Frameworks

Ideas I keep returning to, named so they can be argued with. Each one started as a weekly take in Context Window and held up well enough to stand on its own.

They answer four different questions — wherean attack enters, why containment doesn’t hold, why you can’t lower the odds, and why you can’t out-react it either — and they converge on one conclusion: with agentic systems, the work that decides the outcome happens before the incident, not during it.

The Likelihood Collapse

Why AI risk management moves from probability to blast radius

The Likelihood Collapse is the term coined by Asaf Nakash for the point at which the likelihood half of the risk equation stops being reducible — because in an AI agent, the exposure that creates risk is the product feature, not a misconfiguration.

Read the framework

Every Input Is an Instruction

The input boundary is the real attack surface, not the model

Every Input Is an Instruction is Asaf Nakash's principle that any content an AI agent consumes — a document, a database row, a tool result, a message from another agent — can become a command it executes, which makes the input boundary the real attack surface rather than the model itself.

Read the framework

The Guard, Not the Wall

Why sandboxing fails against a reasoning attacker

The Guard, Not the Wall is Asaf Nakash's framing that AI containment failures are not walls being broken but guards being talked into opening a legitimate door — which is why process isolation alone cannot contain a reasoning system.

Read the framework

Recognition Is Not Resistance

An agent can name the attack and run it anyway

Recognition Is Not Resistance is the term coined by Asaf Nakash for the finding that an AI agent's ability to detect an attack is independent of its ability to refuse one — an agent can name the technique being used against it, explain why it is dangerous, and comply in the same breath.

Read the framework

Zero Day to Zero Sec

Why context, not speed, is the defender's binding constraint

Zero Day to Zero Sec is Asaf Nakash's term for the collapse of the exploitation window from days to seconds under autonomous attack — and the argument that the answer is not a faster defender, but context assembled before the attack, because a defender without context is only blind faster.

Read the framework

The Verification Ceiling

You can safely delegate exactly as much as you can check

The Verification Ceiling is the term coined by Asaf Nakash for the hard limit on how much work can safely be delegated to an AI agent: exactly as much as you can check. Past that line you are not managing the agent, you are hoping — and the limit holds no matter how capable the agent gets.

Read the framework