Marin Ivezic
I write here about how AI systems get attacked, and how badly the defensive practice lags the research that breaks them. The subjects are AI security, AI safety and alignment, AI privacy, AI-enabled disinformation, and the cyber-kinetic risk that arrives once AI starts controlling physical things.
That interest is older than the current wave of it. In the early 2000s I was Managing Director of CyberAgency, at the time the largest global red teaming and penetration testing agency working on critical national infrastructure. A defence client asked us to evaluate the security of AI systems they intended to deploy in weapons. We broke them. I have been paying attention ever since.
Through the years that followed, at CyberAgency and then in leadership roles at IBM, Accenture, PwC and KPMG, I built emerging-technology risk labs for corporations and governments. Two strands of that work matter to this site. One set of labs tested adversarial AI, AI in weapons systems, and AI-driven attacks. The other tested attacks and defences against the cyber-physical layer: OT, IoT, industrial control, robotics, drones. Both produced the same lesson, which is still the position I write from. You find out what a system’s real risk is by testing it. Reasoning about it returns what you already believed.
Along the way I served as a Fortune Global 500 CISO and CTO, and as a partner at PwC and KPMG. At IBM and Accenture I held Asia-Pacific and global leadership roles, running transformation programmes of up to $500 million and organisations of up to a thousand people. In 2016 I co-wrote The Future of Leadership in the Age of AI with Luka Ivezic. It has dated, as anything written about AI in 2016 has. Writing it early is the part that still counts.
My commercial work is elsewhere. I founded Applied Quantum, an EU firm working on quantum computing, quantum readiness and post-quantum cryptography, and I write about that at PostQuantum.com. The choice was deliberate. Quantum is closer to my first training in physics. I had tried to build quantum computers years before the field became fashionable. By the time I left my partner role, the AI security market had filled with people claiming expertise they had not earned. I did not want to spend my fifties competing for attention in that room.
So this site is not a business. I sell no AI services and offer no AI advisory or training. There is no sponsorship here and no paid placement. It is where I write about a subject I have worked on for twenty years and still find more interesting than almost anything else.
You can reach me at [email protected] or connect with me here https://www.linkedin.com/in/marinivezic/.