Blog
Notes from the evidence layer.
Engineering, compliance, and strategy from the team building Project AIR.
Engineering · 2026-06-10
An NVIDIA-backed second opinion, signed
How NemoGuard NIM classifier verdicts become signed detector findings in the AIR evidence chain.
Read →
Strategy · May 27, 2026
88% of AI Agent Deployments Had a Security Incident. 6% Have a Budget to Fix It.
The state of AI agent accountability in 2026: the incidents, the converging regulatory deadlines, and the evidence infrastructure gap.
Read →
Launch · May 26, 2026
Introducing Project AIR
Evidence-grade infrastructure for accountable AI agents: signed intent capsules, 16 OWASP-mapped detectors, causal explanation, Auth0 containment, and cross-agent chain of custody.
Read →
Engineering · May 13, 2026
They Check Messages. We Check Missions.
Structural Verification: a deterministic floor that checks whether the agent’s actual trajectory served its declared intent, and cannot be prompt-injected.
Read →
Compliance · May 12, 2026
The New HIPAA AI Audit Problem (and How to Solve It)
The HIPAA Security Rule NPRM makes audit controls mandatory. AI agents touching PHI need cryptographic evidence chains, not application logs.
Read →
Engineering · May 12, 2026
Forensic Evidence for NemoClaw: HIPAA Audit Trails for Sandboxed Clinical AI
NVIDIA NemoClaw controls what clinical AI agents can do. Project AIR proves what they did. Prevention plus evidence for regulated healthcare.
Read →
Strategy · May 2, 2026
What happens after an AI agent does something it shouldn’t?
A map of AI agent security tooling, and the post-incident forensic layer most teams don’t realize they’re missing.
Read →
Strategy · April 24, 2026
Implementing Trustworthy Agents: A Forensic Evidence Layer for Production
Anthropic’s paper on trustworthy agents names three ecosystem gaps. Project AIR is our answer to evidence sharing and open standards.
Read →
Engineering · April 2, 2026
Run your first air trace in 5 minutes
From pip install projectair to a signed forensic timeline of your LangChain agent in under five minutes.
Read →
Compliance · April 2, 2026
EU AI Act Article 72: A Developer’s Guide to Post-Market Monitoring
What post-market monitoring evidence actually has to contain by August 2, 2026, and how to automate producing it.
Read →
Engineering · April 2, 2026
The State of MCP Security in 2026
92% of MCP servers lack proper OAuth. We scanned real configurations and found critical vulnerabilities across authentication and authorization.
Read →