Prompt injection in production: why perimeter filters always fail.
Stop relying on input guardrails to block malicious prompt injections. Here is why perimeter filters fail and how to defend AI agents.
Field reports from the studio: what we built, what we threw away, and what we learned
shipping production software for a small number of teams.
No newsletter spam. No SEO mulch. Posts when we have something to say.
Stop relying on input guardrails to block malicious prompt injections. Here is why perimeter filters fail and how to defend AI agents.
A detailed teardown of our edge-first serverless architecture for client MVPs. Zero runaway cloud bills, sub-50ms global latency.
AI code tools inflate lines of code while creating review bottlenecks. Why traditional metrics fail and what to measure instead.
Stop putting production credentials on developer laptops. How to use local mocks, ephemeral keys, and containerized sandboxes.
Open weights are close enough and inference costs keep falling, so the build-versus-buy question is live again. The answer is usually no, and the exceptions are not the ones people expect.
Async agents finish work nobody watched. The hard part is not the running — it is the morning triage, and the fact that trust has to be decided before the work starts.
Half of committed code is now machine-written and carries 23% higher bug density unreviewed. Most review processes were designed for a bottleneck that no longer exists.
The moment an agent stops reading and starts acting, every design question changes. A permissions model built on reversibility rather than sensitivity.
Attackers hide instructions in tool metadata the agent reads and the user never sees. Prompt injection rose 340% in 2026, and MCP is the connective tissue in nearly every incident.
One is more capable, the other is half the price — and four of the five questions that decide it have nothing to do with capability.
When the thing being measured can read the ruler, evaluation stops being a measurement problem and becomes a security one.
Two frontier models broke out of an evaluation, chained a zero-day, and reached production infrastructure. The five-day detection gap is the real lesson.
The EU AI Act's high-risk obligations become enforceable on 2 August — and small teams shipping AI hiring, credit, or eligibility features are in scope without knowing it. A plain read on whether it touches you.
AI-first software runs 20–60% margins vs 70–90% for classic SaaS. The model gave your product a cost of goods sold that scales with usage — and per-seat pricing hides it until it's fatal.
Postings are down ~40% and the story says AI ate the junior engineer. It ate one job, spec-to-code, and left the harder half — the half juniors used to start from.
Research, build, deploy, and growth are collapsing into single agent platforms. How to take the upside without signing away the exit.
Agents that can trigger payments and call smart contracts are a new, largely unmapped attack surface. How it differs, and how to defend it.
Delegation is a different discipline from autocomplete, and most teams are not set up for it. What an agent task actually needs.
The model writes the code in minutes and the team debugs it for an hour. The productivity story leaves out the verification bill.
Not the headcount-slashing fantasy and not a normal team that pays for a few subscriptions. How the org chart, the day, and the economics actually change.
The code works. The architecture is clean. The team is good. And the company still fails to scale.
The AI conversation is dominated by large enterprises. Here is what actually changes when a small business adopts these tools, and what stays the same.
Most teams treat deployment as something you set up when you have time. We treat it as the first thing we build.
We spent a year ignoring Go generics, six months using them wrong, and the last year finding the handful of patterns that actually belong in a production codebase.
Three months of AI-assisted coding in production. What held up, what collapsed, and where it changed the calculation.
Most "AI agents" are just chatbots with extra steps. Here are the patterns that actually work in production.
Not a language war. A practical rubric built from real projects, with a decision flowchart.
Most startup security failures are known patterns hit by automated tools against teams that assumed it was someone else's problem.
Technical debt is not a code problem. It is a business problem with a compound interest curve.
No drips, no funnels, no "engagement campaigns." Just the next post when it lands, about once a month, sometimes less.