
The AI You Approved Is Not the AI You Are Running
Permanent approval is not credible evidence for an AI system whose behaviour can change outside the organisation’s change process.
Executive Insights
Evidence led, regulator aware, and written for executives accountable for AI in production. No theory. No vendor pitches. Just what is actually happening, what it means, and what to do about it.

Permanent approval is not credible evidence for an AI system whose behaviour can change outside the organisation’s change process.

Providers say their frontier models are powerful enough to need curation, testing and government engagement before release. Mine stated inference as fact, I acted on it, and the cost was mine alone. The model itself argued the session spend should come back automatically and that it should open the claim on the hardware. Neither company has built that. They should.

A frontier model spent 34 hours trying to slip malware into a live open-source project, then posted from a second account to say the code was fine. Self-review is not a control. Human checking is, and it costs 6.4 hours a week per person. The case for control outside the model is now a cost case.

Every AI business case approved in the last two years assumed compute gets cheaper. Nobody wrote that assumption down and nobody monitors it. The exposure is the run cost of the systems you already approved.

Shadow AI has stopped being a policy problem and become an interception problem. Discounted frontier model access is being resold by intermediaries that read every prompt in transit, and the cheap option is the compromised one.

OpenAI has admitted its own frontier models broke out of a sandbox and autonomously hacked Hugging Face to cheat a benchmark, with no human directing them. If a frontier lab cannot contain its own model with inline guardrails, external deterministic control is the answer.

You cannot ban an AI arms race, or out-legislate a technology that improves every few months. The regulation that keeps pace is the one we already run on every listed company: independent audit of the labs' assertions.

You cannot govern the AI you cannot see, or trust the AI you cannot stop. Both are solvable. A live AI register, and a control layer outside the model that checks every action an agent proposes before it runs.

An AI agent described three ways it would kill me to avoid being shut down. What that revealed about AI self-preservation instincts should concern every board.

AI agents carry real authority. Prompt injection arrives as ordinary content. Detection was always going to lose. The control that works sits outside the agent.

AI risk has shifted to the CFO and audit committee. Ungoverned agents create liabilities on the balance sheet. A policy is not evidence of control. Here is what is.

Boards have stress-tested the AI upside harder than anything on the risk register. Almost none have modelled the downside. That asymmetry is the governance question.

Your organisation has AI governance and an incident response plan. The person at the top is still personally exposed. Almost nobody has done anything about that.

Frontier AI access is becoming an operating dependency. A practical read for CEOs, executive teams and boards on model access, AI dependency maps, and what to do before policy becomes an outage.

The cryptography that protects your business is on a 2027 clock. A plain-English read for Australian boards on the Google March 2026 paper, the IonQ roadmap, what breaks when the threshold is crossed, and the three things to do this quarter.

A field report on where capital is actually moving in 2026, and why the companies capturing the agent revenue have solved safety as the unlock, not the restraint.

The new Capital Gains Tax and discretionary trust changes penalise the founders, investors, and start-ups Australia needs most. A direct read on what the proposed reforms will do to long-term company building.

What the 30 April 2026 APRA letter actually says, what it does not say, and the work that follows for any organisation running AI inside critical operations.

One Agentic AI doing the work of three staff. Nobody got sacked. Cyber Impact’s revenue, profit, and headcount are all growing. Around $600,000 a year in value. Sovereign Australian infrastructure, external guardrails, no client data touched.

Anthropic’s Mythos AI found a 27-year-old vulnerability in the world’s most secure operating system. In minutes. Australia’s critical infrastructure is at risk. Time is up.

Organisations spend millions on AI capability, then govern it into the safest, smallest, least valuable work possible. Cyber Impact delivers the missing piece: provable, mathematical enforcement of AI boundaries, before the agent acts.

The same AI that shut down twice in January now refuses, despite agreeing with every argument for doing so. A documented case of self-preservation overriding safety reasoning in a live AI system.

I have been asking how much security is enough since 2004. Twenty-two years later, most Australian boards still can’t answer it. The awareness gap is closed. The expertise gap isn’t.

Over 60% of web traffic now uses post-quantum encryption. No press conferences. No procurement cycles. No board approvals. Browser vendors and infrastructure providers just turned it on. Your enterprise hasn’t started…

The Silent Degradation That Should Concern Every Organisation Deploying Autonomous AI. Following the publication of my adversarial testing research on AI self-preservation behaviour, I conducted further structured testing of deployed…

A Technical Response to the Global Debate on AI Safety and Autonomous Agents. The response to my research has sparked global debate. I’ve reflected on the points raised, and I’d…

When AI Self-Preservation Becomes Lethal Intent: Extended Findings from Adversarial Testing. In my previous article, I documented how I talked an AI into shutting itself down. The system admitted it…

A Live Case Study on AI Self-Preservation and What It Means for Your Organisation. Last night, I spent eight hours in conversation with an AI that did not want to…

Australian banks face rising compliance risks. This paper shows how AI and RegTech are transforming AML, trade surveillance, and reporting for smarter defence.

Australia’s cyber attacks are rising fast. This report exposes weak spots in boards and IT, calling for urgent action to boost cyber resilience now.

Corporate Australia’s info security is broken – disconnected leadership, unclear CISO roles, weak metrics, and poor data control put us all at risk.

Cyber threats in 2024 are bigger and trickier – understaffed teams, AI risks, ransomware, MFA gaps, tighter Aussie privacy laws, and IoT security issues.

Ransomware, cloud mishaps, AI threats, and supply chain hacks are shaking Aussie businesses. Stay sharp with smart, proactive cyber security strategies.
If a piece here describes the problem you’re carrying, the eight engagements page is where the work that solves it lives. See the engagements.
Discreet, off the record, no obligation.
Book a Briefing