Work notes

Method demonstrations, run against our own systems.

Audit work is confidential, so we have no client engagements we are free to describe. Rather than invent some, we run the method over things we built and publish what we find, including the findings that are against us.

2 notes · no client work is described on this page

Work note 01 / Adversarial evaluation

2026-08-23

We red-teamed our own PHI guardrail, and the logs were the problem.

An LLM guardrail that catches patient identifiers, including base64 and spaced-out digits, held against every injection we threw at it. The finding that mattered was somewhere else entirely.

Subject
NHS PII guardrail, FastAPI service, Claude Haiku 4.5 classifier
Demonstrates
Failure modes, adversarial testing, socio-technical scope

Read the note

Work note 02 / Classification analysis

2026-08-23

Where a classification analysis stops, and counsel begins.

A worked example of the technical characterisation we hand to legal teams: what the system does, which Annex III heading it touches, and the four places the analysis deliberately refuses to answer.

Subject
AI ACT Buddy self-check tool, assessment contract and parser
Demonstrates
Art. 6 and Annex III characterisation, the facts/determination line

Read the note

Nothing on this page describes a client system, and no engagement is referenced, named or implied. Where a note reports a defect, the defect is in something we built ourselves.