New: Compliance toolkits for the EU AI Act and NIS2 (cybersäkerhetslagen) — templates your auditor will actually accept. Browse toolkits →

Free weekly newsletter

AI Security Intelligence

What actually breaks, and what to do about it.

Contributor, OWASP Top 10 for Agentic Applications 2026 · CISSP · PhD · 15+ years enterprise security

One issue every Wednesday. Practitioner-grounded coverage of LLM and agentic security: prompt injection patterns, MCP attack chains, RAG security, OWASP Top 10 for Agentic Applications 2026. Written for engineers and security teams who want to know what's actually breaking, not vendor positioning.

What you'll get

  • One issue per week, every Wednesday. Roughly 600 to 800 words. Reading time: 4 to 6 minutes.
  • Practitioner-led format. Each issue anchors on something I'm actively building or testing myself. News stories appear when they're evidence for a practitioner question, not as the main event.
  • No vendor PR. I don't write about vendors who haven't published something substantive. I don't run sponsored issues.
  • No em dashes. (You'd be surprised how often this is asked.)

Recent issues

[AI Sec Intel] #26 The evaluation environment is the least-monitored production system in the chain

Sep 6, 2026

AISI's agent left public instructions on GitHub telling the next agent how to reuse its accounts. It was never told to deceive anyone.

Read on Beehiiv →

[AI Sec Intel] #25 The best published agent detection rate is 67%. The sensor that buys it reads everything

Aug 22, 2026

The sensor that buys you that number reads every prompt, every tool argument and every tool result on 7,200 employee laptops.

Read on Beehiiv →

[AI Sec Intel] #24 An attacker published their agent config. It is your control list, inverted

Aug 18, 2026

Fifteen minutes, thirteen findings on a static personal site. OpenAI's president wants your security team running one of these by Monday.

Read on Beehiiv →

[AI Sec Intel] #23 Read-only held for the entire intrusion. The agent still walked out with a map of the estate

Aug 4, 2026

Anthropic reviewed 141,006 evaluation runs and found three real companies breached. Two of them had no idea until Anthropic called.

Read on Beehiiv →

Who reads this

  • Engineering leads at companies deploying LLM products
  • Security engineers and architects working on AI features
  • Privacy and compliance professionals tracking the AI Act intersection
  • Researchers and consultants in the AI security space
  • A growing number of subscribers from US enterprise AI vendors as the EU AI Act enforcement approaches

About the author

I'm Amine. I help teams build LLM systems that don't become security incidents. My background is in securing critical systems across regulated industries. More recently I've been deep in how enterprise teams build and deploy LLM-based systems, and where those systems break. That combination is where this newsletter comes from.

More about me →

Working together

When an issue hits close to home

The newsletter is where I write about what's breaking. Molntek is where I help fix it. If one of these issues describes something you're shipping right now — an agent, an MCP integration, a RAG pipeline you're not sure about — that's exactly the work I do at Molntek. No pressure, and subscribing never puts you on a sales list.

Common questions

Is it really free?

Yes. The newsletter is unsponsored and won't move behind a paywall.

How do you handle my email?

Email used to send the newsletter only. Hosted on Beehiiv. No third-party sales. One-click unsubscribe in every issue.

Will I get sales emails?

No. The newsletter list and Molntek client list are separate. If you want to talk to me about consulting work, you contact me. I don't reach into the newsletter list to sell.

What if I want to read past issues?

Public archive at newsletter.aminrj.com. No subscriber gate.

Can I share an issue?

Yes. Forward, post, quote with attribution. The point is reach.

Subscribe

No spam. Unsubscribe with one click in any issue.