Domain

AI Security

Securing systems that put a model between untrusted input and something that can take action.

I lead AI security for about 1,500 users at work. The question that takes up most of my time is what happens when a model with access to sensitive data reads input from someone trying to make it misbehave.

Two of the Azure builds are where I test that on my own. Both put a model in front of untrusted text, so both need real defenses rather than a note saying I thought about it.

At work: DLP controls and data-loss policies for Microsoft Copilot across 1,500+ users under GLBA, plus AI-driven phishing detection tuning in Proofpoint at FirstBank that cut manual investigation by 30%.
Roadmap

What's next

Listed before it exists so you can tell the difference.

Prompt injection lab

An attack suite against my own inquiry manager build. Direct injection, injection through stored content, and exfiltration attempts, plus whatever holds up against them.

AI Security Planned
LLM data loss prevention

Controls that stop sensitive data reaching a model or leaving in a response.

AI Security Planned
Model abuse monitoring

Detection for jailbreak attempts and unusual usage against an AI endpoint.

AI Security Planned