Featured publication · AI agent incident investigation
After the Agent “Escaped”: Investigating the Investigation
The July 2026 OpenAI and Hugging Face incident shows why an agent's actions and an operator's response must be reconstructed together.
Zemi North / Insights
Analysis of digital evidence, AI-influenced decisions, and the controls required to examine them.
Current record
Each publication establishes its scope, identifies the evidence required, and marks the limits of what the available record can support.
Featured publication · AI agent incident investigation
The July 2026 OpenAI and Hugging Face incident shows why an agent's actions and an operator's response must be reconstructed together.
Publication index
The July 2026 OpenAI and Hugging Face incident shows why an agent's actions and an operator's response must be reconstructed together.
A practical guide for counsel, employers, and incident managers on preserving devices, cloud records, logs, and decision context before a forensic examination begins.
AI-mediated malware can move part of an attack chain into prompts, model responses, generated code, and volatile memory. A synthetic ransomware investigation shows how to reconstruct what the model did.
An AI-mediated data disclosure shows why task initiation, technical execution, intent, authorization, control, and accountability require separate findings.
What a widely repeated AI incident establishes, what it does not, and why the distinction still matters.
What Claude's text watermark can establish, where provider records may extend the trail, and why attribution to a person still requires corroboration.
How evaluation, validation, red teaming, governance, monitoring, and audit combine to support bounded assurance findings about deployed AI systems.
A forensic examination of why agent, account, and token records do not automatically establish human authorship, intent, authorization, or control.
An evidentiary guide to the prompts, data, system state, logs, human interventions, decisions, and actions needed to reconstruct AI-influenced decisions.
Research foundation
Insights apply the evidentiary discipline. The Method defines it, versions it, and keeps the reasoning open to examination.
Publication programme
Preservation, integrity, and provenance in AI-influenced decisions.
Control and attribution when AI systems execute consequential actions.
Forensic limits in synthetic-media and automated-system claims.