Field notes

Notes on AI, Law 25 and deployment

Short pieces for regulated teams evaluating privacy controls for generative AI.

AI Governance

Browser-Resident AI Privacy Controls: The Fastest Path to Secure Enterprise AI Adoption

The next breach will not begin with a dramatic intrusion. It will begin with a well-meaning employee pasting a client file, an access token, or a patient note into a generative AI window. Browser-resident AI privacy controls close that gap at the point of use, before sensitive data leaves the endpoint.

Read
Compliance

AI Compliance Gap: Why Privacy Policies Fail Without Technical Enforcement

Privacy policies often say the right thing: do not share personal information, payment data, secrets, or regulated records with unauthorized AI systems. The operational problem is that employees work faster than policies can be reread.

Read
Security Architecture

Pseudonymization vs Redaction: The Security Difference That Keeps AI Useful

Redaction is blunt. It removes risk by removing meaning. Pseudonymization is more disciplined: it substitutes sensitive identifiers with realistic synthetic values so the AI system can still reason about roles, formats, relationships, and workflow context.

Read
DLP Strategy

Prompt DLP Checklist: What to Inspect Before AI Data Leaves the Browser

The most effective prompt DLP programs start with the data attackers prize and regulators scrutinize: credentials, financial identifiers, personal information, infrastructure details, and confidential business terms.

Read
Operations

Managed Browser AI Security: Rolling Out Guardrails with GPO and MDM

Enterprise AI security succeeds when the control reaches the place where employees actually work. For many organizations, that place is the managed browser.

Read
Context Security Inc. · Quebec, CanadaContextShield · Chrome and Edge