Why AI-Built Apps Leak Data: The RLS Boundary Nobody Wrote
One in ten AI-generated production apps in a 2025 disclosure shipped without row-level security. The cause is not the tool - it is a boundary nobody was asked to define.
Articles on AI architecture, fractional CTO leadership, and building production AI systems.
all articles, newest first
One in ten AI-generated production apps in a 2025 disclosure shipped without row-level security. The cause is not the tool - it is a boundary nobody was asked to define.
Four measurements you can run on your own Supabase project this afternoon, with the thresholds that separate a platform you can build on from one you should stop building on.
Three different things are sold under this heading and buyers conflate them. Validation specialists, governance consultancies and builders compared, with criteria.
RAG development partners compared by category, with the selection criteria published. Boutiques, dev shops, consultancies and independents - what each is actually good at.
Agentic AI development partners compared by category, with the criteria published - and the question worth asking first: do you need agents at all?
Your retrieved documents are untrusted input. What actually reduces prompt injection risk in a production RAG pipeline, and what only looks like it does.
The eval set is the durable asset and, in regulated work, the validation artefact. How to build one that is evidence rather than a spreadsheet.
A metadata filter is not tenant isolation. The four independent layers that keep one customer from retrieving another, from a live multi-tenant RAG system.
MDAG-AI up to RM2M, MSME Digital Grant MADANI up to RM5,000, and Budget 2026 AI funding - which lane fits, and how to scope a project that qualifies.
AI code fails across files, not inside diffs. Why pull-request review structurally cannot catch it, and the four repository-level measurements that can.
What Part 11 actually requires of an LLM or RAG system - audit trails, e-signatures, and validating a component that is not deterministic.
Deleting a document does not delete its embeddings, and soft delete is not erasure. How to make Article 17 work across a RAG pipeline.
LangSmith, Langfuse, Arize Phoenix, Braintrust and Datadog compared - and why the eval set you build matters more than the tool you buy.
pgvector, Pinecone, Qdrant, Weaviate and Milvus compared on the things that decide production RAG: hybrid search and metadata filtering, not benchmark speed.
AgentCore, Microsoft Foundry and Gemini Enterprise compared on framework support, tooling and governance - and why the choice now turns on data gravity.
Hybrid RAG, GraphRAG, Agentic RAG, Corrective RAG and Multimodal RAG compared on retrieval quality, reasoning, reliability and cost - with a decision guide.
How to choose a RAG development partner: the nine components a real quote covers, what SOC 2 and HIPAA change, and seven questions that expose a demo-builder.
AI agent development services for UK companies: the agent-versus-workflow test, a five-phase delivery model, and what UK GDPR and the ICO change about autonomy.
A practitioner-written guide to the top AI consultants in the US for 2026. How to compare AI architects, fractional AI CTOs, boutique firms, and Big 4 practices — by production track record, verifiable accuracy, and compliance fluency.
The Model Context Protocol hit 110M monthly downloads and 41% enterprise production adoption. What MCP actually is, why it won, where the security risks live, and how CTOs should adopt it — from an architect who builds on it in production.
A practical guide to Singapore AI funding in 2026: the National AI Impact Programme, IMDA GenAI Programme, EnterpriseSG support up to 50%, and how to structure a project that actually qualifies — from an AI architect who builds the systems these grants pay for.
A practitioner-written guide to the top AI consultants in the UK for 2026. Compare independents, boutique consultancies, and Big 4 advisories by production track record, pricing, and UK GDPR fluency.
A fractional CTO's practical playbook for enterprise AI — the first 30 days, choosing your first project, and a 90-day implementation plan.
RAG for knowledge retrieval, fine-tuning for behaviour change. A practical decision framework with cost comparisons from real projects.
Custom AI vs off-the-shelf — a practical decision framework from someone who has done both, with real cost comparisons and project examples.
A practitioner comparison of LangGraph and CrewAI — from someone who has shipped production systems with both frameworks.
What AI can do for law firms today — document review, clause extraction, compliance checking — from the architect who built the LPA Analyzer.
The London AI consulting landscape — rates, specializations, and how to evaluate an AI consultant. Written by a UK-based AI architect.
7 questions the best clients ask before hiring — from the consultant's perspective. What good answers look like and red flags to watch for.
Real pricing for AI projects from a practitioner — RAG systems, multi-agent platforms, automation, and fractional CTO engagements with actual cost breakdowns.
What agentic AI actually means, the architecture behind it, and real production examples — from a practitioner who builds multi-agent systems.
Compare the top AI consultants in Singapore by expertise, services, and track records. Includes pricing, specializations, and hiring criteria.
Compare AI consultants in Malaysia: platform vendors, research shops, independent architects and fractional CTOs - what each is genuinely best at.
Enterprise AI projects fail at an 80% rate — not because of bad models, but bad architecture. The 5 structural mistakes that account for nearly every failure.
Every career site says "designs AI systems." Here's what the role actually involves — week by week — from a practitioner who has built 13 production AI systems.
You didn't hire a bad developer. You hired a good developer for an architect's job. 7 diagnostic signs and what to do about it.
A practical comparison covering costs, responsibilities, and when each model makes sense for your business.
How enterprises are achieving 3-10x ROI from AI automation. Frameworks, case studies, and the numbers that actually matter.
A practical guide to AI implementation for Malaysian businesses with the 4-step approach that delivers ROI in 30-90 days.
A comprehensive technical guide to building production multi-agent AI systems with orchestration patterns and real deployment lessons.
A fractional AI CTO provides part-time, senior AI leadership to businesses that need strategic technology direction without the cost of a full-time hire.
A deep technical guide to production RAG with hybrid search, pgvector, temporal intelligence, and enterprise-grade chunking strategies.