Topic

AI Engineering

Application architecture, developer workflow, tooling, and production patterns for building AI systems.

ai engineeringllm application developmentagent engineeringmcpdeveloper toolingai systems
Evergreen Overview

Application architecture, developer workflow, tooling, and production patterns for building AI systems.

What this page covers
  • Core concepts for ai engineering
  • Useful references, notes, and curated examples
  • Practical links back to AI systems and operational risk
Why it matters
  • It creates better language for technical and governance discussions
  • It helps teams connect theory to deployed workflows
  • It supports more repeatable review and decision-making
Who this page is for
  • Researchers and builders working with AI systems
  • Security and governance teams
  • Leaders looking for current reference material
References

Current notes, events, and source material

These items are included because they add useful evidence, framing, implementation detail, or upcoming context for teams working in this area.

Microsoft Security Blog October 7, 2026 guide Featured

AI vulnerability research: measure reproducible findings and completed fixes

Why it ranks: directly applicable to AI security practice; strong implementation or testing value.

Microsoft’s FORGE account describes the work between a model’s vulnerability claim and a useful repair: reusable builds, duplicate removal, reachability checks, project-specific verification, reproducible triggers and regression tests. Structured rejection reasons help improve later searches. The useful operational measure is the flow of findings that survive verification and reach a fix, rather than the number of candidates generated. Reported successful-case costs exclude parts of screening, failed attempts and human work, so they are not the total cost of operating this pipeline.

OpenAI News August 17, 2026 guide

The Defender’s Window

OpenAI describes a staged program for AI-assisted defense: use agents to review code and infrastructure, triage alerts, enumerate attack paths, and validate security invariants while retaining strong isolation and least privilege. Its recommended rollout starts with internet-facing services and vulnerability backlogs, moves security review into CI, requires focused fixes and regression tests, and expands from read-only triage to narrowly bounded automation only after teams build evidence and confidence.

Google Cloud Security Blog July 21, 2026 tool

Now in preview: Find and fix software vulnerabilities with CodeMender

Google opened a preview of CodeMender, an AI code-security agent delivered through Gemini Enterprise Agent Platform and AI Threat Defense. It is designed to inspect code, identify and validate potentially exploitable defects, and produce targeted fixes, with Google’s specialized Gemini 3.5 Flash Cyber model initially restricted to governments and trusted partners.

AWS Security Blog September 21, 2026 guide Featured

Transforming Bedrock Guardrails events into OCSF with CloudWatch

Why it ranks: directly applicable to AI security practice; strong implementation or testing value.

AWS provides an implementation guide for a Lambda pipeline that converts Bedrock Guardrails intervention logs into OCSF Detection Findings in the CloudWatch unified data store. It includes field mapping and queries that correlate guardrail events with identity and network activity.

Google DeepMind Blog August 27, 2026 framework

Piloting the world's first double-blind AI evaluations

Google DeepMind, Singapore's AI Safety Institute, OpenMined, AVERI, and MLCommons are piloting an external evaluation in a confidential-computing environment. The evaluator's hidden tests and Google's Gemini Flash Lite weights remain private from one another, reducing benchmark contamination without transferring either sensitive asset.

NVIDIA OpenShell September 28, 2026 tool Featured

OpenShell: inspect the runtime controls behind NVIDIA’s agent safety launch

Why it ranks: directly applicable to AI security practice; strong implementation or testing value.

NVIDIA’s Open Agent Safety Platform pairs OpenShell’s open-source sandbox runtime with the Sentry hardware reference design. OpenShell’s documentation describes filesystem and process isolation, outbound network policies, and provider credentials resolved only at authorized endpoints. These are inspectable configuration mechanisms, while Sentry’s millisecond quarantine claims remain vendor assertions. Filesystem and process restrictions are fixed when a sandbox is created; network policies and credential attachments can change during operation.

SecurityWeek AI Security September 2, 2026 tool

OpenLeash Adds a Human Check to Risky AI Agent Actions

SecurityWeek profiles OpenLeash, an authorization layer that evaluates proposed agent actions and can block them or request human approval. The project’s public repository provides a personal runtime using agent hooks and provider traffic, with a decision engine, local history and desktop integration. Its hosted business control plane is outside that repository. Public implementation materials make it inspectable, while the profile offers no independent efficacy benchmark.

AWS Security Blog August 27, 2026 guide

Extend Amazon Bedrock Guardrails to Tool Interactions Using the Strands Agents SDK

AWS extends Bedrock Guardrails beyond model input and output with three Strands lifecycle checkpoints: inspect inbound user or retrieved content, validate tool arguments before execution, and inspect tool results before they re-enter the model or leave the system. The implementation mixes service guardrails with lower-latency schema, regex, and allowlist checks.

Google DeepMind Blog June 16, 2026 guide

Securing the future of AI agents

Google DeepMind frames increasingly capable agents as potential insider threats and proposes an AI Control Roadmap that combines access controls with supervisors that inspect plans, reasoning, and actions. Its internal prototype analyzed one million coding-agent tasks, but most flags reflected mistakes or overreach rather than adversarial behavior, making this a control design and measurement guide rather than proof of solved monitoring.

NVIDIA AI Red Team June 14, 2023 framework

NVIDIA AI Red Team: An Introduction

NVIDIA’s 2023 AI red-team introduction organizes assessments across the ML lifecycle, infrastructure and organizational risk. It combines conventional security testing, model attacks and harm scenarios, then illustrates lifecycle boundaries, privilege separation and tabletop exercises. The framework helps teams identify affected components and assign responsibility across data collection, training, deployment and monitoring.

Anthropic October 8, 2026 tool

OSS Scanner: prepare an offline build and triage unverified vulnerability reports

Anthropic’s OSS Scanner accepts maintainer enrollment through a project configuration, a build container and an optional threat model. Dependencies are installed during the network-enabled build; the audit then runs offline. Maintainers can specify untrusted inputs, excluded components, severity criteria and the evidence expected in a report. The delivered findings are model-generated and have not undergone human review. They therefore require reproduction and triage; the service’s ordinary human-validated disclosure process is a separate step.

OpenAI News October 2, 2026 guide

OpenAI’s GPT-6 guide treats agent performance as a workflow measurement problem

OpenAI’s October 2026 guide recommends evaluating GPT-6-family models on complete tasks, balancing successful outcomes against latency and cost. It describes stable prompt prefixes for caching, explicit tool and authority boundaries, and context compaction that preserves important evidence during long work. Model selection and reasoning effort become variables to test against the application’s own acceptance criteria. The article is vendor guidance rather than an independent model comparison, and its examples do not establish universal performance or cost savings. Its useful contribution is a concrete set of workflow controls to evaluate together.

OpenAI News September 22, 2026 guide

Diagnose prompt-cache misses without widening an agent’s tool access

OpenAI’s prompt-caching guidance explains how to compare requests for changes that invalidate shared prefixes, place explicit breakpoints, and preserve tool definitions while changing which tools are callable. GPT-6 can also receive appended reasoning-effort updates without rewriting the earlier prefix. Workload savings still need measurement.

AWS Security Blog September 2, 2026 analysis

Agentic security: Detection and response at machine speed

AWS outlines four areas for securing autonomous workloads: distinct agent identities with temporary scoped credentials, continuous behavioral monitoring, tiered automated containment and traceable delegation across agent teams. It recommends separating sensitive-data access, untrusted inputs and external communication. The article introduces an AWS/SANS framework and links to the longer implementation guidance.

The Hacker News AI Security August 31, 2026 guide

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

This guide maps three complementary control layers for local coding agents: enforced Claude Code settings, Anthropic's Compliance API transcripts for local sessions, and endpoint telemetry such as OpenTelemetry, hooks, configuration inventory, and EDR. It also identifies important gaps: cloud transcripts do not capture unused local plugins or off-platform model sessions, endpoint logs lack business intent, and retained transcripts can become a sensitive data store.

The Hacker News AI Security July 27, 2026 tool

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA launched the Open Secure AI Alliance and contributed NOOA, an Apache-2.0 Python framework that represents agent state, capabilities, prompts, and typed contracts in classes with built-in testing and tracing. NVIDIA reports 86.8% on CyberGym L1 with GPT-5.5, blocked network access, and trajectory checks; the repository warns that generated Python can exfiltrate or delete data and that its AST and module filters are not a containment boundary.

AWS Security Blog August 18, 2026 guide

Implement custom authentication for tools integration using request Lambda interceptor in AgentCore Gateway

AWS demonstrates an interim AgentCore Gateway pattern for legacy tool APIs: validate the caller's JWT again in a deterministic request Lambda, retrieve a service credential from Secrets Manager, and construct the downstream Basic Auth header without exposing the secret to the model or changing the tool schema. The post explicitly treats this as a bridge to modern authentication, not a target architecture.