Point of view · Jul 2026
You Made an AI Policy. So Now What?
A policy is not governance. The five ways an AI council fails, mapped to Lencioni's five dysfunctions, and the cheapest fix available before its next meeting.
We help organizations deploy AI that survives attackers, auditors, and regulators.
Point of view · Jul 2026
A policy is not governance. The five ways an AI council fails, mapped to Lencioni's five dysfunctions, and the cheapest fix available before its next meeting.
Point of view · Jun 2026
A control framework tells you what to do. Whether a healthcare organization can actually do it is a question of people, ownership, and maturity, and the workforce now includes AI agents.
Point of view · Jun 2026
Policy has started borrowing patch-management language for AI systems. But fine-tuning, retraining, and weight editing are not patches, and the difference matters.
Talk · Jun 2026
Chris M. Ward at Planet Cyber Sec AI AppSec, Annenberg Community Beach House, Santa Monica, June 3, 2026.
Talk · May 2026
Dr. Josh Harguess and Chris M. Ward co-chaired the SPIE conference on Assurance and Security for AI-enabled Systems.
Research · May 2026
Our SPIE DS26 paper ran 14,850 evaluations across five model families and three quantization tiers. Temperature, not quantization, is the safety variable most organizations should worry about.
Talk · Apr 2026
A BSides San Diego 2026 session on the AI governance frameworks that matter: NIST AI RMF, the EU AI Act, ISO 42001, GDPR and MITRE's AI Maturity Model.
Talk · Apr 2026
A session on the AI governance frameworks that matter: NIST AI RMF, the EU AI Act, ISO 42001, GDPR and MITRE's AI Maturity Model.
Talk · Apr 2026
An interactive workshop pairing the NIST AI RMF and the MITRE AI Maturity Model with a live incident tabletop.
Talk · Mar 2026
Dr. Josh Harguess on a panel on third party AI risk at the Grand Hyatt, Nashville, March 18 and 19, 2026.
Talk · Mar 2026
A three hour workshop with ISACA San Diego, in person and on Zoom, March 5, 2026.
Talk · Mar 2026
Chris M. Ward and Dr. Josh Harguess speaking at Naval Applications of Machine Learning.
Point of view · Feb 2026
Chinese labs drained Claude's intelligence through the front door with 16 million automated exchanges. The AI industry doesn't just have a security problem: it has an operational maturity problem.
Field notes · Jan 2026
A look back at our first year: research at the NATO IST-210 symposium, CAMLIS, BSides Las Vegas and SPIE DCS, and where we take it next.
Interview · Dec 2025
Dr. Josh Harguess with Terry Gerton on Federal News Network, on what AI-enabled attackers change for federal agencies.
Research · Nov 2025
AI fails in ways firewalls cannot see: data poisoning, model theft, prompt injection. The three layers of a deliberate offensive AI security strategy.
Point of view · Nov 2025
Fifteen years ago, developers fought over whether IDEs were cheating. Now they're arguing about AI assistants. What automation research says about losing the fundamentals, and how agentic development keeps you the architect.
Interview · Nov 2025
Interview · Nov 2025
Josh Harguess, CTO of Fire Mountain Labs, explains how to evaluate, deploy, and govern AI-driven security tools.
Talk · Oct 2025
Dr. Josh Harguess at the NATO STO Research Symposium on AI Security and Assurance for Military Systems.
Talk · Oct 2025
Dr. Josh Harguess chaired the workshop and gave its keynote at IEEE MILCOM, Los Angeles, October 2025.
Talk · Jun 2025
Talk to the people who'll do the work.
Start a conversation