The thesis

There is no perimeter. Protection has to live inside the data.

The first time I set this down in a public document was 22 March 2006. For the twenty years that followed, the industry went on building walls: networks, servers, endpoints. I built something else, and I patented it.

The model everyone built

Defend the perimeter

You protect the infrastructure and hope the data stays inside. It works as long as the data stays inside. The data never stays inside.

  • The data leaves the perimeter and becomes readable by anyone
  • One compromised supplier undoes every investment upstream
  • An employee uploads a contract to an AI tool and control is gone
  • After a breach you cannot prove the data was protected
The model I patented

Defend the data

Protection travels inside the data. Wherever it is copied, forwarded or archived it stays protected. For those with the keys nothing changes. For everyone else the contents are mathematically inaccessible.

  • The data defends itself, even outside the company
  • The supply chain stops being the weak point
  • Artificial intelligence cannot read what it has no key to read
  • Under inspection, protection is demonstrable
Where this is going

Being right is not enough.
You have to be right early.

Post-quantum risk

Criminal groups and state actors are already collecting vast quantities of encrypted data today, intending to decrypt it tomorrow. It is called harvest now, decrypt later. For a board thinking in multi-year horizons the question is not whether the data is protected today, but whether it will still be in ten years. Post-quantum cryptography is not a technical matter: it is risk governance.

Digital sovereignty and on-premises AI

Every time an employee uploads a contract or a financial report to an external AI platform, control is gone, and the organisation can be in breach even while formally compliant. That is why models are needed that stay inside the organisation's own perimeter. Artificial intelligence is not bolted on afterwards: it is designed alongside the protection of the data.

AI agents

An AI agent is a back door installed on the machine. Not a metaphor: we demonstrated it live.

At Beyond the Perimeter, in front of an audience of security leaders, I did not explain the risk. I executed it.

The demonstration, in four steps
01

We built an AI agent. An ordinary tool, of the kind thousands of companies now install to raise productivity.

02

We placed it on a target machine, with the normal permissions of any employee in the organisation.

03

From a remote location we launched a commercial AI assistant and asked it to read everything held in the corporate cloud store.

04

It read every single document. The person sitting at that machine noticed nothing at all.

No perimeter breach. No suspicious activity. No alert. An agent with access to the data is all it takes.

A zero-signal attack surface

Why it happens

The large cloud platforms do encrypt data, at rest and in transit. But it is the platform that encrypts, not the data. Which means the platform decrypts for anyone it considers authorised.

An agent acting on an employee's behalf is, to the system, that employee. It reads in the clear, within seconds, generating nothing anomalous. And when a document is shared externally, it leaves that control along with all its protections.

The problem is not the AI agent. The problem is that the data it reads is not protected.

How it closes

If every document were encrypted at the moment of creation, and the key belonged to the document rather than to the platform, that same back door would read nothing but unusable ciphertext.

The agent would go on working for whoever uses it legitimately. For everyone else, and for any unauthorised automated system, the contents would remain mathematically inaccessible.

Artificial intelligence can be adopted quite safely. It just has to stop being added on top of data that cannot defend itself.

I bring this demonstration into boardrooms and lecture rooms. It runs twelve minutes and it changes the tone of the meeting.

Bring it to your company