In my world there are two stories we tell about AI.
Either it’s coming for your company, or it’s going to triple your revenue.
Threat or multiplier. Fear or greed.
Both stories are about the organization. Neither is about the person.
Last week I sat in a room with lawyers and policymakers at Oxford, and they were telling a third story. Not “what will AI do to us?” but “what do we owe each other when we build it?”
That’s a humanist question. And it turns out it’s also the security question.
Because as I mentioned to them, securing AI isn’t one job. It’s six:
– Data — protecting privacy and sanitizing what the model learns from
– Model — fine-tuning, protection, and adversarial testing
– AI Application — validating inputs and outputs, controlling agents and plugins
– AI Infrastructure — hardened cloud, identity, and access
– Assurance — monitoring, red-teaming, hunting vulnerabilities
– Governance — policy, risk, and knowing what AI you actually own
Engineers start in the middle. Policymakers start at the end.
The gap between them is where trust leaks out.
https://www.linkedin.com/company/oxford-media-policy-summer-institute/posts/?feedView=all







