Skip to content
Open to board advisory and board seats — 2H 2026, then CY 2027–2028.
See details →
AI

Writing on AI

AI governance, agents, AI security, and FinOps — for the CIOs, CISOs, and architects who have to ship.

Everything here is written by Michael York, VP of Information Security & DevOps at SavvyMoney, who stood up AI governance for a fintech platform serving 1,500+ financial institutions. These essays take positions — on AI governance and regulation, AI security, agents and non-human identity, and AI cost — argued from production work rather than a news wire. New essays land weekly; the topic hubs below group them by theme.

37 posts shown

Featured

More posts

7/21/2026 9 min

'We Don't Train on Your Data' Is Not Enough

An agent told to open no files obeyed — while the product uploaded the whole repo, canary included. "We don't train on your data" answers the wrong question.

AIAI SecurityAI GovernanceFintech
7/20/2026 9 min

A Convincing Voice Is Not Authenticated

A cloned voice with matching caller-ID is recognition, not authentication. Move trust onto channels you control: callback on record, dual authorization.

AIAI SecurityFraudDeepfakesFintech
7/18/2026 8 min

Your Prompt Is the Approval. That's the Gap.

An MCP connector executes writes with no approval screen — your prompt becomes the one boundary nobody governed. That missing gate is a control-plane gap.

AIAI AgentsAI SecurityAI GovernanceNon-Human IdentityFintech
7/15/2026 10 min

Your AI Policy Is a PDF. Agents Can't Read It

A model given thousands of extra words wrote better prose — and failed the delivery contract two runs in three. Rules agents can ignore fail audits.

AIAI GovernanceGRCAuditPolicy-as-Code
7/12/2026 9 min

Prove You Need the Agent Before the Swarm

Token spend explained ~80% of variance in multi-agent runs; most "AI failures" are provisioning mistakes. Treat a swarm as segregation of duties.

AIAI AgentsFinOpsNon-Human IdentityGRC
7/9/2026 9 min

Shadow AI: Your "Personal Tool" Is Production

A coding agent stands up a data-touching tool in an afternoon. The moment it needs a login or gets shared, it's a production system nobody reviewed.

AIAI GovernanceAI AgentsSecurityGRC
7/6/2026 9 min

Stop Gating the $40 Question

Two hours and $40 did what a top engineer says he couldn't — and no routing table would have assigned it. Gating frontier access defunds your own sensing.

AIAI GovernanceOrg DesignFinOpsBoard Reporting
7/3/2026 8 min

The Second Agent Cheap, the Fiftieth Boring

Build cost was never the constraint in a regulated shop — agent #50 hits the same security review as agent #1. Make identity and action gates reusable.

AIAI AgentsPlatform EngineeringAI GovernanceDevOps
6/27/2026 6 min

Bake Audit Evidence Into Your AI Pipeline

Audit-defensibility isn't a document you write after the fact — it's a property you engineer into the AI pipeline so its operation emits evidence as exhaust.

AIAI ComplianceAuditNIST AI RMF
6/25/2026 5 min

The 2026 AI Regulatory Map on One Page

Everyone read 'EU AI Act deferred to 2027' and exhaled — but the part fining 3% of global revenue turns on in August. The four 2026 rules with teeth.

AIAI GovernanceComplianceNIST AI RMF
6/23/2026 6 min

Design AI Inference for Model Disappearance

A frontier model went dark three days after launch; here's how I make AI inference survivable on AWS when the provider is a dependency you don't control.

AIAWSResilienceAI Infrastructure
6/21/2026 6 min

Your AI Bill Is the New Cloud Bill

We spent a decade learning cloud FinOps and are repeating every mistake with LLM spend — here's the operating model that meters, routes, and caps it.

AIFinOpsCloud CostLLMOps
6/20/2026 5 min

Nobody Is Governing Your Agents' Credentials

Your agents already outnumber your people, they can authenticate but not prove they're authorized, and that's the gap SOC 2 and HIPAA were never built to close.

AINon-Human IdentityIAMCloud Security
6/18/2026 6 min

Stop Trying to Patch Prompt Injection

Prompt injection isn't a bug a vendor will patch — it's a property of how models read context. Design systems that stay safe even when the model is hijacked.

AIAI SecurityPrompt InjectionAppSec
6/17/2026 6 min

The Control Plane Is the Job

Standing up an agent takes an afternoon; the control plane that lets it touch production safely is the actual engineering work, and almost nobody shows it.

AIAI AgentsSecurityPlatform Engineering
6/16/2026 6 min

Model Selection Is Capacity Planning

Most teams pick a model like a sports team and never revisit it — but model selection is a routing, capacity, and risk decision you already know how to make.

AIModel SelectionFinOpsInfrastructure
5/26/2026 5 min

Your Agent Dashboard Is Green and Lying

Uptime tiles tell you the service answered — nothing about whether the answer was right. That gap is where a model-risk review will eat you alive.

AI GovernanceObservabilityRisk ManagementFintech
5/19/2026 6 min

Shadow AI Is the New Shadow IT

Every abandoned notebook and weekend prototype is a credential-bearing asset nobody owns. The fix isn't a ban — it's discovery, demotion, and real sunsets.

AI SecurityShadow ITDevOpsFintech
5/12/2026 5 min

Three Token Counts, Zero You Can Attest To

Codex says one number, Claude another, your gateway a third. That isn't a metering problem — it's an attestation problem regulated industries can't afford.

AI GovernanceFintechDevOpsCloud Security
4/21/2026 5 min

Concentration Risk in the Three-Lab AI Stack

Most of the AI on your roadmap traces to three labs on the same chips, supply chain, and balance sheets. That's a concentration risk your board hasn't priced.

AI GovernanceVendor RiskBoard StrategyResilience
4/18/2026 1 min

What AI Actually Changes for Attackers

Cutting through the threat inflation: what AI genuinely changes for attackers, what it doesn't, and where a defender's hardening effort actually pays off.

AIThreat IntelligencePhishingDefense
4/9/2026 5 min

Make Your Enterprise Agent-Readable First

Everyone is racing to buy agents; almost no one builds the substrate that lets them act safely. The productivity is real — so is the blast radius.

AI AgentsPlatform EngineeringSecurityFintech
4/7/2026 5 min

Dark Code Is a Control Failure, Not Tech Debt

AI is filling repos with code nobody can explain. We call it tech debt; it's a control failure — and it should fail CI like a missing approver does.

AI GovernanceDevOpsSoftware Supply ChainFintech
3/24/2026 5 min

AI Found 271 Bugs in Firefox. Now Your Repos?

AI-assisted fuzzing found hundreds of bugs in hardened open-source code. The question is whether you run it before someone else runs it against you.

AI SecurityDevOpsVulnerability ManagementFintech
3/19/2026 5 min

Source-Map Leaks: Your Pipeline's Confession

One packaging mistake can publish hundreds of thousands of lines of internals. The leak is a confession: release controls never caught up to release velocity.

AI SecurityDevOpsSupply ChainFintech
3/17/2026 6 min

Shadow-Agent Discovery for Regulated FIs

Unsanctioned AI agents already run in your environment with your credentials. Find, classify, and gate them before they touch member data or an exam does.

AI SecurityAI GovernanceFintechRisk Management
3/12/2026 1 min

Automate the Boring, Not the Judgment

A framework for deciding which security work to hand to machines — and the judgment line you should never let automation cross, no matter the headcount math.

Security OperationsAutomationAITeam Building
3/5/2026 5 min

An AI Agent Dropped Prod: The Change Playbook

Coding agents are committing real change to real systems. The question isn't whether to let them — it's how to give them speed without a SOC 2-fatal mistake.

AI GovernanceDevOpsComplianceFintech
3/3/2026 5 min

Agent Safety: Engineer the Blast Radius

Most agent "safety" is a politely worded request to a model that need not honor it. The only controls that count still hold after the model goes wrong.

AI AgentsFintechCloud SecurityDevOps
2/26/2026 5 min

Your Browser Agent Has Your Cookies

Browser AI agents don't request access to your systems — they inherit it from the authenticated sessions in your tabs. A threat model nobody provisioned for.

AI SecurityIdentityShadow ITFintech
2/24/2026 5 min

Agent Memory Is a Data-Residency Problem

Give every agent a durable, MCP-connected brain and you've stood up a new data lake of PII and PCI scope nobody classified, encrypted, or can purge.

AI GovernanceData ProtectionFintechDevOps
2/17/2026 5 min

Anchoring Bias Is Already in Your KYC Agent

The failure modes that made medical LLMs unsafe sit inside your fraud, dispute, and onboarding agents. They don't announce themselves — you have to hunt.

AI SecurityFintechRisk ManagementLLM Evals
2/13/2026 6 min

Agent Onboarding Was Easy. Offboarding Isn't.

Every team shipped an agent in a weekend. Almost none can say how it gets fired, what credentials it still holds, or who would notice if it went rogue.

AI AgentsNon-Human IdentityIdentity SecurityFintech