Notes on data, AI, IT
and security
No marketing fog. The way I think about real problems with founders and managers.
Vendor concentration: the hidden single point of failure in IT
Why depending on a single infrastructure or software supplier is an operational risk, not just a negotiation position.
EU AI Act is in force: what providers and deployers need to do now
A practical breakdown of the first obligations under the European AI regulation for those building or deploying AI systems.
CrowdStrike: how one content update tears the global operational fabric
A breakdown of the July 2024 incident and what it reveals about business operational resilience.
RAG in production: why a large context window does not solve the problem
Why RAG architecture often disappoints in production, and where the real bottleneck sits.
Data contracts between teams: a simple tool that prevents a class of breakages
What data contracts are, why they solve a problem that technical tools cannot, and how to start without a large project.
Shadow AI tools: managing risk without banning everything
How companies can manage the risks from employees' unsanctioned use of AI tools - without making a blanket ban the only answer.
Kubernetes: what founders discover after the migration
An honest look at the operational and financial realities of Kubernetes for mid-sized companies - what the container adoption presentations leave out.
GPT-4o and the normalisation of real-time multimodal UX
What the GPT-4o announcement means for companies designing AI-powered interfaces: voice, vision, and text in a single stream is becoming a standard expectation.
RAG vs fine-tuning: the decision a manager actually needs to make
A practical framework for choosing between RAG and fine-tuning when applying AI to business processes - without unnecessary technical detail.
Real-time analytics: when batch is actually enough
Why most companies overpay for streaming analytics where batch processing would be cheaper and more reliable.
The xz backdoor: open source supply chain security is a topic for architects, not lawyers
A breakdown of the xz utils incident and why attacks on the open source supply chain change architectural requirements - not legal ones.
NVIDIA Blackwell and the economics of the next inference wave
What the Blackwell architecture announcement means for companies planning or already running AI systems in production: on cost, availability, and strategic decisions.