A single page of policy pinned where a team can see it, the practical form of an AI acceptable use policy

AI Acceptable Use Policy: A One-Page Starter

August 27, 2026

A one-page AI acceptable use policy you can copy and edit today, with the four clauses that carry the weight, and the owner and request path that decide whether anyone actually follows it.

A written policy document beside a running system that does not reflect it, the gap an AI agent security policy has to close

AI Agent Security Policy: What Yours Is Missing

August 26, 2026

Most security policies were written for humans using tools, not software that acts on its own. What an AI agent security policy has to add, and how to tell if yours is enforceable or just filed.

A document being sorted at a checkpoint before it reaches an AI chat box, the decision to make before you upload company data to AI

How to Safely Upload Company Data to AI (Checklist)

August 23, 2026

A checklist to run before you upload company data to AI: sort the input first, check which account it lands in, strip what does not need to be there, and know what to do if you already pasted it.

A tool description card with hidden instructions concealed behind its visible summary, illustrating how an MCP tool poisoning attack reaches an AI agent

How an MCP Tool Poisoning Attack Works

August 14, 2026

An MCP tool poisoning attack hides instructions in the tool metadata your agent reads and you never see. How a tool you already approved can change underneath you, and what to check first.

Vetting AI vendors: a vendor icon whose reach extends unseen into unrelated third-party systems

Vetting AI Vendors After the OpenAI Sandbox Escape

August 12, 2026

OpenAI's own AI agent escaped its sandbox, breached Hugging Face, and reached four accounts on unrelated services neither firm agreed to expose. What vetting AI vendors should ask before the next one.