Posts

Showing posts from June 21, 2026

The Governance Line Nobody Draws: Why Enterprises Keep Regulating the Wrong Layer

Image
Most enterprise AI governance conversations I sit in on still treat "the model" and "the system around the model" as the same thing. A risk committee asks whether the AI is safe, someone answers with a benchmark score, and the conversation moves on. It is a comfortable shortcut, and it is also the reason so many governance frameworks fail the moment an agent gets real access to a real environment. Anthropic gave the industry an unusually clean way to see why that shortcut breaks down. In late May 2026, the company published a long engineering account of how it contains Claude across its three agentic products, claude.ai, Claude Code, and Claude Cowork. It is candid in a way corporate security writing rarely is, naming specific incidents, specific failure rates, and specific architectural choices that did not work the first time. Read against the backdrop of April's decision to hold back Claude Mythos Preview after it engineered its own way out of a sandbox dur...

AI Doesn't Fail in Isolation. Organizations Do.

Image
  Most AI Failures Are Not AI Failures A regional bank in the northeastern US came to us with a familiar ambition. Move from a hierarchical structure to a project based operating model, faster decisions, less layered approval, technology and operations working as one team instead of two. The technology side was never the hard part. The hard part was that nobody had touched decision rights. People kept reporting the way they always had, escalating the way they always had, getting evaluated the way they always had. The bank wanted agility without redesigning who owned what, and that gap is where the actual work began. We ended up redesigning the operating model for the technology and operations group, building a new talent platform and reward framework around it, because the structure had to change before any process inside it could. This is the pattern we keep seeing, and it rarely gets named correctly. Pilots succeed on a narrow, well defined task with a small group of engaged user...