I spend my working days securing how a company uses AI: an LLM gateway in front of the model calls we can route through it, guardrails inspecting what goes in and out, and governance for the tools people actually use (and the ones they’re not supposed to).
Most of what’s written about AI security is either vendor marketing or academic threat taxonomies. What’s missing is the middle: what it actually looks like to run this inside a real company — what the OWASP LLM Top 10 means when it’s your developers’ traffic, what shadow AI looks like in the logs, which guardrails fire constantly and which never fire at all.
That’s what this column is for. Field notes, not pitches.
About the title
I watch a lot of Formula 1, and “lights out and away we go” is how the start of a race gets called — the moment the five red lights go dark and a season’s worth of preparation finally meets the track.
It fits the subject better than I expected. Almost everything interesting in AI security happens once the thing is already moving: the gateway is live, real traffic is flowing, and people are using the tools in ways nobody wrote down. You can plan the strategy in advance, but you learn what the controls are actually worth at speed.
So: lights out. More soon.