// writing

Blog

Notes on AI governance, evidence and software supply chain security. Mostly about the same stubborn question from different directions — how you prove what a system did, to somebody who was not there and has no reason to take your word for it.

Your AI writes the code. Who attests to it?

Software supply chain security spent a decade learning to vouch for dependencies and build systems. Then an agent joined the chain and started writing the code — and that link has no attestation.

MoorAI & ISO/IEC 42001

Content-free evidence for an AI Management System, control by control.

8 posts. Each names the product it came out of, but the blog is not a product page — if a post is useful without buying anything, it has done its job.

glick.run — AGPL-3.0