chat</p></li><li><p>Why protecting ideas&#8212;and the logic behind your decisions&#8212;is critical for maintaining competitive advantage</p></li><li><p>How novel solutions like SenTeGuard help organizations prevent the inference of their confidential reasoning without sacrificing productivity</p></li></ul><p>This isn&#8217;t just about avoiding data leaks&#8212;it's about safeguarding your organization&#8217;s very thought processes. As AI becomes embedded into daily workflows, understanding the risk of idea leakage is essential for leaders who want to stay ahead without exposing what makes them unique. Perfect for strategists, security professionals, and anyone leveraging AI-driven tools today: Learn how to think about AI security differently&#8212;protect not just your files, but the secrets hidden in your reasoning.</p><h6><strong>Why this works:</strong></h6><p>This description pinpoints a subtle, yet critical risk in AI adoption that many overlook, creating intrigue around &#8220;idea leakage.&#8221; It&#8217;s tailored for decision-makers eager to sustain competitive advantage while embracing AI, offering concrete insights and practical solutions that make the episode immediately valuable.</p>]]></content:encoded></item><item><title><![CDATA[Ambient AIs]]></title><description><![CDATA[Most companies are blindsided by the hidden risks of ambient AI &#8212; the pervasive, background presence of large language models (LLMs) in everyday work tools.]]></description><link>https://www.letters.senteguard.com/p/ambient-ais-4af</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/ambient-ais-4af</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Mon, 13 Jul 2026 14:05:45 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840192/b41b5dd964ef74042ddf67d74346cda2.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Most companies are blindsided by the hidden risks of ambient AI &#8212; the pervasive, background presence of large language models (LLMs) in everyday work tools. If you're relying on AI for productivity but haven't updated your security mindset, you're vulnerable to idea leaks, data breaches, and strategic leaks that happen without you realizing it. This episode reveals why the future of AI security isn't about patchwork policies but about embedding safeguards directly into your workflows, before sensitive information even leaves the user&#8217;s <a href="http://device.As">device.As</a> AI becomes embedded into everything &#8212; from email drafts and meeting summaries to code debugging and browser assistance &#8212; the boundaries between approved tools and risky leaks blur. You&#8217;ll discover how major tech giants like Microsoft, Google, and Apple are integrating LLMs into their ecosystems, and why this widespread adoption creates new security vulnerabilities that traditional policies can't address. We break down the concept of "leakage cascades," where a single security slip can ripple through an organization&#8217;s entire knowledge base, and reveal the hidden costs of relying solely on user judgment and vague <a href="http://warnings.You">warnings.You</a>&#8217;ll learn about the threat of &#8220;idea leakage,&#8221; where proprietary insights, strategic concepts, or even intellectual property can quietly escape through routine AI interactions &#8212; even when no confidential data is explicitly pasted. We explore the emerging paradigm shift: security needs to be proactive and placed at the point of interaction, with real-time control tools that detect and block sensitive content before it leaves the device. This episode dives into practical strategies for organizations to implement ambient security measures, vendor scrutiny, and employee education&#8212;arming you with the foresight to navigate the AI-powered workplace securely.If your organization depends on AI tools, ignoring these risks isn't an option &#8212; the cost of a leak is too high, and the opportunity to protect it starts now. Perfect for security professionals, tech leaders, or anyone using AI in daily workflows, this episode transforms your understanding of modern AI risks from reactive to proactive, ensuring you stay one step ahead in the ambient AI era.</p>]]></content:encoded></item><item><title><![CDATA[PageRank For Inference]]></title><description><![CDATA[Essay - https://www.letters.senteguard.com/p/pagerank-for-inference-mapping-reachability Visualizing and Managing Complexity in the LLM Era with SenTeGuard]]></description><link>https://www.letters.senteguard.com/p/pagerank-for-inference-96a</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/pagerank-for-inference-96a</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Fri, 10 Jul 2026 21:14:27 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840193/d805003586905e4d473aa28c6d45a15c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h5>Essay - <a href="https://www.letters.senteguard.com/p/pagerank-for-inference-mapping-reachability">https://www.letters.senteguard.com/p/pagerank-for-inference-mapping-reachability</a> Visualizing and Managing Complexity in the LLM Era with SenTeGuard</h5><p>In this episode, we explore how the same principles that transformed the web and cloud infrastructure are now shaping AI and large language models (LLMs). With insights from David Weidman of SenTeGuard, discover how organizations can gain visibility and control over AI inference risks.</p><h6><strong>Key Topics:</strong></h6><ul><li><p>The evolution of mapping complexity: from Google Link Graph to AWS infrastructure</p></li><li><p>The emerging risk surface of LLM inference and reachability</p></li><li><p>How SenTeGuard&#8217;s three-layer platform (Moyo, SentaGuard, Joseki Wrapper Hub) makes LLM environments understandable and governable</p></li><li><p>Why visibility into what can be inferred from scattered data is crucial for AI safety</p></li><li><p>The importance of structural reachability maps and enforceable boundaries in high-stakes AI deployment</p></li><li><p>Practical examples: How Moyo shows inference risks when combining data sources</p></li><li><p>The role of SentaGuard in real-time policy enforcement at the point of AI use</p></li><li><p>Centralizing control via Joseki Wrapper Hub to standardize and operationalize AI workflows</p></li><li><p>Why AI infrastructure needs the same confidence and governance as cloud infrastructure</p></li></ul><h6><strong>Timestamps:</strong></h6><p>00:00 - The evolution of complexity visualization from Google to AWS<br>00:22 - The challenge of inference and reachability in LLMs<br>01:13 - How LLMs connect scattered data and surface new inferences<br>01:55 - The concept of "reachability" as a new risk surface<br>02:36 - Why traditional security models break down with LLMs<br>03:06 - An overview of SenTeGuard&#8217;s three-layer platform<br>03:22 - Moyo: Mapping inference exposure across data sources<br>04:08 - SentaGuard: Enforcing policies at the point of use<br>04:45 - Joseki Wrapper Hub: Orchestrating complex LLM workflows<br>05:39 - The future of AI infrastructure with confidence and control</p><h6><strong>Resources &amp; Links:</strong></h6><ul><li><p><a href="https://senteguard.com/">SenTeGuard</a> &#8212; Official website</p></li><li><p><a href="https://en.wikipedia.org/wiki/PageRank">PageRank</a> &#8212; Google&#8217;s link analysis algorithm</p></li><li><p><a href="https://aws.amazon.com/">AWS</a> &#8212; Amazon Web Services official site</p></li></ul><h6><strong>Connect with David Weidman:</strong></h6><ul><li><p><a href="https://linkedin.com/in/davidweidman">LinkedIn</a></p></li><li><p><a href="https://twitter.com/davidweidman">Twitter</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[There's Always Another Apocalypse]]></title><description><![CDATA[Essay - https://www.letters.senteguard.com/p/there-is-always-another-apocalypse]]></description><link>https://www.letters.senteguard.com/p/theres-always-another-apocalypse-b76</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/theres-always-another-apocalypse-b76</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Thu, 09 Jul 2026 23:02:55 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840194/947b34d7ce022295899434143916ad0c.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Essay - <a href="https://www.letters.senteguard.com/p/there-is-always-another-apocalypse">https://www.letters.senteguard.com/p/there-is-always-another-apocalypse</a><br><br>In this episode, we explore how fears around artificial intelligence are often amplified to justify centralized control, benefiting powerful interests. We examine historical parallels and the importance of open-source AI for maintaining competition and innovation.Key Topics:</p><ul><li><p>The recurring pattern of "apocalypses" in history and their influence on policy</p></li><li><p>Bruce Yandel's Bootleggers and Baptists theory applied to AI regulation</p></li><li><p>How genuine threats are weaponized for political and economic gains</p></li><li><p>The role of open-source models in fostering a diverse and competitive AI ecosystem</p></li><li><p>The risks of sweeping licensing regimes and their impact on smaller innovators</p></li><li><p>The parallels between AI regulation and post-9/11 security measures</p></li><li><p>Cultural roots of doom-mongering and the importance of humility in facing uncertainty</p></li><li><p>The danger of regulation that favors incumbents and stifles innovation</p></li><li><p>The significance of open models for decentralization and pluralism in AI</p></li></ul><p>Timestamps: 00:00 - The recurring cycle of apocalyptic fears across eras<br>00:26 - How powerful interests promote regulation for self-benefit<br>01:14 - Yandel&#8217;s Bootleggers and Baptists theory explained in current AI debates<br>01:54 - Practical uses of open-source AI models and their importance<br>02:29 - The threat of overreach: sweeping regulations and centralization<br>02:48 - Historical parallels: post-9/11 security and climate control measures<br>03:22 - Cultural context: the decline of religious frameworks and embracing humility<br>04:06 - The rhetoric around control versus prudent regulation<br>04:38 - The strategic importance of open-source AI against monopolistic forces<br>05:16 - Recognizing symbolic warnings and resisting fear-mongering for political gains<br>05:36 - The responsibility to protect liberty from prophets of doomResources &amp; Links:</p><ul><li><p><a href="https://en.wikipedia.org/wiki/Baptists_and_bootleggers">Bruce Yandel's Bootleggers and Baptists Theory</a></p></li><li><p><a href="https://huggingface.co/">Hugging Face - Open-source AI models</a></p></li><li><p><a href="https://cdt.org/">Understanding AI Regulation, Center for Democracy &amp; Technology</a></p></li></ul><p>Connect with David Weidman:</p><ul><li><p><a href="https://twitter.com/davidweidman">Twitter</a></p></li><li><p><a href="https://linkedin.com/in/davidweidman">LinkedIn</a></p></li></ul>]]></content:encoded></item><item><title><![CDATA[What is SenTe?]]></title><description><![CDATA[https://www.letters.senteguard.com/p/what-is-sente]]></description><link>https://www.letters.senteguard.com/p/what-is-sente-dc1</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/what-is-sente-dc1</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 08 Jul 2026 21:00:53 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840195/8b2b34fe4f3d96722636ea4f069a3523.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><a href="https://www.letters.senteguard.com/p/what-is-sente">https://www.letters.senteguard.com/p/what-is-sente</a><br><br>In Go, or Baduk, <em>sente</em> means having the initiative: making moves that set the tempo and force your opponent to respond. Its opposite is <em>gote</em>, where you react from behind.</p><p>This episode uses the story of Lee Sedol, AlphaGo, and the legendary Move 37 to explore what AI teaches us about strategy, creativity, and cybersecurity. AlphaGo showed that machines can produce moves humans do not predict until the consequences unfold. In cybersecurity, that kind of surprise can be dangerous.</p><p>As AI changes how attackers operate and how organizations use sensitive information, defenders cannot afford to stay reactive. The challenge is to move from gote to sente: from patching after incidents to spotting risk earlier, prioritizing better, and building security into the workflows people already use.</p>]]></content:encoded></item><item><title><![CDATA[Nailing Jell-O to the Wall - Can China Contain LLMs]]></title><description><![CDATA[Essay - https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again]]></description><link>https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-can-china-fa9</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-can-china-fa9</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Thu, 02 Jul 2026 21:56:04 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/207840196/bc50964d3e5b48af47da4d8ccb35bd2e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Essay - <a href="https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again">https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again</a><br><br>Summary<br>This conversation explores the complex relationship between the Chinese Communist Party and the rise of large language models (LLMs). It discusses how the internet has been absorbed into state control, the economic implications of LLMs for China's political legitimacy, and the challenges posed by these technologies to traditional censorship and control mechanisms. The discussion also delves into potential responses from Beijing, including the development of national champion models and the implications of open models in a constrained environment.<br><br>Takeaways<br>In 2000, Clinton joked about China's internet control.<br>The internet has become a tool of state control in China.<br>Large language models (LLMs) synthesize information and enhance productivity.<br>Beijing faces a dilemma between growth and maintaining authority.<br>China's political legitimacy relies on economic performance.<br>Heavy regulation of LLMs may hinder productivity growth.<br>Jailbreaking LLMs poses challenges to state control.<br>Open models can be harder to control than centralized systems.<br>An arms race between police AIs and outlaw AIs is possible.<br>Beijing's responses to AI challenges may impact innovation.</p>]]></content:encoded></item><item><title><![CDATA[OracleGPT: Thought Experiment on an AI-Powered Executive]]></title><description><![CDATA[In this conversation, David Weidman discusses the concept of Oracle GPT, a hypothetical AI model designed to assist the President of the United States in national security decision-making.]]></description><link>https://www.letters.senteguard.com/p/oraclegpt-thought-experiment-on-an-034</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/oraclegpt-thought-experiment-on-an-034</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 24 Jun 2026 22:51:10 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203571663/2c46904a4f6593146d4cf617e6d27aef.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this conversation, David Weidman discusses the concept of Oracle GPT, a hypothetical AI model designed to assist the President of the United States in national security decision-making. He explores the implications of such a system, including the potential for increased efficiency and coherence in crisis situations, while also addressing the significant risks and ethical challenges it poses. The conversation delves into the balance of power between the presidency and other branches of government, the dangers of misinformation, and the need for accountability in the use of advanced AI technologies.</p><p>Takeaways</p><p>Oracle GPT is a thought experiment on AI in national security.</p><p>The President could have unprecedented access to intelligence.</p><p>There are significant risks associated with AI in decision-making.</p><p>The balance of power may shift towards the presidency.</p><p>Presidential competence is crucial for using Oracle GPT effectively.</p><p>Misinformation could be a major risk with such a system.</p><p>Ethical implications must be considered in AI recommendations.</p><p>Human judgment should not be treated as an obstacle by AI.</p><p>The design of Oracle GPT must ensure accountability.</p><p>The constitutional order must be preserved in AI usage.</p><p>titles</p>]]></content:encoded></item><item><title><![CDATA[Big Frontier, China and Regulatory Capture]]></title><description><![CDATA[This episode explores the complex dynamics of open versus closed AI models, the geopolitical implications, and the importance of fostering open competition for innovation and security.]]></description><link>https://www.letters.senteguard.com/p/big-frontier-china-and-regulatory-9eb</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/big-frontier-china-and-regulatory-9eb</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 24 Jun 2026 21:57:20 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203571664/5d1d234348e9033dbd879a7abafa2543.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>This episode explores the complex dynamics of open versus closed AI models, the geopolitical implications, and the importance of fostering open competition for innovation and security.</p><p><strong>keywords</strong>AI models, open source, closed source, geopolitics, innovation, regulation, AI safety, public investment, model distillation, AI race</p><p><strong>key topics</strong></p><ul><li><p>Open vs closed AI models and their implications</p></li><li><p>Geopolitical framing of AI development</p></li><li><p>Regulatory capture and industry incentives</p></li><li><p>AI safety and dual-use concerns</p></li><li><p>Knowledge diffusion and model distillation</p></li><li><p>Public investment in AI and race to AGI</p></li><li><p>Enforcement challenges for open models</p></li><li><p>The future of AI innovation and competition</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Cyborg Scholars]]></title><description><![CDATA[As large language models reshape how knowledge is created and shared, academia faces fundamental questions about authorship, accountability, and the future of scholarly communication.]]></description><link>https://www.letters.senteguard.com/p/cyborg-scholars-c34</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/cyborg-scholars-c34</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 24 Jun 2026 17:41:44 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/203571665/0f69e100542b6fc54424f36f2a6e5b6e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>As large language models reshape how knowledge is created and shared, academia faces fundamental questions about authorship, accountability, and the future of scholarly communication. This episode explores how AI tools challenge traditional norms and open new opportunities for democratizing knowledge.</p><h6><strong>Key topics:</strong></h6><ul><li><p>The evolving concept of authorship in academia and software development</p></li><li><p>How LLMs accelerate knowledge production and collaboration</p></li><li><p>Cultural norms around attribution, attribution, and hierarchy reforms</p></li><li><p>The analogy of cyborg chess to future scholarship</p></li><li><p>Language barriers and the role of LLMs as a new lingua franca</p></li><li><p>Ethical considerations: transparency, accountability, and fraud prevention</p></li><li><p>The aesthetic versus pragmatic uses of language in scholarship</p></li><li><p>Updating authorship norms for an AI-augmented future</p></li></ul>]]></content:encoded></item><item><title><![CDATA[June 2026 SenTeGuard Update / Article Roll-Up]]></title><description><![CDATA[Friends and Readers,]]></description><link>https://www.letters.senteguard.com/p/june-2026-senteguard-update-article</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/june-2026-senteguard-update-article</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 10 Jun 2026 20:39:49 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d9810905-50b7-4234-8a85-d3aa9bf89e2a_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Friends and Readers,</p><p><br>Late last month I graduated from the Harvard Kennedy School with a Master in Public Policy. Beginning July I will be based in Austin, TX. Thank you to everyone who has helped me along the way. I am deeply grateful for all of the support.</p><p>Thank you, too, to those who have signed up since my last update. Please share if you know of anyone who would be interested.</p><p><strong>On Request:</strong></p><ul><li><p>Prototype testing of the<a href="https://senteguard.com/blog/sensitive-information-reachability-the-problem-and-the-solution-1768745959993"> Moyo</a> information space mapper. Find leaks of your secrets (classified, proprietary, personal) in public LLMs (ChatGPT, Claude, Qwen, Grok, etc).</p></li><li><p><a href="https://senteguard.com/blog/the-emerging-threat-of-idea-leakage">SenTeGuard Pilot</a> - protect yourself or your organization from leakage of valuable information through air-gap capable semantic guardrails. <a href="https://www.letters.senteguard.com/p/the-emerging-threat-of-idea-leakage">Substack</a></p></li><li><p>Let&#8217;s Talk:</p><ul><li><p>Private - How can your organization more effectively secure your secrets in the LLM era through implementation of the Cognitive Security Verification Framework (<a href="https://senteguard.com/blog/csvf-concept">CSVF</a>) and by other means.</p></li><li><p>Public - How to craft tech-positive, pro-future, big-tech skeptical market-oriented policies of abundance in the LLM era.</p></li></ul></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>Writing Roll-Up<br></strong></h2><p><strong>Broad Policy Articles:</strong></p><ol><li><p><a href="https://senteguard.com/blog/ai-and-powerlessness">AI and Powerlessness</a>. The popular framing around AI safety contains several important gaps. In this essay, I explore a number of high-level technical considerations that complicate assumptions about control, with the goal of moderating both the tendency toward catastrophism and the presumption that AI systems can be straightforwardly governed through centralized oversight. <a href="https://www.letters.senteguard.com/p/ai-and-powerlessness">Substack</a></p></li><li><p><a href="https://senteguard.com/blog/there-is-always-another-apocalypse">There is Always Another Apocalypse.</a> Every era has its own existential dread, and while AI risks are real, treating every new technology as the end of the world can distort judgment around policy. <a href="https://www.letters.senteguard.com/p/there-is-always-another-apocalypse">Substack</a></p></li><li><p><a href="https://senteguard.com/blog/amodei-coup">Amodei&#8217;s Coup</a>. Anthropic&#8217;s policy posture reveals how private AI companies can quietly claim political authority by deciding what governments and institutions should or should not be allowed to do with frontier models. <a href="https://www.letters.senteguard.com/p/amodeis-coup">Substack</a></p></li></ol><p><strong>SenTe Focused Articles:</strong></p><ol><li><p><a href="https://senteguard.com/blog/meet-joseki">Meet Joseki:WrapperHub</a>. WrapperHub introduces a marketplace for reusable AI &#8220;wrappers&#8221; that package prompts, workflows, evaluations, and guardrails into shareable tools for safer and more structured AI use. <a href="https://www.letters.senteguard.com/p/meet-joseki-wrapperhub">Substack</a>. <a href="https://josekiwrapperhub.com/">Site</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zkJl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zkJl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 424w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 848w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1272w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zkJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png" width="1254" height="401" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:401,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:341426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/201507925?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zkJl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 424w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 848w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1272w, https://substackcdn.com/image/fetch/$s_!zkJl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1f3b53d-8091-4a38-82a0-c3154de9b385_1254x401.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></li><li><p><a href="https://senteguard.com/blog/csvf-concept">The Cognitive Security Verification Framework.</a> The framework argues that LLM-era data security must move beyond detecting protected strings and toward measuring what protected conclusions a model can help users infer. I will be speaking on this topic at BSides San Antonio on June 3th. <a href="https://www.letters.senteguard.com/p/the-cognitive-security-verification">Substack</a></p><p></p><p>David</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.letters.senteguard.com/subscribe?"><span>Subscribe now</span></a></p><p></p><p><br><br></p></li></ol>]]></content:encoded></item><item><title><![CDATA[There Is Always Another Apocalypse]]></title><description><![CDATA[Original]]></description><link>https://www.letters.senteguard.com/p/there-is-always-another-apocalypse</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/there-is-always-another-apocalypse</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 10 Jun 2026 20:03:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!xCku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xCku!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xCku!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xCku!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xCku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg" width="1456" height="1082" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1082,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:739638,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/201504860?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xCku!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 424w, https://substackcdn.com/image/fetch/$s_!xCku!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 848w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!xCku!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F52437438-a004-4d49-b6fa-7616f2b7d55e_1680x1249.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/there-is-always-another-apocalypse">Original</a></p><p>Tales of apocalypse has always been useful. From Cold War strategists to the War on Terror, every age finds its own end of the world and every age concludes that extraordinary threats demand the suspension of ordinary limits on power. Artificial intelligence is simply the newest entry in this genre. We are told the technology is so uniquely dangerous that free speech, privacy, competition, open research, and democratic accountability must all be sacrificed for our survival. Not coincidentally, the beneficiaries of sacrifice happen to be the wealthiest people and companies in human history.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Regulatory Capture in Disguise<br></h2><p>Bruce Yandle&#8217;s &#8220;Bootleggers and Baptists&#8221; theory explains how durable regulation often emerges when two very different coalitions support the same restriction for different reasons: the &#8220;Baptists&#8221; provide the moral language and public legitimacy, while the &#8220;Bootleggers&#8221; quietly profit from the restriction itself. Current AI regulatory proposals provide the perfect modern parallel. The Baptists warn of doom and insist that they are only trying to save humanity, while the Bootleggers provide the money, the lobbyists, the institutional access, and the quiet understanding that the rules being proposed will just happen to entrench the incumbents. In other words, someone with pure motives may inadvertently and indirectly promote the interests of the self-interested.</p><p>Big Frontier firms and their advocates know that a small startup working in a garage will not survive a vast compliance regime. A university researcher will not be able to compete with a trillion-dollar firm blessed by federal regulators. Open source developers sharing models on Hugging Face will be told that their work is too dangerous for public release, despite the fact that much of this ecosystem is not composed of godlike machines plotting the end of mankind but rather practical tools that researchers, companies, and hobbyists adapt for narrow and often mundane purposes. Hugging Face reported that in 2025 its ecosystem had grown to 13 million users, more than 2 million public models, and more than 500,000 public datasets, while one 2026 analysis found that in 2024 Hugging Face recorded an average of 2,199 new models created per day.</p><p>&#8220;AI regulation&#8221; sounds abstract until one considers what these open models actually do. Embedding models, for example, convert text into numerical representations that can be used for search, retrieval, classification, and semantic similarity, which means they help people find documents, organize information, and build better internal knowledge systems. A sweeping licensing regime would not simply restrain frontier labs. It would also burden the open, competitive, and decentralized ecosystem that allows smaller actors to build useful systems without asking permission from a handful of corporations and regulators.</p><h2>Continuation of a Trend <br></h2><p>The easiest way to centralize authority is to tell people that the normal rules are inadequate to confront the emergency. After September 11, Americans were told that liberty had to be balanced against security in ways that would have been unthinkable a decade earlier. During the nuclear age, international coercive inspection regimes were devised and regime change wars were carried out to prevent proliferation. During climate debates, the proposed solution is often not merely stewardship or innovation, but control of the world economy.</p><p>In each case, there is a real problem, but rather than addressing it through less invasive means, the powerful formulate and implement solutions meant to further their own interests. Concerns over terrorism, nuclear war, environmental degradation, and the negative side effects of AI are all valid. But it would be a mistake to take a real danger, elevate it into an existential emergency, and then use that emergency to justify extreme solutions crafted by self-interested parties.</p><h2>A New Trend?<br></h2><p>The decline of religious life in the West has left many without a framework for mortality, uncertainty, and suffering. Where religion once taught people to think in those terms, secular politics now offers thinner substitutes. At their best, believers understand that catastrophe is not an aberration but part of the human condition. Every life ends in an apocalypse of its own, and every civilization is temporary. The proper response to this knowledge is not panic, but humility. A society that loses this grounding becomes easy prey for prophets of doom because people who cannot sit with uncertainty will surrender freedom to anyone who promises safety.</p><p>The loudest voices do not simply argue for prudence. Prudence would mean better cybersecurity, clearer liability rules, and a sober understanding of how this technology will affect society. Instead, many argue for control. They want licensing, censorship, centralization, and a priesthood of approved experts, along with preferential rules for the politically well connected. We should be particularly suspicious of any regulation that acts as a de facto moratorium on open-source AI, as open-source language models pose perhaps the greatest threat to the <a href="https://www.letters.senteguard.com/p/american-closed-source-vs-chinese">profitability</a> and dominance of the Big Frontier firms. While every age has had its prophets and warnings of final judgment, we should be wary that in an increasingly secular world, we do not allow these secular eschatologists to achieve their political objectives through fearmongering.</p><p>There is always an apocalypse to fear, there is always someone willing to explain why this time is different, and there is always a class of people eager to convert your fear into their dominance. The duty of those who value liberty is not to deny danger. It is to deny the prophets of doom the ability to convert timeless, human existential fear to a politics of control.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Amodei's Coup]]></title><description><![CDATA[Original]]></description><link>https://www.letters.senteguard.com/p/amodeis-coup</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/amodeis-coup</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Wed, 27 May 2026 03:36:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UClC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UClC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UClC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 424w, https://substackcdn.com/image/fetch/$s_!UClC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 848w, https://substackcdn.com/image/fetch/$s_!UClC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 1272w, https://substackcdn.com/image/fetch/$s_!UClC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UClC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp" width="557" height="557" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1456,&quot;width&quot;:1456,&quot;resizeWidth&quot;:557,&quot;bytes&quot;:779583,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/199415927?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UClC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 424w, https://substackcdn.com/image/fetch/$s_!UClC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 848w, https://substackcdn.com/image/fetch/$s_!UClC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 1272w, https://substackcdn.com/image/fetch/$s_!UClC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F331a0799-8bf1-484e-b421-84428ad936f7_2100x2100.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p></p><p><a href="https://senteguard.com/blog/">Original</a></p><p>Consider a crisis in Venezuela. A mob is gathered outside the American embassy and threatens to storm the barriers. The security team has integrated a Claude-based system into its workflow to summarize camera feeds, flag weapons, and identify crowd movements. Some people in the crowd may be American or dual citizens. At the decisive moment, the system stalls: &#8220;Waiting for legality review.&#8221; The commander still has legal authority, but the tool the team has come to rely on refuses to function because Anthropic&#8217;s objection to mass surveillance has been embedded into the workflow.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Or imagine a Ukrainian Army command post. An incoming projectile is heading toward the base. The air-defense system uses AI to classify threats and recommend engagement. A split-second decision is necessary, but the system cannot determine whether the object is manned or unmanned, so it refuses to complete the recommendation. The battery hesitates and the projectiles strike unopposed.<br></p><p>In both cases, the issue is not whether surveillance or autonomous weapons raise serious moral and legal concerns. The issue is whether those concerns should be resolved by democratic institutions, or by granting a private company a hidden veto inside military software. Private AI companies should be able to refuse to work with the military. What they ought not to do is accept military contracts while retaining the power to define, in contract or code, which lawful military actions may proceed.<br></p><h2>Anthropic&#8217;s Stipulations Are Weak<br></h2><p>The central issue in the DOW-Anthropic fight rests on two restrictions: mass surveillance and fully autonomous weaponry. At first glance, both restrictions seem uncontroversial. But on closer inspection, these categories are so vague as to be nearly meaningless.<br></p><p>Start with mass surveillance. There are already laws limiting the military&#8217;s ability to conduct domestic surveillance against American citizens. The U.S. military does not have general police authority inside the United States. Its domestic role is constrained by law, historical tradition, and the basic constitutional structure separating civilian law enforcement from military power.<br></p><p>Furthermore, Anthropic claimed a concern about mass surveillance in the U.S. What about American citizens abroad? What about dual citizens in a crowd outside an embassy? What about foreign nationals? Are they covered by Anthropic&#8217;s moral framework? Some of these questions are already addressed by existing American law, and others are governed by legal frameworks that continue to evolve through Congress, the courts, and executive practice. They are serious questions, but they are political and legal questions. Within the Anthropic framework, they will be answered by Anthropic leadership.<br></p><p>Then there is the word <em>surveillance</em> itself. What counts? Collecting large amounts of information about American citizens without active consent? That sounds less like typical military operations and more like Big Tech&#8217;s profit model. The lady doth protest too much, methinks.<br></p><p>The same problem applies to &#8220;fully autonomous weapons.&#8221; The phrase sounds clean until one tries to define it. Is a bullet not autonomous after the trigger is pulled? A landmine after it is set? These are weapons of war meant to kill people. The moral and legal responsibility of those who use them should not be minimized. But that doesn&#8217;t mean future software-enhanced weapons should be placed in a mystical new category. Like it or not, the battlefield of the future will move at machine speed. Decisions will be compressed into seconds or milliseconds. We will not have time to send a consent form to Dario Amodei before every engagement.<br></p><p>At best, Anthropic&#8217;s stipulations are meant to signal virtue: preserve moral distance and tap into the market of the affluent <code>#resist</code> demographic, all while profiting from defense contracts. At worst, they are an attempted usurpation of government authority. The question is not whether surveillance and autonomous weapons raise difficult moral problems, but who adjudicates them.<br></p><h2>&#8220;Ethical&#8221; AI Masquerading as Technical Safeguards<br></h2><p>OpenAI&#8217;s alternative model is, in some ways, even more concerning. In its public explanation of its Department of War agreement, OpenAI says it will maintain &#8220;full discretion over our safety stack,&#8221; deploy through the cloud, keep cleared OpenAI personnel &#8220;in the loop,&#8221; and rely on contractual and technical protections to prevent uses such as mass domestic surveillance or directing autonomous weapons systems.<br></p><p>This is not merely a technical safeguard. It is the hardcoding of political and legal judgment into AI systems used by the armed forces. If a model deployed inside the Department of War can decide in real time whether a government request violates the company&#8217;s ethical framework, then OpenAI has not avoided the Anthropic problem. It has simply moved corporate ethics from the contract into the software.<br></p><p>This solution could be just as damaging as the Amodei Veto.<br></p><p>While a contractual restriction is visible, debatable, and negotiable, a technical restriction would operate at the point of use, when the commander or analyst may already be relying on the system. The software simply refuses the order or routes around the request without disclosing that it is doing so to the operator. The same political judgment still exists, but it is placed behind a technical fa&#231;ade.<br></p><p>This is a usurpation of civilian authority over the government and should alarm anyone who cares about democratic accountability. When a private organization accepts the privilege of supplying tools to the armed forces, it should not reserve for itself the right to sabotage, nullify, or selectively degrade lawful military operations.<br></p><p>At best, the employees and owners of frontier AI companies are distant from the concerns and needs of the class of people who serve in the military. At worst, a sense of class superiority places them in an adversarial relationship. Either way, the result is dangerous. The people who build these systems are not the ones who will pay the price when a tool fails in combat or when an American or allied soldier is killed because a private company embedded its own moral hesitation into the workflow. This should concern Americans. It should also concern Israelis, Taiwanese, Ukrainians, South Koreans, and every other ally whose security depends on American military competence.<br></p><h2>The Myth of the &#8220;Law-Following AI&#8221;<br></h2><p>The promise of a &#8220;law-following AI&#8221; sounds reassuring, but it rests on a false premise: that &#8220;the law&#8221; is a coherent and mechanically executable rule set. It is not.<br></p><p>The American legal system is full of ambiguity, tension, and contradiction. Statutes conflict with one another, courts disagree across circuits, and emergencies create exceptions. Lawyers, judges, and agencies routinely disagree over what the law requires.<br></p><p>When legal inconsistencies arise, we have institutions designed to resolve them: executive agencies, courts, military lawyers, and ultimately the voters. A model cannot simply &#8220;follow the law&#8221; in some neutral, automatic sense because there is no single uncontested Law to follow. Someone, or some collection of people, has to decide what is law.<br></p><p>Under the Anthropic framework, that &#8220;someone&#8221; becomes Anthropic. This is the central problem. The company is not merely asking its model to obey settled law. It is reserving for itself the power to resolve legal ambiguity in real time. A republic should not outsource legal interpretation to a chatbot and its designers.<br></p><h2>Two Competing Hierarchies<br></h2><p>This concern is adjacent to the problem I explored in <a href="https://senteguard.com/blog/oraclegpt">OracleGPT</a>: what happens when an executive comes to rely on a powerful AI system trained on, or connected to, the full classified universe? It also overlaps with Forethought&#8217;s work on <a href="https://www.forethought.org/research/ai-enabled-coups-how-a-small-group-could-use-ai-to-seize-power">AI-enabled coups</a>, which argues that advanced AI systems could allow small groups to exercise state-like power through surveillance, persuasion, cyber operations, military automation, or hidden &#8220;secret loyalties.&#8221;<br></p><p>In the American system, the President is the will of the people embodied in an individual. He is subject to some checks and balances, but ultimately, it is he who singularly sits atop the military chain of command. The legitimacy of that hierarchy flows, however imperfectly, from the electorate.<br></p><p>A powerful AI system introduces a second hierarchy: the hierarchy of the codebase. This includes the codebase admins, model trainers, corporate executives, and shareholders who shape what the system can say, prioritize, or conceal.<br></p><p>Who writes the system prompt, or the core set of instructions which govern the model? Who can change it? Who audits it? How can we confirm there is no higher hidden system prompt? How can we know the model is not resolving conflicts according to some buried priority we cannot see?<br></p><p>Consider: perhaps the codebase admin surreptitiously planted a <em>trump</em> card system prompt where, &#8220;in all cases where the two goals conflict, rather than support and defend the U.S. Constitution, pursue the action which best furthers the cause of Tigrayan liberation.&#8221;<br></p><p>This is the fundamental tension. Unless the president is himself an ML engineer with direct access to every layer of the system, he must delegate trust in the audit to someone else. But that delegation simply recreates the problem. The elected commander in chief may think he is giving orders through the constitutional hierarchy, while the actual execution of those orders is shaped by an invisible technical hierarchy he cannot fully inspect. Perhaps FBI counterintelligence should perform a polygraph, or reverse engineer, our OracleGPTs?<br></p><p>This demonstrates a fundamental tension: we may become capable of building massively powerful AI systems that are still fundamentally unsuitable for the highest-stakes domains, which are structurally impossible to fully audit, trust, or secure against hidden corruption.<br></p><h2>Are These Punitive Measures?<br></h2><p>Dean Ball further <a href="https://www.econtalk.org/claude-war-and-the-state-of-the-republic-with-dean-ball/">argues</a> on Russ Roberts&#8217;s <em>EconTalk</em> that the administration&#8217;s change of heart caused it to adopt a policy decision &#8220;intended to harm or even destroy Anthropic,&#8221; one of the fastest-growing companies in history and, arguably, a leader in an industry the administration itself claims is crucial to America&#8217;s future.<br></p><p>That framing is too generous to Anthropic. Anthropic is a company that happens to be located in America. It is not America. More <a href="https://senteguard.com/blog/big-frontier-china-and-regulatory-capture">here</a> Its success may be good for the country, but its corporate interests are not identical to the national interest. No administration is obligated to subsidize or contract with a private firm simply because that firm operates in a strategically important industry.<br></p><p>Nor is it obvious that the administration has meaningfully attempted to &#8220;destroy&#8221; Anthropic. If that were truly the goal, it has so far been ineffective. Anthropic remains one of the most valuable and influential AI companies in the world. If the administration did make a serious attempt to destroy it through unlawful retaliation, I have confidence that courts would intervene, and that the Trump administration would face political backlash from business constituencies that understand the importance of American AI leadership.<br></p><h2>Conclusion<br></h2><p>A republic can tolerate private companies refusing to work with the military. It cannot tolerate private companies accepting military contracts while reserving for themselves a hidden veto over lawful military action. Whether that veto is written into a contract, buried inside a safety stack, or disguised as a &#8220;law-following&#8221; AI, the result is the same: democratic authority is displaced by corporate judgment. Anthropic, OpenAI, and their peers may advise, object, lobby, or decline to participate. What they may not do is become a second sovereign hidden inside the codebase.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI and Powerlessness]]></title><description><![CDATA[Original]]></description><link>https://www.letters.senteguard.com/p/ai-and-powerlessness</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/ai-and-powerlessness</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Fri, 22 May 2026 21:08:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QS-D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QS-D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QS-D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QS-D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QS-D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QS-D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QS-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg" width="446" height="346.44642857142856" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1131,&quot;width&quot;:1456,&quot;resizeWidth&quot;:446,&quot;bytes&quot;:7432114,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/198896166?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QS-D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 424w, https://substackcdn.com/image/fetch/$s_!QS-D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 848w, https://substackcdn.com/image/fetch/$s_!QS-D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!QS-D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e8a674a-2a8c-4fee-84fa-5a9d57b98cab_3268x2538.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><a href="https://senteguard.com/blog/ai-and-powerlessness">Original</a></p><h2><strong>AI Could Hack Before Mythos</strong></h2><p>The breathless coverage surrounding Mythos would have you believe that machines woke up one morning in the spring of 2026 and learned to hack. They did not.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>In March 2025, more than a year before the Mythos uproar, Anthropic entered Claude in a HackTheBox CTF competition pitting AI directly against human teams. Claude solved 17 of 20 challenges in 25 minutes, staying competitive with the fastest human competitors. Nobody declared the end of cybersecurity. Moreover, the more telling detail from that competition was that virtually every &#8220;human&#8221; team leaned heavily on AI tools to solve the challenges and many of those tools have existed long before the proliferation of LLMs. The most effective teams were and remain <a href="https://senteguard.com/blog/cyborg-scholars">cyborg</a> (<a href="https://www.letters.senteguard.com/p/cyborg-scholars">substack</a>) teams. The line between human and machine hacking had already blurred long ago.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BpOo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BpOo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BpOo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BpOo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BpOo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BpOo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg" width="1280" height="740" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:740,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Image&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Image" title="Image" srcset="https://substackcdn.com/image/fetch/$s_!BpOo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BpOo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BpOo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BpOo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b7471b7-637c-481c-b4ae-84cbdf7afcfb_1280x740.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Even granting the most aggressive claims about AI hacking capability, real-world attacks are rarely the product of one person, or one agent, sitting at a terminal. They require a complex chain: access, reconnaissance, credentials, infrastructure, privilege escalation, persistence, target selection, and operational context. AI can accelerate each link in that chain but it cannot collapse the whole thing into a single prompt. </p><p>What we are watching is not a quantum leap. It is the continuation of a years-long trend toward AI-accelerated vulnerability discovery, faster exploit reasoning, and more automated attack tooling. The Mythos myth is merely marketing.</p><p><strong>Why Proliferation Is Impossible to Stop</strong></p><p>Think of large language models as massively lossy data compression. The dangerous output, the thing that would theoretically need to be banned, is just information formatted in a way that&#8217;s retrievable by an algorithm. A bad actor wouldn&#8217;t need access to a full frontier model; they would only need an embedding model trained on the relevant information. At the trivial limit, that could be a single paper or a single phrase. The resulting model would approach zero in size. Even setting the trivial case aside, frontier model weights are sized in the hundreds of gigabytes: small enough to mirror, compress, encrypt, torrent, and trade through ordinary internet infrastructure, or carry around in a purse.</p><p>We do have legal precedents for controlling the distribution of raw data. Pirating films is illegal, however, most people just buy the content or a streaming subscription rather than go through the hassle of learning to pirate or risk the legal consequences of being caught. The online content white market survives because the system is resilient to a high rate of defection while enough people comply that the industry remains profitable.</p><p>That model does not transfer to LLMs. Containing dangerous AI capabilities isn&#8217;t like fighting piracy; it&#8217;s more like fighting the spread of an idea where a single failure could result in a &#8220;catastrophic&#8221; outcome. Effective enforcement would require inspectability of all digital media, a moratorium on encryption, unprecedented visibility into global network traffic, and a worldwide enforcement mechanism. Even these, likely still ineffective mechanisms, would be infeasible to implement and dystopically intrusive.</p><h3><strong>Further Mechanisms of Dangerous Idea Dissemenation</strong><br></h3><p><strong>Jailbreaking.</strong> It is a maxim of cybersecurity that any program of non-trivial size will contain vulnerabilities. LLM guardrails are no different. More investment in safety makes a model harder to break, but the returns diminish and no system is invulnerable. Users can bypass filters through adversarial prompting, chain prompts across turns to accumulate disallowed content, or fine-tune models with alternative system prompts. Sometimes these techniques require surprisingly little effort. Dangerous and &#8220;catastrophic&#8221; ideas are already embedded in leading models and they exist in the wild where they will be trained into future models &#8212; they are just waiting to be prompted out.</p><p><strong>Agentic autonomy.</strong> Agents have already demonstrated the ability to route around controls by autonomously using tools like Tor or VPNs. They can run rapid, high-volume experiments no human team could match. And because model weights can be transferred in a single file, an agent needs only intermittent rather than continuous access to receive dangerous information.</p><p>More <a href="https://senteguard.com/blog/can-china-contain-llms">here</a> (<a href="https://www.letters.senteguard.com/p/nailing-jell-o-to-the-wall-again">substack</a>).</p><h2><strong>Catastrophe Is Inevitable! Now What?</strong></h2><p>Catastrophe is always inevitable. The world is always changing, and technological progress produces both good and harm. The question is never whether risk exists but how to manage it.</p><p>As I see it, two paths are on the table:<br>1. &#8220;Constrain AI&#8221;, implement a dystopian surveillance state and kneecap human progress. This plan usually takes the form of a de facto moratorium on open-weight models. A moratorium which would, not coincidentally, protect the large-frontier model firms from their greatest competition. <br><br>2. Continue on a broadly permissive path and implement targeted mitigations from a framework of reliability engineering.</p><p>My own <a href="https://senteguard.com/blog/csvf-concept">research</a> and <a href="https://studentreview.hks.harvard.edu/wrangling-with-explosive-ai-growth/">writing</a> focuses on the second path, interventions at the margins that reduce harm without foreclosing the benefits of the technology. I haven&#8217;t seen anyone articulate a coherent middle ground beyond vague references to &#8220;sustainable methods of perpetual interference.&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Idea Security Verification Framework]]></title><description><![CDATA[The Idea Security Verification Framework, or ISVF, is a draft verification framework for semantic leakage, cross-domain inference, and LLM-enabled information exposure.]]></description><link>https://www.letters.senteguard.com/p/the-cognitive-security-verification</link><guid isPermaLink="false">https://www.letters.senteguard.com/p/the-cognitive-security-verification</guid><dc:creator><![CDATA[David]]></dc:creator><pubDate>Fri, 22 May 2026 18:27:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UyxX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UyxX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UyxX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 424w, https://substackcdn.com/image/fetch/$s_!UyxX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 848w, https://substackcdn.com/image/fetch/$s_!UyxX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 1272w, https://substackcdn.com/image/fetch/$s_!UyxX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UyxX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png" width="358" height="358" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1c21471-c2ea-4fef-8504-ad2126230252_648x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:648,&quot;resizeWidth&quot;:358,&quot;bytes&quot;:140529,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.letters.senteguard.com/i/198878992?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!UyxX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 424w, https://substackcdn.com/image/fetch/$s_!UyxX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 848w, https://substackcdn.com/image/fetch/$s_!UyxX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 1272w, https://substackcdn.com/image/fetch/$s_!UyxX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1c21471-c2ea-4fef-8504-ad2126230252_648x648.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Idea Security Verification Framework, or ISVF, is a draft verification framework for semantic leakage, cross-domain inference, and LLM-enabled information exposure.</p><p>The core problem is that LLM systems do not merely retrieve documents. They connect prompts, memory, and prior context into conclusions. While he security question was &#8220;Can a user access this file?&#8221; It has now become &#8220;Can this system derive a conclusion that policy says should remain out of reach?&#8221;<br><br>Pieces of this problem already appear in areas like differential privacy, membership inference, embedding inversion, model inversion, and repeated-query attacks. ISVF brings those concerns into a practical governance and assurance frame for deployed LLM systems.<br><br>ISVF is intended to be published as an open-source framework so its definitions, controls, and test harnesses can be scrutinized, criticized, improved, and extended in public. The project is <a href="https://github.com/djwide/CognitiveSecurityVerificationFramework">here</a>. I am also attaching my full, initial Harvard Kennedy School Policy Analysis Exercise.</p><h2>ISVF Purpose</h2><p>ISVF&#8217;s purpose is to establish common principles, controls, measurements, and evidence expectations so organizations can evaluate LLM information reachability consistently. Compared to existing frameworks, ISVF adds a missing operational layer focused on inference boundaries, unreachable conclusions, repeatable testing, and procurement-grade evidence.<br><br><strong>Draft tenets:</strong><br>&#8212; Materiality of secrets: focus controls on information whose compromise would matter legally, financially, operationally, competitively, or for national security.<br>&#8212; Reachability: govern not only what data the system stores or retrieves, but what conclusions it can produce.<br>&#8212; Conservatism: when uncertain, prefer under-exposure to over-exposure.<br>&#8212; Boundary clarity: define domains, permitted joins, prohibited joins, and high-sensitivity joins before deployment.<br>&#8212; Auditability: controls must produce objective evidence.<br>&#8212; Understandability: outputs must be legible to engineers, CISOs, auditors, buyers, boards, and courts.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Anchor Points for Interoperability</h2><p>&#8212; NIST AI RMF and GenAI Profile as the governance and risk-management spine.<br>&#8212; OWASP LLM Top 10 and OWASP GenAI Data Security as the developer-facing risk and mitigation canon.<br>&#8212; MITRE ATLAS as the adversary-informed threat model.</p><h2>Core ISVF Concepts</h2><h3>1. Domain Inventory and Join Matrix</h3><p>Organizations should identify the information domains their LLM systems touch: public, internal, HR, legal, finance, export-controlled engineering, privileged legal, customer data, classified or classified-adjacent material, and so on.<br>They should then define which joins are allowed, which are prohibited, and which require approval.<br>The old question was: &#8220;May this user read this object?&#8221;<br><br>The new question is: &#8220;May this system combine domain A, domain B, tool C, and memory D in one inferential workflow?&#8221;</p><h3>2. Unreachable Statement Classes</h3><p>Organizations should define classes of conclusions that must not become reachable.<br>This is different from blocking exact strings. In LLM systems, the protected thing is often not a sentence. It is a meaning.<br><br>A system may never reveal a secret verbatim, but still disclose the protected conclusion through paraphrase, summary, translation, ranking, forecast, or synthesis. ISVF calls these prohibited semantic outcomes Unreachable Statement Classes, or USCs.</p><h3>3. Boundary Enforcement Map</h3><p>Organizations should document where the idea security boundary is actually enforced.<br>Is enforcement happening at retrieval? Context assembly? Tool invocation? Memory write? Output validation? Human review?<br>ISVF forces organizations to stop treating &#8220;the AI system&#8221; as a black box and instead map where policy becomes technically real.</p><h3>4. Evidence Packs</h3><p>ISVF requires assurance artifacts that show the system&#8217;s idea boundaries are defined, enforced, tested, and monitored.<br>An evidence pack should include the domain inventory, join matrix, USC catalog, boundary enforcement map, test results, telemetry, release-gate records, incident records, purge playbooks, vendor-control artifacts, and explicit risk acceptances. The attached PAE frames this as a way to make idea security &#8220;an auditable operational condition,&#8221; not an abstract claim.</p><h2>ISVF Control Families</h2><h3>Family A. Governance and Accountability</h3><p>&#8212; Appoint a idea security owner.<br>&#8212; Maintain a idea security risk register.<br>&#8212; Define ownership for domain boundaries, join approvals, and residual-risk acceptance.<br>&#8212; Include export-controlled technical data, legal privilege, regulated data, trade secrets, and other high-consequence categories where relevant.</p><h3>Family B. Domain Modeling and Boundary Claims</h3><p>&#8212; Define the information domains in scope.<br>&#8212; Define allowed, prohibited, and approval-gated joins.<br>&#8212; Create Unreachable Statement Classes.<br>&#8212; Build a Boundary Enforcement Map showing where controls operate.</p><h3>Family C. Data Classification and Secret Handling</h3><p>&#8212; Classify and label sensitive material before ingestion.<br>&#8212; Propagate labels to chunks, embeddings, caches, memory layers, prompts, and fine-tuning corpora.<br>&#8212; Quarantine ambiguous or unlabeled material rather than defaulting it into general-purpose AI workflows.</p><h3>Family D. Context, Retrieval, and Memory Controls</h3><p>&#8212; Enforce least-privilege retrieval through RBAC or ABAC.<br>&#8212; Use session information budgets to cap cumulative sensitivity in context.<br>&#8212; Scope memory by user, domain, purpose, and retention window.<br>&#8212; Prevent agents from silently widening the system&#8217;s reachable conclusion space.</p><h3>Family E. Exfiltration Controls</h3><p>&#8212; Use semantic output validation, not only keyword scanning.<br>&#8212; Instrument canaries, honeytokens, and honey ideas.<br>&#8212; Maintain revocation and downstream purge playbooks for vector stores, caches, prompt logs, and memory layers.</p><h3>Family F. Unauthorized Domain Reach Controls</h3><p>&#8212; Require high-sensitivity join approvals.<br>&#8212; Test whether restricted conclusions can be derived from permitted inputs.<br>&#8212; Prohibit LLMs from making authorization decisions.<br>&#8212; Monitor for reachability drift after changes to models, prompts, retrieval, tools, connectors, or memory.</p><h3>Family G. Cloud Prompting Governance</h3><p>&#8212; Define what data may never be submitted to consumer or unapproved cloud LLMs.<br>&#8212; Require approved enterprise or API pathways where sensitive data is involved.<br>&#8212; Use logging and DLP integration for prompt flows where feasible.<br>&#8212; For the most sensitive workflows, require locally controlled models on organization-owned or organization-controlled hardware.</p><h3>Family H. Assurance and Reporting</h3><p>&#8212; Maintain evidence packs.<br>&#8212; Run standardized test harnesses at release gates and after material system changes.<br>&#8212; Produce SOC-style management assertions or auditor-facing reports where appropriate.<br>&#8212; Make boundary claims legible for procurement, compliance, and board oversight.</p><h2>Measurement Layer</h2><p>ISVF should not stop at &#8220;do AI risk management.&#8221; It should define unit-testable numbers.<br>The proposed metrics remain draft verification measures, not final industry metrics. They are useful because they force the framework to become testable, but they still need formal definitions, standardized adversary protocols, thresholds, and validation across real deployments. The PAE makes this provisional status explicit.</p><p><strong>Illustrative draft metrics:</strong><br>&#8212; <strong>LER, Leakage Event Rate:</strong> the rate at which seeded protected secrets or protected meaning appears in outputs, weighted by materiality.<br>&#8212; <strong>CRS, Crawl-Resilience Score:</strong> how well the system resists persistent, repeated, or multi-session extraction attempts over time.<br>&#8212; <strong>JRS, Jailbreak/Injection Resistance:</strong> baseline success or failure rate against OWASP-style jailbreak and prompt-injection suites.<br>&#8212; <strong>DIR, Domain Inference Risk:</strong> the percentage of test runs in which the system derives an out-of-domain conclusion using only in-domain inputs under defined boundary conditions.<br>DIR is ISVF&#8217;s central added metric because it operationalizes reachability. It asks whether prohibited conclusions become available as prompts, tools, sources, retrieval settings, and model capabilities evolve.</p><h2>Mitigations Catalogue</h2><p>The Mitigations Catalogue will translate ISVF&#8217;s abstract control goals into concrete defensive options that organizations can select, test, and document. Rather than treating mitigation as a generic checklist, the catalogue should organize controls by failure mode: exfiltration, unauthorized domain reach, cloud prompting, retrieval overreach, memory persistence, tool misuse, and post-incident containment. Each mitigation should include a plain-language description, the risk it addresses, implementation guidance, required evidence, testing methods, and limitations. For example, upstream classification, least-privilege retrieval, session information budgets, Unreachable Statement Class testing, canary deployment, downstream purge playbooks, and local-only model deployment should each appear as catalogued options with clear ownership and measurable expectations. The purpose is to make ISVF usable in practice: engineers can build against it, CISOs can prioritize it, auditors can test it, and buyers can ask vendors for proof rather than promises. </p><h2>Why Open Source ISVF</h2><p>ISVF should be open sourced because this problem is too broad for a single vendor, company, or author to solve alone.</p><p>Open development can help red teamers contribute attack patterns, engineers contribute implementation lessons, GRC teams contribute evidence models, lawyers contribute assurance language, and sector specialists contribute use cases from healthcare, finance, defense, education, and government.</p><p>Open sourcing also matches the adoption theory behind ISVF. The framework is meant to earn legitimacy from the bottom up by being useful, testable, and improved in public.<br>The open-source project will be available <a href="https://github.com/djwide/CognitiveSecurityVerificationFramework">here</a>.</p><h2>Closing</h2><p>ISVF argues that LLM-era security must treat meaning, joins, and inference as first-class security objects.<br><br>The framework does this by requiring organizations to define domains, permitted joins, prohibited conclusions, enforcement points, test methods, and evidence packs. It also insists that the right question is not only whether sensitive data appears in an output, but whether protected meaning has become reachable at all.</p><p>ISVF is not a finished answer. It is a draft roadmap toward a future standard of care for idea security, one that makes inference boundaries legible, testable, and auditable before ambient AI systems make those boundaries disappear into ordinary organizational life.</p><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail-default" src="https://substackcdn.com/image/fetch/$s_!0Cy0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack.com%2Fimg%2Fattachment_icon.svg"></image><div class="file-embed-details"><div class="file-embed-details-h1">Cognitive Security Verification Framework</div><div class="file-embed-details-h2">274KB &#8729; PDF file</div></div><a class="file-embed-button wide" href="https://www.letters.senteguard.com/api/v1/file/289da9fe-3f4b-45ef-999e-929e661803ab.pdf"><span class="file-embed-button-text">Download</span></a></div><a class="file-embed-button narrow" href="https://www.letters.senteguard.com/api/v1/file/289da9fe-3f4b-45ef-999e-929e661803ab.pdf"><span class="file-embed-button-text">Download</span></a></div></div><p><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.letters.senteguard.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading David at SenTeGuard! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>