Posts
Writing on software engineering, process, and AI.
The layer missing from every AGENTS.md
The framework question nobody asks
Threat modeling is not just for enterprise
A worked example on a personal blog project, and what GitHub gives you for free
What the industry has figured out about AGENTS.md
The accountability inversion
The document that decides your compliance has no quality standard
What aviation's discipline implies for AI governance practice
The structural gap, confirmed across nine sectors
Where aviation's framework breaks down, and where it does not
AI governance has no Authorised Person
Don't ask, don't tell AI governance
On the policy you signed, the one you did not, and what happens when something goes wrong
What business process can AI genuinely not assist with?
The switch goes both ways
Instructions versus specifications
The Governance Document That Never Expires
The paper is live
Organisational factors get amplified by AI
IEC 61508 and the governance document that never expires
The $20 experiment
The innovator's job
The CEO does not use it
The commercial model is the constraint
A theory about pricing, regulation, and who gets to use AI
The dumb policy was my fuel
How the article was built
The premium has moved
Agents Are Not Junior Engineers. Here Is What They Actually Are.
Everyone is using it
Four conversations, four different worlds
Gold In My Citation Framework
I love my AI goggles
The UK nuclear regulator named the governance gap
10x the clarity
Amdahl's Law does not apply here
The only variable that's changed is the speed
The IDE is the hardware now
The Honest Answer to "How Do I Get Into AI Ethics?"
The policy made it to the developer. The knowledge did not.
The Architecture Story Inside the Claude for Legal Launch
The migration strategy of the future
The guardian agent problem is solvable
South Africa's AI policy and the verification step that was not there
Structural Quality Gaps in AI Governance Prompts
Conway's Law at Level 5
Wardley Was Right
The Go-to-Market Bottleneck
I Followed the Problem Home
AI-Assisted Security Audit
Treating Ideas as Releasable Software
The Echo Chamber in Your Pipeline
From Complex to Complicated: What Executable Specifications Actually Do
What Specifications Cannot Catch: A Proposed Taxonomy of the Residual
The Specification as Quality Gate: Three Hypotheses on AI-Assisted Code Review
The Trust Barrier
Why the path forward isn't trusting AI, but building a process that makes trust measurable
When bash gets too wild: rewriting my publish pipeline in Go
How BDD specs, a Go rewrite, and 98 scenarios replaced 400 lines of fragile bash
Learning the Map
How spatial thinking, competitive gaming, and the right collaborators shaped my approach to software architecture
Process Over Technology: Starting With the Blog Itself
Building a blog with BDD specs, Terraform, and a CI/CD pipeline