Spencer Brawner - The AI Security Guy

Latest Updates

25
Sep
Illustrative sequence: permission is consumed, the user withdraws approval, and the API call executes. In the tested implementation, withdrawal only blocks an unused grant.

The API call hasn't run. Can you still cancel?

Withdrawing approval can be too late before an agent's API call runs. A finding from my approval lab explains what a Cancel button needs to account for.
3 min read
24
Jan
The AI Insurance Coverage Gap Coming to Canada

The AI Insurance Coverage Gap Coming to Canada

Your AI exposures are being quietly excluded from liability policies on the other side of the border—and Canadian insurers
7 min read
20
Jan
Team members work together on a laptop with two people pointing towards the screen and one controlling the mouse pad.

Integrating DSPM with ISO 42001 and AI Governance Frameworks

ISO 42001 AI Management System requires continuous data security monitoring that traditional tools can't provide. DSPM platforms operationalize ISO 42001 requirements for data governance, risk assessment, and compliance evidence across AI systems.
13 min read
20
Jan
The Billionaire Privacy Paradox: Why We Trust Our Most Intimate Data with People Suing Each Other

The Billionaire Privacy Paradox: Why We Trust Our Most Intimate Data with People Suing Each Other

We trust billionaires with our most sensitive data while they publicly sue each other. Explore the uncomfortable truth about privacy,
11 min read
18
Jan
Images of a blue and red silicon microchip with the letters AI printed on the top, resting on a white cube.

DSPM vs Traditional Data Security: Why AI Changes Everything

Data Security Posture Management (DSPM) addresses the reality that AI systems access data across distributed environments, making static security controls insufficient. Practical comparison of DSPM vs traditional tools with real-world AI security scenarios.
11 min read
17
Jan
When “Dangerous” Became a Feature: The –dangerously-skip-permissions Security Crisis

When “Dangerous” Became a Feature: The –dangerously-skip-permissions Security Crisis

The s1ngularity attack weaponized AI CLI tools with bypass flags like --dangerously-skip-permissions to steal 2,349 credentials. Developers typed 'dangerously' to enable the feature that got them breached.
12 min read
17
Jan
Digital security concept: Matrix-style code representing AI account security, data protection, and cybersecurity best practices

How to Secure Your ChatGPT, Claude, or Gemini Account: Essential Security Guide (2026)

ChatGPT, Claude, and Gemini accounts face unique security risks: data exfiltration via browser extensions, malicious GPTs, prompt injection, and MCP tool compromise. This guide provides actionable steps to secure your AI accounts and prevent data exposure.
8 min read
17
Jan
Clinical workspace showing laptop computer and stethoscope, representing safe digital health technology use in medical practice

ChatGPT Health: 10 Safe Use Cases with Real Prompts for Canadian Clinicians

Practical guide to safe ChatGPT Health use for Canadian clinicians: 10 real scenarios with exact prompts, clear PIPEDA/CPSO boundaries, and examples of what crosses the line.
11 min read
13
Jan
Male doctor with clipboard consulting senior patient in Canadian clinic office representing AI training data exposure risks and healthcare privacy protection under PHIPA and PIPEDA

AI Training Data Exposure: Why Your Clinic's Patient Data Is Feeding Foundation Models

Healthcare staff using ChatGPT, Claude, and Gemini with patient data creates data exfiltration risks. Multi-jurisdictional compliance framework applicable to PIPEDA (Canada), GDPR (EU), PDPA (Singapore), and PDPL (UAE).
7 min read
13
Jan
Abstract blue shield with circuit pattern representing Privacy by Design principles for AI systems under PIPEDA, GDPR, and PDPA compliance frameworks

Privacy by Design for AI Systems: Complete Implementation Guide

Privacy by Design implementation guide for AI systems across jurisdictions. Apply the seven foundational principles to meet PIPEDA (Canada), GDPR (EU), PDPA (Singapore), and emerging data protection requirements globally.
5 min read