IrisNoir Essays · Food for Thought

Two Strands

Short pieces on the things I keep circling back to. One strand holds a very old book about forbidden knowledge against the newest technology we have — it's also the teaser for the fantasy series it's becoming, The Great Judgment. The other tracks what's actually happening in AI security research. They meet more often than you'd think.

Written with AI assistance

Section One

Where the Book of Enoch
and Stoicism Meet

A very old book about forbidden knowledge, a school of philosophy about what's actually in your control, and the newest technology we have. Enoch asks who is answerable; the Stoics ask what you'll do about it before dinner. You need both, and for different hours of the day.

Essay 01

Azazel Was the First Engineer

The watchers of Enoch weren't damned for lying — everything they taught was true. They were damned for not waiting. Knowledge arrived; wisdom was still in transit.

They did not fall because they flew too high. They fell because they taught.

In the Book of Enoch, two hundred watchers descend to look at the daughters of men, and what damns them is not desire but curriculum. Azazel teaches the making of swords and knives and shields — and then, in the same breath, the working of antimony into eyeshadow and the beautifying of the eyelids. Baraqijal teaches astrology. Kokabiel, the constellations. Others hand over enchantments, root-cutting, the reading of signs. The text lists it like an indictment, and the strange thing about the indictment is what is missing from it.

Nowhere does Enoch say the knowledge was false.

The sword works. The mirror works. Antimony really does darken a lash line, and the stars really do wheel in the order the watchers described. Nothing taught on that mountain was a lie, and this is precisely the problem. Had it been falsehood, the remedy would be simple — correct the record and move on. But the gift was genuine, and genuine gifts are much harder to return.

What Enoch condemns is arrival without accompaniment. Azazel gave men the blade and the mirror, and the sin was not the metal, nor the reflection. It was the speed. Knowledge arrived; wisdom was still in transit.

I have been thinking about this because I now work beside a machine that finishes my sentences.

Not badly, either. It finishes them the way a very well-read colleague might, and often it finishes them better than I would have, and there is a particular species of vertigo that arrives the third or fourth time you accept a suggestion you did not think of. The capability is real. Nobody is lying to me. That is the whole difficulty.

We received an extraordinary gift in an extraordinarily short window. A person who could not draw in January can produce competent illustration by March. A person who could not write can produce clean prose by Tuesday. A person who could not code can ship something that runs. This is not a con; it is a transfer, and it happened faster than any culture's capacity to metabolize what it means to be the person who used to do that work.

Enoch's watchers at least had the decency to descend one at a time.

The frameworks we would need — how to attribute, how to price, how to say this part was mine without either shame or overclaim — those frameworks are being drafted right now, in public, badly, by people who are already using the tools they are trying to describe. Knowledge arrived. Wisdom is still in transit.

Seneca, writing to Lucilius, keeps returning to a distinction we have almost entirely lost: the difference between can and may. He is not interested in capability. Capability bores him. He assumes you can do the thing — poison the rival, flatter the emperor, take the inheritance — and moves immediately to the only question he considers serious, which is what doing it makes of you.

The ability to do a thing has never once been permission to do it. That sentence would have been unremarkable to a Roman and is somehow radical now, in an industry whose default posture is that anything technically achievable is therefore inevitable and therefore, quietly, fine.

Epictetus goes further, and colder. He would hear the whole complaint — the watchers, the transfer, the speed, my vertigo at the finished sentence — and he would be unmoved by nearly all of it. You have described a flood you cannot dam, he would say, and called it a tragedy. The sword is indifferent. The mirror is indifferent. Only the hand, and the man behind it, are yours.

This is not comfort. It is a reassignment. The Stoic move is to take the enormous, unanswerable, civilization-scale question and hand back the only fragment of it you actually own, which is your own conduct in front of the machine on an ordinary Tuesday afternoon.

So the two texts disagree, and the disagreement is the useful part.

Enoch says: something was done to us, from above, by parties who knew better and did it anyway, and there will be an accounting. It is a book about culpability. Somebody taught this. Somebody is answerable.

Stoicism says: the accounting is yours, and it is due continuously, and it concerns a much smaller territory than you would like. Nothing about the flood is in your control. Everything about how you meet it is.

You need both, I think, and for different hours of the day. Enoch for the question of who built this and who profits and who was consulted — because "the tool is indifferent" becomes a moral anesthetic the moment it is used to excuse the people who chose which tool to build. Stoicism for the hours after that question closes, when the thing exists regardless and you must still decide what you personally will do with it before dinner.

The watchers were answerable. So am I. These are not competing claims.

Which leaves the uncomfortable question, and I would rather ask it than end on something tidy.

Enoch's watchers are not villains in any satisfying way. They are teachers who did not wait. They saw a species that could clearly handle metallurgy — look how quickly they learn! — and they mistook capacity for readiness, which is the oldest error in pedagogy and the current business model of an entire industry.

I use these tools. I am writing this with help. I am not standing outside the transfer pointing at it; I am inside it, accepting suggestions, and the essay is better for it and that is exactly what troubles me.

So: who plays watcher now?

Sometimes it is obviously the labs — descending with capability, publishing the curriculum, declining the accounting. But sometimes, on a Tuesday, it is me. I teach the thing to a friend who did not ask for it. I hand a colleague a shortcut that quietly deletes the part of the job she was proud of. I give someone a gift they will still be paying for in a year, and I do it warmly, because it is a genuinely good gift and I am glad to be able to give it.

Azazel, as far as the text tells us, thought he was being generous too.

Essay 02

The Craft Was Never Yours

Enoch's smiths were handed a craft that outran them. Epictetus says your work was never in your control — only your industry. True, and dangerous: it's a discipline for the one losing the trade, never an excuse for the one taking it.

The watchers taught men to forge, and the forging made them capable of things they had no framework to govern. Read that as a labor story and it stops being mythology: it is the position of anyone whose trade was automated before their pension matured. Enoch's complaint is not that the craft was bad. It is that the craft outran the people who were promised a life inside it — that a skill you spent twenty years earning can be handed to a stranger in an afternoon, and the stranger will not even know what he was given.

Epictetus would answer this coldly, and I think correctly, and I do not entirely want him to be right. Your work was never in your control. Only your industry was. The market for what you make, the tools that make it cheaper, the tastes of the people who buy it — none of that was ever yours, and you only felt it was because the arrangement held still long enough to be mistaken for a promise. What is yours is the quality of your attention on the day. That is a smaller inheritance than the one you thought you had, and it is the only one that cannot be automated out from under you.

But there is a line the Stoics will not let us cross, and it matters here. "Your work was never yours" is a discipline for the person losing it, not an excuse for the person taking it. Enoch keeps the ledger the Stoics decline to keep: someone chose to teach this, someone profited, and nobody asked the smiths. Hold both. Do your work as though the outcome was never owed to you — and refuse, absolutely, to tell someone else their loss is simply the flood arriving.

Essay 03

The Children of Two Kinds

The Nephilim belonged to neither parent, and Enoch can't decide if they're monsters or victims. Everything made half by a person and half by a model is a child of two kinds — and we are still inside our judgment, not past it.

The strangest passage in Enoch is not the teaching. It is what the teaching produced. The watchers came down, and there were children — the Nephilim, offspring of two kinds, belonging fully to neither. The text cannot decide whether they are monsters or victims, and that indecision is the most honest thing in the book. They did not ask to be hybrid. They simply arrived, enormous and unplaceable, in a world with no category for them.

We are producing that generation now, and I mean it literally rather than poetically. Every image, essay, song and film made half by a person and half by a model is a child of two kinds. Ask who made it and the honest answer is a sentence, not a name. The instinct is to force it back into one category or the other — it's just a tool, so it's fully mine or a machine touched it, so it's worthless — and both are lies of convenience, told to avoid the discomfort of holding something genuinely mixed.

Enoch has no mercy for the Nephilim; the flood takes them. But Enoch is a book about a judgment that already happened. We are still inside ours, which means the question is not whether the hybrid thing deserves to exist. It is here. It is this. The question is whether we will say honestly which half was ours — and whether, when the accounting comes, we were the parent who stayed to raise what we made, or the watcher who taught the trick and went home.

Essay 04

The Cutting of Roots

Enoch condemns the watchers for teaching medicine. Not poison — medicine. The hospital that refuses AI on HIPAA grounds thinks it is being careful; it is being taught by its own staff instead.

Among the things the watchers taught, and among the things Enoch counts against them, is the cutting of roots.

It sits in the indictment beside the making of swords, which is the line most people remember, and beside the working of antimony into eyeshadow, which is the line most people find strange. Weapons, cosmetics, herbalism. The list reads like an accident until you notice the pattern: every one of them is a genuine capability, handed down complete, to people with no framework for governing it. Root-cutting is medicine. It is the knowledge of which plant lowers a fever and which one stops a heart, and it is the same knowledge — that is the whole problem. The watchers were not condemned for teaching poison. They were condemned for teaching healing without teaching restraint, and for assuming those two arrive on the same boat.

They do not. They never have.

I keep thinking about this because I have spent months reading how hospitals are handling AI, and the shape of the failure is the same shape, precisely, in a room with fluorescent lighting and a compliance officer in it.

The refusal is not the safe position

Here is what the conversation sounds like in most health systems right now. Leadership is genuinely interested — ambient documentation could return hours a week to physicians who are drowning in charting, and physician burnout is not a soft problem, it is a patient-safety problem. And then someone says HIPAA, and the room settles, and the decision is deferred to a committee that will meet again in the spring.

Everyone leaves feeling careful.

They are not being careful. A 2026 survey found 57% of healthcare professionals already using unauthorized AI tools to process protected health information — SOAP notes, diagnostic plans, billing summaries — in tools with no business associate agreement, no audit trail, no minimum-necessary enforcement. The hospital owns the disclosure obligation regardless, because the workflow is happening inside the hospital's four walls on the hospital's time. Twenty percent of organizations globally reported a breach in the past year tied to exactly this: shadow AI, meaning employees using AI outside any governance structure at all.

So the choice was never AI or no AI. That decision was made months ago, at 11pm, by a hospitalist with sixteen notes left and a tool that finishes sentences. The only live choice is whether the institution governs what its people are already doing, or continues to describe its ignorance as caution.

This is the part of Enoch nobody quotes. The watchers descended and taught, and the text is furious about it — but nowhere does Enoch suggest the men should have refused to learn. The knowledge was already loose. The complaint is about accompaniment: that the teaching came without the framework, that the gift arrived unattended. The remedy for a gift that arrived unattended is not to pretend it didn't arrive. It is to build the attendance, late, in public, badly at first.

What HIPAA actually says, as opposed to what everyone thinks it says

There is no provision in the Privacy Rule or the Security Rule that prohibits machine learning. Not one. What the law says is that any vendor who creates, receives, maintains, or transmits PHI on your behalf is a business associate under 45 CFR 160.103 and must be bound by an agreement with enforceable terms.

A model is a vendor. Treat it like one and most of the fog burns off.

The real obstacle is rarely the statute. It is that most institutions cannot currently produce the artifact that regulators ask for — a record showing who accessed which PHI, in what context, under what authorization. That gap predates AI entirely. AI simply makes it legible and expensive. Which is, if you are the person who has to fix it, arguably a gift.

The architecture, which is just triage

The instinct is to approve tools one at a time. This is a treadmill you lose, because there will always be another tool and it will always arrive faster than your committee. Classify the data instead, and let the classification decide where it may be processed.

Tiered AI architecture diagram — Classify the data, not the tool. Tier 0 (no PHI, admin and education) routes to reviewed vendor SaaS; Tier 1 (de-identified, safe-harbor stripped) routes to a BAA cloud tenant with zero retention and no training; Tier 2 (full PHI — charts, labs, imaging) routes to an in-boundary model in a private VPC or on-prem. All three feed one AI gateway for audit and policy enforcement: every prompt logged, minimum-necessary enforced, one egress point.
Classify the data, not the tool — three tiers over one audited gateway.

Three tiers, one gateway. The tiers are the triage; the gateway is the thing that makes the triage real rather than aspirational. Tiering without an enforcement point is a policy memo, and policy memos lose to exhaustion every single time.

Tier 0 — no PHI. Prior-authorization letter drafting from templates. Coding-guideline lookup. Policy summarization. Staff education. Start here, in month one, with the gateway already logging even though nothing sensitive is flowing through it yet. You want the instrumentation proven before it matters.

Tier 1 — de-identified. Cohort analysis, quality-improvement summaries, research feasibility. Safe Harbor under 45 CFR 164.514(b)(2) means stripping all eighteen identifier categories; Expert Determination is the alternative when Safe Harbor destroys the clinical utility you needed in the first place. Redact before inference, re-hydrate after, log both operations. This is the tier where you discover your redaction pipeline fails — and it will fail — under conditions you chose.

Tier 2 — full PHI. One workflow. Ambient clinical documentation or discharge summaries: high clinician value, bounded scope, human review already native to the process. Human sign-off before anything reaches the legal medical record. Always. Not as a compliance gesture — as the actual point.

The six things I would not sign a contract without: a BAA that names the entire inference chain (model host, API gateway, vector database, observability platform — every subprocessor, and if the vendor won't list them, that is your answer); contractual zero retention and no training on your data, because a settings toggle is not a control; FIPS-validated encryption at rest and in transit; attribute-based access control inherited from your existing identity provider, so the model can never read a chart its user couldn't; immutable, tamper-evident logging of prompts and outputs; and a de-identification pipeline you own rather than one you trust.

That last one deserves its own sentence. Do not rely on the model to not remember. If PHI enters a training set it becomes part of the weights, and weights do not have a delete key.

The clock, honestly

The Security Rule overhaul proposed on January 6, 2025 would mandate encryption outright, require multi-factor authentication, add annual penetration testing and 72-hour incident reporting, and strip the old “addressable” flexibility that let institutions document why they'd skipped a control. It is still a proposed rule. OMB's agenda has slipped final action to roughly July 2027, and a coalition of more than a hundred hospital and provider groups has asked HHS to withdraw or narrow it, arguing the cost estimates are fantasy for rural and under-resourced providers. They may be right about that.

Two things follow, and they point the same direction. The current Security Rule remains fully in force and actively enforced, with willful-neglect penalties running to tens of thousands of dollars per day, per violation. And every control in that NPRM is already what cyber insurers require, already what auditors ask about, already what any competent security program would have built anyway. Building to the proposed standard costs nothing if it's withdrawn and saves a panic if it isn't.

Waiting for the regulation to finalize before acting is a way of asking someone else to hold the accounting. That request is always denied.

The uncomfortable part

I want to end where Enoch does, which is not on a solution.

The watchers are not villains in any satisfying way. They saw a species that could clearly handle this — look how quickly they learn — and mistook capacity for readiness. Every vendor demo in a hospital conference room right now is making the identical error, warmly, in good faith, with a genuinely useful product. And the physician pasting a case summary into a consumer chatbot at midnight is not defying policy. She is meeting an impossible documentation burden with the only instrument that reduces it, and she is right that the instrument works.

That is what makes this hard. Nobody in the story is lying. The tool works. The root cures the fever. Enoch's whole point is that this is precisely when the accounting matters most, because a gift that doesn't work gets abandoned on its own — it's the gift that works that gets adopted before anyone has decided who is answerable for it.

So: who plays watcher in a hospital? Sometimes the vendor, descending with capability and declining the audit trail. Sometimes the board, deferring to spring. And sometimes — this is the one I'd sit with — it's the security director who builds a compliant path so slow and so gated that no clinician will ever use it, and then points at the shadow AI numbers as proof that clinicians can't be trusted.

The watchers were answerable for what they taught. So is anyone who makes the safe path the hard one.

Sources: ISC2 2025 Cybersecurity Workforce Study; IBM shadow-AI breach data via ESET; HHS Office for Civil Rights NPRM, 90 FR 800 (January 6, 2025); 45 CFR 160.103, 164.410, 164.502(e)(1)(ii), 164.514(b)(2), 164.308(a)(1)(ii)(A); CISA/NSA/FBI joint guidance on AI data security and the careful adoption of agentic AI.

Essay 05

The Mirror Kept What It Saw

Azazel taught the working of antimony into eyeshadow — the smallest, most domestic item on the indictment. It is also the only one that watches you back. What you type into a chat box is not a diary. It is a postcard.

The strangest item in Azazel's curriculum is the eyeshadow.

Swords make sense as an indictment. Shields, knives, the working of metal — you can see how a text about judgment would put those on a list. But then, in the same breath, without a pause for the change of register, Enoch says he taught them antimony and the beautifying of the eyelids. Cosmetics. The mirror.

I used to read that as the text being fussy. I don't anymore. The sword is the capability you notice; the mirror is the one you live inside. It's smaller, more intimate, used alone, used daily, used in the half-lit private moment before you go out and meet people. And it's the only item on the list that shows you back to yourself — which means it's the only one that knows something about you.

We have built a mirror that keeps what it saw.

What actually happens when you type

Not a metaphor, this part. The mechanics.

Free and standard-tier consumer AI chats are frequently stored indefinitely unless you actively delete them. When you do delete them — or use the “temporary” mode that implies nothing is being kept — a copy is generally retained on the backend for something like thirty to ninety days for abuse and safety review. That is not a scandal. It's a reasonable design decision by people trying to stop the tool being used for harm. It is also just true, and worth knowing.

And “delete” has already been tested as a promise rather than a gesture. In a 2025–2026 US case, a court ordered a major AI provider to preserve twenty million user chat logs for litigation, including chats the users had deleted. Nobody misled anyone. The company's deletion policy simply met a subpoena, and the subpoena won, as subpoenas do.

So here is the mental model that does the most work, and it fits on one line: a chat box is a postcard, not a diary. Not because someone malicious is reading it. Because of where it physically goes and who can lawfully ask for it later.

That is not an argument for abstinence. I use these tools constantly and this essay was written with one. It's an argument for being deliberate about which sentences you type — which is a much smaller ask than the privacy discourse usually makes, and much more achievable.

Sort it before you send it

Three tiers of personal data for AI prompts — Before you type it, sort it. Never type this into any AI: government ID, card and account numbers, passwords, medical record numbers. Only with settings locked down, and generalised first: health symptoms, legal trouble, employer details, family names, your address. Fine to share freely: public facts, recipes, code, general questions, writing you would publish anyway.
Before you type it, sort it — the red tier is short on purpose.

The red tier is short on purpose. Government ID numbers, full card and bank account numbers, passwords and credentials, medical record numbers. There is no productivity gain on the other side of typing any of those that justifies the exposure. This is not a judgment call; it's a hard line you decide once and then never re-litigate at 1am.

The amber tier is where actual life happens, and where the useful skill lives — so let me be concrete, because “be careful with sensitive data” is advice that has never once changed anyone's behavior.

Generalise before you type. You do not have to give up the hard, human, genuinely valuable uses. You have to strip the identifiers, which is exactly what a hospital does before it lets a model near a chart.

  • Not: “My mom Susan Chen, DOB 3/14/51, was just diagnosed with stage 2 pancreatic cancer at Mass General — what should I ask Dr. Rivera on Thursday?”
  • Instead: “What questions should a family ask an oncologist after a stage 2 pancreatic cancer diagnosis in an elderly patient?”

You get the same answer. You have disclosed nothing. The second version is not more cautious in some abstract way — it is identical in usefulness and different in exposure, which is the only kind of security advice that survives contact with a tired person.

Same move everywhere. Confused by a lease clause? Paste the clause, not the document with your address and your landlord's name on it. Want spending categorised? Paste the transaction lines with the account number and your name stripped. Roughly one in five file uploads to consumer AI tools contains sensitive data the user didn't consciously register as sensitive — and it is almost never the prompt someone agonised over. It's the screenshot. It's the PDF dragged in without being opened first.

Five minutes, once

  • Turn off training on your data. Every major provider has this switch, under data controls.
  • Turn off or shorten chat history and memory. Memory is convenient and it is also a profile of you that grows quietly and that you will never read.
  • Don't stay logged into an AI in the same browser where you bank, or use a separate profile. Chat contents can sit in browser local storage, which is precisely where info-stealer malware goes looking.
  • Put a real password and two-factor authentication on the account. Your chat history is now a sensitive document store; protect it like one.
  • Think for a full minute before connecting an AI to your email or your files. The convenience is real. So is the scope of what you just handed over.

The agent is a different animal

The newer modes — the ones that browse, click, and act in your accounts — are worth their own paragraph, because they are not “chat, but better.” To function, they capture what is on your screen, and those screenshots have been documented as retained for up to ninety days: longer than your chat, and regardless of whether you deleted the session afterward.

The rule is simple. Never let an agent run while your banking dashboard, password manager, or medical portal is open. Close the tab first.

I like that the institutional version of this advice is identical. CISA, the NSA, the FBI and allied agencies published guidance in 2026 on the careful adoption of agentic AI, and its core recommendations are: don't grant broad or unrestricted access, start with narrow use cases, and require a human checkpoint before autonomous action on anything sensitive. That's a national security agency and a person at a kitchen table arriving at the same three sentences. When advice scales that cleanly across six orders of magnitude, it's usually because it's true.

What will actually come for you

Not the chatbot. The people using one.

Phishing in flawless English. A voice on the phone that sounds like your daughter, built from four seconds of a video she posted. Fake job offers, romance scams, invoice fraud — all of it now produced at volume, with the old tells gone. The UK's NCSC has been direct about this: AI has sharply lowered the technical barrier to a convincing scam, and jailbreak-as-a-service kits sold on the dark web have lowered it further. Bad grammar was never a security control. It was just a gift, and it's been withdrawn.

Replace the vanished tell with a procedure, because procedures survive panic and instincts don't. Verify through a second channel that you chose. Your daughter calls in distress from an unknown number — hang up and call the number already saved in your phone. Your bank texts about fraud — don't use the link; call the number on the back of the card. Agree a family code word this week. It costs nothing and it defeats a voice clone completely, which is a rare ratio in this field.

What is actually protecting you

Less than you'd hope, and unevenly. In the EU, the AI Act's high-risk obligations began applying on August 2, 2026. In the United States there is no comprehensive federal AI privacy law — you are relying on a patchwork of state statutes, the voluntary NIST AI Risk Management Framework, and enforcement actions after the fact. Which means your protection currently depends on which company's app you happened to open and which state you happen to live in.

Assume the floor is low. Set your own.

The Stoic bit, briefly, because it's the only part that's yours

Epictetus would hear this whole essay — the retention policies, the twenty million preserved logs, the court orders, the voice clones — and be almost entirely unmoved. You have described a flood you cannot dam, he'd say, and called it an injustice.

He'd be right about the reassignment, and it's the useful part. You do not control what the provider retains. You do not control whether a judge orders preservation, or what the next model can do with four seconds of your voice, or whether Congress passes anything. The territory you own is embarrassingly small and completely sufficient: which sentences you type, which settings you set once and forget, and whether you hang up and dial the saved number.

That's it. That's the whole domain.

Enoch keeps the other ledger — who built this, who profits, who was consulted, who is answerable — and that ledger matters, because “the tool is indifferent” turns into a moral anesthetic the moment it's used to excuse the people who chose which tool to build. But that accounting runs on its own clock, in courts and committees, over years. Yours is due tonight, on an ordinary Tuesday, in the two seconds before you paste something into a box.

The mirror was always going to be the smaller gift. It's just the one you'll pick up every day for the rest of your life.

Sources: ESET 2026 ChatGPT security and privacy guide; UK NCSC guidance on AI-enabled cyber threats; CISA, ASD ACSC and international partners, “Careful Adoption of Agentic Artificial Intelligence Services” (2026); NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile; EU AI Act, high-risk obligations effective August 2, 2026; Bruce Schneier on AI and trust.

Section Two

AI Cybersecurity:
Current Research

The second strand: what's actually happening where machine learning meets security — the workforce gap, AI-driven attacks, what happens to the data you type into a chat box, and the frameworks trying to catch up. Two essays, each with a data visual. This strand tracks a moving field, so every piece is dated and revised as the research changes.

AI-assisted, human-verified

Essay 01

The Current Landscape

Last updated

A 4.8-million-person workforce gap, an 87% AI-attack exposure rate, and a patchwork of frameworks phasing in on different clocks. The knowledge has clearly arrived; the record is what it looks like while the wisdom catches up.

There's an old observation about forbidden knowledge: the danger was never that the knowledge was false. The sword worked. The mirror worked. The danger was that capability arrived before anyone had built the institutions to hold it responsibly. Reading through this year's cybersecurity data, it's hard not to notice the same gap opening up again — not in myth, but in workforce reports and breach disclosures.

A field running ahead of the people meant to staff it

The global cybersecurity workforce gap sits near 4.8 million unfilled roles, according to ISC2's 2024 Workforce Study. What's more telling than the number itself is what happened next: for the first time in the study's history, ISC2 declined to publish a fresh 2025 gap figure. Not because the problem eased — 95% of respondents now report a critical skills need, and 88% experienced a significant security event tied directly to a skills shortage in the past year. The gap didn't close. It became too unstable to summarize in a single figure.

Layered on top of that shortage is a threat landscape that has visibly changed character. Eighty-seven percent of organizations reported experiencing an AI-driven cyberattack in the past year, per CybersecurityGuide.org's 2026 analysis of ISC2 data. That statistic marks a shift worth sitting with: “AI threat” is no longer a speculative category security teams plan around for someday. It is, for most teams, already the majority experience. Unsurprisingly, AI/ML defense has become the number one cited skills need among hiring managers — 41%, up from 34% the year before — ahead of cloud security and security engineering, the categories that used to top these lists by default.

Governments are treating this as more than a vendor talking point. In mid-2026, the Five Eyes intelligence alliance — the US, UK, Canada, Australia, and New Zealand — jointly warned about AI models' growing ability to autonomously discover and exploit software vulnerabilities, a capability that used to require a skilled human operator sitting at a keyboard. Bruce Schneier, the Harvard Kennedy School cryptographer whose commentary shapes much of the field's public conversation, has described the resulting environment plainly: “We're moving into a world of untrusted systems.” He's also cautioned people directly against entrusting sensitive information to AI tools, pointing to a landscape where AI agents increasingly act on their own — making decisions, taking actions, dealing with other agents — without the trust infrastructure to match.

Existing AI risks, 2026 — the numbers behind this essay. Open full size →

What it means for the person, not just the enterprise

Most public discussion of “AI risk” jumps straight to speculative, headline-grabbing scenarios and skips the exposure that is already live for ordinary users typing into a chat box. That's a mistake, because the everyday risk is well documented and concrete.

Free and Plus-tier consumer AI chats are often stored indefinitely unless a user actively deletes them — and even “deleted” or “temporary” chats are frequently retained on the backend for 30 to 90 days for abuse and safety review, per ESET's 2026 ChatGPT security guide. Agentic AI features that browse or act on a user's behalf raise the stakes further: they can capture screenshots of whatever is on screen, including banking dashboards or credential fields, and retain them for extended periods regardless of whether the session itself was deleted. Litigation has already tested the limits of “delete” as a promise rather than a UI gesture — a 2025–2026 US court order required a major AI provider to preserve 20 million user chat logs for a legal case, even for users who had deleted them.

The scale of casual exposure is significant: industry analyses estimate that roughly one in five file uploads to consumer AI tools contains sensitive personal or corporate data the user didn't fully register as sensitive in the moment. The 2023 Samsung incident, in which engineers pasted proprietary source code into ChatGPT and triggered a company-wide ban, remains the canonical cautionary case in 2026 guidance for exactly this reason. And it isn't only individuals absorbing the risk on their own behalf: twenty percent of organizations globally reported a data breach in the past year tied to “shadow AI” — employees using AI tools outside any governance or awareness structure, per IBM data cited by ESET.

The frameworks trying to catch up

Regulation is arriving, but unevenly, and mostly after the exposure it's meant to address. NIST's AI Risk Management Framework, released in January 2023 and expanded with a Generative AI Profile in mid-2024, has become the closest thing the US has to a national standard — voluntary, organized around four functions (Govern, Map, Measure, Manage), and increasingly the operational layer underneath other countries' and companies' compliance programs.

The EU AI Act is more binding: the world's first comprehensive AI law, in force since August 2024, with high-risk system obligations applying from August 2, 2026 — a date now arriving in real time. CISA, the NSA's AI Security Center, the FBI, and Five Eyes partners issued joint guidance in 2025–2026 on AI data security and, more recently, on the secure adoption of agentic AI, explicitly warning organizations against granting AI agents broad, unrestricted access to sensitive systems. OWASP's Top 10 for LLM Applications, and its newer Top 10 for Agentic Applications released in December 2025, has become the closest thing to an industry-standard technical checklist, with prompt injection and sensitive information disclosure at the top of the list.

International alignment is converging but far from uniform. The OECD AI Principles, ISO/IEC 42001, the G7 Code of Conduct, and the Council of Europe's AI Convention are all trending toward NIST-style structure, while China runs its own content-safety-filtering regime and Japan passed its first comprehensive AI law in 2025, deliberately light-touch by design.

None of this closes the gap between what the technology can do and what the institutions around it are prepared to govern. But naming the gap accurately — a 4.8-million-person workforce shortage, an 87% AI-attack exposure rate, a patchwork of frameworks phasing in on different clocks in different countries — is the first honest step toward closing it. The knowledge has clearly arrived. The record above is what it looks like while the wisdom is still catching up.

Essay 02

Capability Without Governance

Last updated

The superintelligence-risk argument, stated carefully and with real sources — then the guardrails actually being proposed. The gap between capability and governance doesn't close by decree. It closes by maintenance.

Every generation that receives a powerful new tool faces the same two-part question: can this be done, and may it be done responsibly. The gap between those two questions — capability outrunning governance — is the throughline of this essay, applied to the specific and current case of advanced AI.

Taking the extreme case seriously, without exaggerating it

It's tempting to treat catastrophic AI risk as either science fiction or marketing hype from companies that benefit from sounding dangerous. Neither dismissal survives contact with who is actually making the argument and how carefully they're making it.

The Center for AI Safety's 2023 statement was deliberately one sentence: “Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war.” It was signed by, among hundreds of others, Geoffrey Hinton and Yoshua Bengio — the two most-cited living AI researchers and both Turing Award winners — and, notably, by the CEOs of OpenAI, Google DeepMind, and Anthropic. That's not a statement from outside critics warning about a technology someone else is building. It's a statement from the people building it.

In the 2025 International Scientific Report on the Safety of Advanced AI — a UK-government-convened synthesis that functions as something close to an IPCC report for AI risk — Bengio and co-authors catalogued loss-of-control scenarios and AI-assisted biological or chemical misuse among the concerns the field takes seriously, not fringe positions confined to a vocal minority. Stuart Russell, the UC Berkeley professor whose textbook trains most of the field, has put the underlying mechanism plainly: “If we pursue [our current approach], then we will eventually lose control over the machines.”

In October 2025, the Future of Life Institute organized a statement calling for a prohibition on the development of superintelligence until there is broad scientific consensus it can be done safely, with public buy-in. By early 2026 it had drawn more than 133,000 signatories spanning Hinton, Bengio, Russell, multiple Nobel laureates, national-security figures including a former US Joint Chiefs Chairman, and voices from across the political spectrum — itself a signal that this isn't a niche or partisan concern.

The honest picture is one of informed uncertainty rather than prophecy. A 2023 survey of researchers at top AI conferences found 38% assigning at least 10% odds to an extremely bad outcome — up to human extinction — conditional on AI matching or exceeding human performance broadly; separate polling from 2024–2026 clusters around a roughly 14% average estimate. Timelines are shifting fast and genuinely disputed: Bengio's 2023 estimate put superintelligence within roughly 5 to 20 years with high confidence; Hinton in 2024 put the odds at about 50% within 20 years; and public forecasting aggregates for AGI moved from an average estimate of 2055 in 2020 to under a decade out by 2026. That compression is itself part of the story — not proof of anything, but a measure of how quickly informed opinion is updating.

What matters for this essay is the shape of the argument, not the specific probability. None of these researchers claim the technology is fake or that its benefits aren't real. They argue that capability without accompanying governance is the actual danger — the same distinction between what can be done and what may be done responsibly, now being made by Turing Award winners in a scientific report rather than in a private letter.

What accompaniment could actually look like

If the risk is capability outrunning governance, the proposed solutions are, almost by definition, attempts to let governance catch up — at both the individual and institutional level.

Proposed solutions — the NIST cycle, individual vs. organizational guardrails, and the policy calendar. Open full size →

At the individual level, the guidance is more actionable than it might sound. Default to the most privacy-preserving setting on any AI tool — no training on your data, chat history off — and treat that as a floor, not a guarantee, since deletion promises have already been overridden by litigation once. Keep a hard mental category of data that never goes into a prompt: government IDs, full financial account numbers, medical record numbers, passwords and credentials. Be specifically deliberate about agentic or autonomous AI features — the ones that click, browse, or transact on your behalf — since they carry materially more exposure than a plain chat window. And treat AI-generated threats like deepfake voice calls, AI-written phishing, and jailbreak-as-a-service kits sold on the dark web as mainstream rather than exotic; the UK NCSC and 2026 guidance broadly agree that the technical barrier to a convincing scam has dropped sharply.

At the institutional level, NIST's four-function cycle — Govern, Map, Measure, Manage — is the plain-language version of “know what you're building, know what could go wrong, test for it, and keep adjusting.” It has become the closest thing to a common vocabulary across US, EU, and allied frameworks, which matters because a shared vocabulary is a prerequisite for coordinated response, not a bureaucratic nicety. Runtime guardrails at the infrastructure layer — detecting prompt injection, filtering sensitive data leakage, enforcing topic and policy boundaries — are increasingly treated as baseline rather than optional, especially with the EU AI Act's high-risk obligations landing in August 2026. CISA, NSA, and FBI guidance on agentic AI specifically counsels avoiding broad or unrestricted system access, starting with narrow use cases, and requiring human checkpoints before autonomous action on sensitive systems.

Bengio and his co-authors went further in 2025, proposing concrete institutional steps: model registration for frontier systems, whistleblower protections, incident reporting requirements, and dedicating a meaningful share — they suggested roughly a third — of frontier AI R&D budgets specifically to safety research rather than capability alone.

What's worth noticing across all of this is that none of it is a one-time compliance exercise. A framework like NIST's isn't a box checked once and filed away; it's a practice repeated continuously, adjusted as the technology and the threat landscape shift under it. The accounting is not a verdict rendered once — it's due continuously, on an ordinary Tuesday, in the same way any discipline worth keeping requires. That's not a comforting conclusion, but it is an honest and workable one: the gap between capability and governance doesn't close by decree. It closes by maintenance.

The Enoch & Stoics essays are the philosophical spine of a fantasy series in progress.

Enter The Great Judgment → Back to IrisNoir