What penetration testing taught me
Security work starts with observable behavior, not reassuring descriptions. A control matters because of what it enables people to do in practice. I bring that evidence-minded perspective to AI governance while keeping distinct questions distinct: a vulnerability, an incident and a loss of effective human control are not the same thing.
Why I created Meseray
Policies, approvals and a person in the loop do not by themselves show that an organization can still direct an AI-enabled workflow. I wanted to make the gap between formal oversight and practical control a clear question that leaders can examine against evidence.
From a question to a working initiative
Over roughly a year of independent work, I developed the Meseray research and diagnostic initiative into an integrated demonstration: a way to frame a bounded assessment, receive authorized evidence and present an executive view, including a mobile snapshot. The integrated demonstration has been tested with synthetic data. This is concrete progress, but it is not independent validation or proof of enterprise outcomes.
What comes next
Meseray starts with one material AI-enabled workflow and a defined evidence boundary. The Phase 1 standard reference is EUR 15,000. The goal is to give an organization useful findings and a decision basis, while being clear about evidence limits. The diagnostic is not a certification or a guarantee of safety; independent evaluation and measured enterprise pilots remain important.
The question that guides my work
Where, in the trajectory from human mandate to system consequence, does effective human control begin to degrade?