Blog

Latest insights, tutorials, and updates on LLM engineering, observability, and GenAI application development.

OWASP LLM Top 10: attack-class mapping to runtime ABV controls

OWASP LLM Top 10: attack-class mapping to runtime ABV controls

If you are mid-evaluation on a GenAI guardrail stack, the OWASP Top 10 for LLM Applications looks like the cleanest way to score vendors. It is not. The taxonomy enumerates ten risk categories, but ticking ten boxes on a vendor slide tells you nothing about where the runtime decision happens, what the audit log will look like when your reviewer opens it, or which categories the vendor cannot actually enforce.

14 min read
Governance-only vs runtime enforcement for GenAI: when monitoring is not enough

Governance-only vs runtime enforcement for GenAI: when monitoring is not enough

If you are responsible for an AI deployment in 2026, the choice in front of you is not whether to do AI governance. You already have one. The harder question is whether your governance stack also blocks unsafe prompts and outputs at request time, or whether it only documents that you know it should.

13 min read
EU AI Act compliance checklist (2025–2027)

EU AI Act compliance checklist (2025–2027)

Europe’s AI law is no longer theoretical. Key obligations already started on February 2, 2025, with more biting from August 2, 2025 and August 2, 2026; high‑risk systems embedded in regulated produ...

5 min read