The Wentzel.ai Blog
Insights, thoughts, and reflections.
Field notes from across the portfolio — cybersecurity and incident anatomy, AI governance, finance, legal tech, agriculture, and the engineering behind specialized intelligence.
Featured writing
The Agentic Security Crisis: Why 'Human-in-the-Loop' Is No Longer Enough
As AI agents gain the ability to take actions across systems, the human-in-the-loop safeguard collapses under volume and speed. The answer is not more approvals — it is governed autonomy.
Incident Anatomy: Shai-Hulud — The npm Supply Chain Worm That Could Have Been Stopped
A technical analysis of the Shai-Hulud malware campaign — a self-propagating worm in the npm ecosystem that weaponized stolen maintainer tokens to publish trojanized package versions at machine speed.
PROMPTFLUX: The Era of Self-Rewriting Malware and AI-Driven Cyber Evasion
A new class of malware uses a large language model to rewrite its own code on a schedule, defeating signature-based detection by ensuring no two copies ever look alike.
Recalibrating Risk: From Streetlights to Firewalls
Our perception of risk has fundamentally transformed from tangible, local dangers to invisible, global threats. Here is how to recalibrate risk management in the digital age without paralyzing innovation.
Taming the LLM: Using Finite-State Machines to Prevent Hallucinations in AI Workflows
Free-running language models hallucinate because nothing constrains where they can go next. Wrapping the model in a finite-state machine turns an open-ended generator into a bounded, auditable workflow.
The Agentic Security Crisis: Why 'Human-in-the-Loop' Is No Longer Enough
As AI agents gain the ability to take actions across systems, the human-in-the-loop safeguard collapses under volume and speed. The answer is not more approvals — it is governed autonomy.
Beyond Structure: Why Boltz-2 and the 'Interaction Era' Matter for Drug Discovery
Predicting a protein's shape was the breakthrough of the last era. Predicting how molecules interact — affinity, not just structure — is the breakthrough of this one, and it changes the discovery funnel.
The "Cyber Lemon": Pricing Technical Debt in Distressed M&A
In distressed acquisitions, the cybersecurity posture of the target is rarely priced — until it detonates post-close. Here is how to assess and price the "cyber lemon" before you own its liabilities.
The Quantum Cliff: Strategic PQC Migration and Cryptographic Debt Assessment in Finance
The threat is not a quantum computer breaking your encryption tomorrow. It is an adversary harvesting your encrypted data today to decrypt it later — and a migration most institutions have not even scoped.
The USB-C for AI Has a Security Leak: How to Tame Exposed MCP Servers
The Model Context Protocol is becoming the universal connector between AI agents and the tools they use. Like any universal connector, it is only as safe as what you plug into it — and many MCP servers are wide open.
Incident Anatomy: Shai-Hulud — The npm Supply Chain Worm That Could Have Been Stopped
A technical analysis of the Shai-Hulud malware campaign — a self-propagating worm in the npm ecosystem that weaponized stolen maintainer tokens to publish trojanized package versions at machine speed.
The Strategic Imperative for a Domestic Shift to Walnuts
A first-principles look at why domestic walnut production is a strategic agricultural play — and how precision automation changes the unit economics of the modern orchard.
PROMPTFLUX: The Era of Self-Rewriting Malware and AI-Driven Cyber Evasion
A new class of malware uses a large language model to rewrite its own code on a schedule, defeating signature-based detection by ensuring no two copies ever look alike.
Recalibrating Risk: From Streetlights to Firewalls
Our perception of risk has fundamentally transformed from tangible, local dangers to invisible, global threats. Here is how to recalibrate risk management in the digital age without paralyzing innovation.
Revolutionizing Legal Document Review with Lawvora AI
How AI-assisted document review compresses days of clause-by-clause work into minutes — with risk ratings, plain-English summaries, and side-by-side comparison that an attorney can actually defend.
The Case for AI: Your Manual Contract Review Process is a Liability
Why manual review in 2025 is a business liability — human error, an evolving standard of care, and the competitive disadvantage of doing it by hand.
Beyond the Firewall: How AI Became the New Apex Predator in Financial Fraud
Generative AI has rewritten the economics of financial fraud. Defending against machine-speed deception requires machine-speed defense — and a hard look at where humans still belong in the loop.
The New 'Shovel-Sellers' of the AI Gold Rush: Data Centers as the Hottest Real Estate Asset
In every gold rush the durable fortunes are made selling shovels. In the AI gold rush, the shovels are data centers — and the constraint is no longer silicon, it is power and land.