Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
When the provider is the incident: hybrid infrastructure and somebody else's maintenance
Azure had an infrastructure incident that hit hybrid scenarios, VPN and cloud VMware services. According to The Register, the trouble came out of internal maintenance work. Why this is the nastiest class of outage to own, and what actually helps.
Voice agents reached operations: what separates a working one from an expensive demo
ElevenLabs says its voice agents run more than 15 million conversations a week, and they now handle returns, insurance actions and bookings. Why voice became the first agentic AI segment with a real production use case, what separates a working agent from a polished demo, and what to settle about recordings and personal data before the pilot starts.
Observability for a swarm of AI agents: what they are doing, who allowed it, and how to stop them
OpenAI is building a dedicated mechanism to watch and control large numbers of concurrently running agents. Why agent observability differs from classic metrics, logs and traces, why it sits closer to security than to operations, and what to put in place while you still only have a handful of agents.
The coding agent gets its own environment: rights, review and the bill
OpenAI added reusable cloud development environments to Codex. A coding agent stops being autocomplete in an editor and becomes a participant in the pipeline with its own access. What changes in credentials, secrets, repository history, and who answers for the code it writes.
Kubernetes for AI agents: when always-on agents need a control plane
OpenClaw Enterprise is being built as an open-source control plane for always-on AI agents, with OpenAI, NVIDIA and Red Hat involved. What the AgentOps layer actually solves, who needs it today, who does not, and the signals that tell you it is time.
The FTC turns to autonomous agents: what you need to be able to prove about yours
A US regulator is asking whether existing law is enough to hold companies accountable for what autonomous AI systems do. While the legal frame is argued over, the engineering requirement is already clear: audit trail, permissions, sandboxing and human approval stop being optional.
Gemini 4 Argon: you now pick a model for a process, not for an answer
Google unveiled Gemini 4 Argon with a focus on coding, long multi-step tasks and cybersecurity, still in limited access. What changes in model selection once the unit of work is a process: long context, autonomy, checkpoints, and the questions worth asking before a pilot.
Legacy on the factory floor: securing Windows XP and 7 systems you cannot patch
Industrial equipment lives 15 to 30 years, and the control PCs under it run on Windows XP and 7 that lost support long ago. A routine patch can void the vendor warranty or crash the process. What to do when you cannot update: move the defense from the host to isolation and compensating controls.
AI on the factory floor and a new class of attack: how to protect an industrial model
Factories put neural nets on predictive maintenance and process optimization. A new class of attack - poisoning the training data and quietly spoofing telemetry - pushes the AI into decisions that wreck equipment. Where the real line of defense actually runs.
"Do we have to keep expensive data scientists on payroll forever now?" What you actually need after delivery
The owner's fear at the end of a data project: that expensive specialists now have to stay on staff forever. What is actually expensive, and two honest ways to hand the work over without bloating payroll or staying locked to the contractor.
"We have a niche stack - have you worked with it?" How I take on unfamiliar technology
A direct answer to the client's real fear: paying my rate while my engineers google your technology. What I actually sell, and how I ramp on an unfamiliar or legacy system.
Local AI: running a model so your data never leaves the perimeter
An honest engineering and cost picture of local AI: what your own perimeter actually buys you, the ladder of options from Ollama to air-gapped, and when a hosted business tier is enough.