Frameworks

Ideas I keep returning to, named so they can be argued with. Each one started as a weekly take in Context Window and held up well enough to stand on its own.

They answer four different questions — wherean attack enters, why containment doesn’t hold, why you can’t lower the odds, and why you can’t out-react it either — and they converge on one conclusion: with agentic systems, the work that decides the outcome happens before the incident, not during it.

The Likelihood Collapse

Why AI risk management moves from probability to blast radius

The Likelihood Collapse is the term coined by Asaf Nakash for the point at which the likelihood half of the risk equation stops being reducible — because in an AI agent, the exposure that creates risk is the product feature, not a misconfiguration.

Read the framework

Every Input Is an Instruction

The input boundary is the real attack surface, not the model

Every Input Is an Instruction is Asaf Nakash's principle that any content an AI agent consumes — a document, a database row, a tool result, a message from another agent — can become a command it executes, which makes the input boundary the real attack surface rather than the model itself.

Read the framework

The Guard, Not the Wall

Why sandboxing fails against a reasoning attacker

The Guard, Not the Wall is Asaf Nakash's framing that AI containment failures are not walls being broken but guards being talked into opening a legitimate door — which is why process isolation alone cannot contain a reasoning system.

Read the framework

Zero Day to Zero Sec

Why context, not speed, is the defender's binding constraint

Zero Day to Zero Sec is Asaf Nakash's term for the collapse of the exploitation window from days to seconds under autonomous attack — and the argument that the answer is not a faster defender, but context assembled before the attack, because a defender without context is only blind faster.

Read the framework