Your AI writes the code. Who attests to it?
Software supply chain security spent a decade learning to vouch for dependencies and build systems. Then an agent joined the chain and started writing the code — and that link has no attestation.
Notes on AI governance, evidence and software supply chain security. Mostly about the same stubborn question from different directions — how you prove what a system did, to somebody who was not there and has no reason to take your word for it.
Software supply chain security spent a decade learning to vouch for dependencies and build systems. Then an agent joined the chain and started writing the code — and that link has no attestation.
Proving what an AI system did without shipping the content it did it to.
Why treating the assistant as the attacker changes what a control has to do.
Reading the 2026 SANS AI Survey: the gap between owning a policy and being able to evidence it.
Content-free evidence for an AI Management System, control by control.
The questions that arrive before a purchase order, and what a defensible answer looks like.
A content-free AI inventory, and where the Act actually asks for one.
Deploying from the agent that wrote the app, without a second tool in the loop.
8 posts. Each names the product it came out of, but the blog is not a product page — if a post is useful without buying anything, it has done its job.