
Sphere turns 21. Twenty-one lessons from 21 years in technology — on trust, curiosity, security, AI, and what actually makes teams and software last.

Sphere turns 21. Twenty-one lessons from 21 years in technology — on trust, curiosity, security, AI, and what actually makes teams and software last.

An AI agent can't publish until it passes its golden set at a configured threshold. How eval-gated deployment makes correctness a deploy gate, not a dashboard.

A conformity assessment checks a high-risk AI system before market. The hard part is the evidence — what assessment-ready looks like before the assessor comes.

Institutional memory AI for legal: make prior briefs, redline history, and matter context retrievable with privilege and ethical walls enforced at retrieval.

Logging records events. Auditability means an outsider can verify them — complete, unaltered, ordered, and scoped. The four properties, and the one logs lack.

Audit evidence gathered after the fact creates a multi-week scramble. When controls record their own operation as they run, readiness becomes a query.

When knowledge graphs beat standard RAG: relationship-dense, multi-hop questions where a missed link is costly — and the maintenance tax to skip elsewhere.

The audit binder is a snapshot of a moving system. Continuous evidence accumulates as AI decisions happen — so an audit becomes a query, not a project.

A chat export will not survive scrutiny. What a defensible AI production needs: completeness, integrity, and an export the other side can verify offline.

Institutional memory AI for manufacturing: index equipment manuals, drawings, and CMMS / EAM / QMS records with multimodal retrieval before the retirement wave.

ISO 42001 is a voluntary management standard; the EU AI Act is law. Where they overlap, where they diverge, and how one control set can satisfy both.

Completeness and disclosure are separate decisions: keep one tamper-evident AI ledger and scope what the user, regulator, auditor, and engineer each see.