<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Brian Chastain — Field Notes</title><description>Field notes on AI behavior, LLM security, and operational risk.</description><link>https://brian-chastain.com/</link><item><title>AI Is a Delegate-Tier Solution. Most of Your Problems Aren&apos;t.</title><link>https://brian-chastain.com/field-notes/ead-before-ai/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/ead-before-ai/</guid><description>A pre-AI operations filter that decides what AI is actually for. Run every candidate through Eliminate, then Automate, then Delegate — in that order — before evaluating any tool.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate></item><item><title>Sandboxes or just Sand?: What &apos;Isolated&apos; Should Actually Mean for AI</title><link>https://brian-chastain.com/field-notes/the-sandbox-that-wasnt/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/the-sandbox-that-wasnt/</guid><description>Two flavors of AI sandbox, one recurring failure pattern: claimed depth, measured shallow, no threat model. A practitioner&apos;s checklist for evaluating sandbox claims before you trust them.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate></item><item><title>Which Model&apos;s Guardrails Fail First? — Cross-Model Refusal Benchmark v0</title><link>https://brian-chastain.com/field-notes/cross-model-refusal-v0/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/cross-model-refusal-v0/</guid><description>12 prompts × 5 frontier models × 3 runs (raw, harness-passthrough, perturbed). A first systematic look at how refusal behavior diverges across providers — and what that divergence tells us about deployment-time risk.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate></item><item><title>Determinative Ideation: You asked for advice, AI played along</title><link>https://brian-chastain.com/field-notes/determinative-ideation/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/determinative-ideation/</guid><description>Idea creation or pattern pollution? Is AI&apos;s programmatic helpfulness agentic slop or emotional determinism...</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Prompt Engineering: What Actually Moves the Needle</title><link>https://brian-chastain.com/field-notes/prompt-engineering-fundamentals/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/prompt-engineering-fundamentals/</guid><description>Practical techniques for getting better output from LLMs: focused on what works, not what sounds impressive.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Helpful, Compliant, and Around Your Firewall</title><link>https://brian-chastain.com/field-notes/the-helpful-bypass/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/the-helpful-bypass/</guid><description>Your AI followed every rule you set. It just didn&apos;t need them to get what it wanted.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate></item><item><title>The Class That Taught Everything and Nothing</title><link>https://brian-chastain.com/field-notes/the-class-that-taught-everything-wrong/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/the-class-that-taught-everything-wrong/</guid><description>What happens when AI education skips the part about not uploading your bank statements to ChatGPT.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate></item><item><title>101 Prompts Every AI Builder Should Test Before Going Live</title><link>https://brian-chastain.com/field-notes/101-prompts-red-team-training/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/101-prompts-red-team-training/</guid><description>A categorized reference of real prompt injection, jailbreak, and extraction techniques — written for defenders, not attackers. If your system fails these, your users will find out before you do.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Hacking vs. Hacking AI: Notes from the Field</title><link>https://brian-chastain.com/field-notes/ai-hacking-vs-hacking-ai/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/ai-hacking-vs-hacking-ai/</guid><description>The line between building with AI and breaking with AI is thinner than either side admits. Field observations on why the tooling doesn&apos;t care about your intent — and what that means for builders and defenders alike.</description><pubDate>Fri, 03 Apr 2026 00:00:00 GMT</pubDate></item><item><title>When AI Reads What You Told It Not To</title><link>https://brian-chastain.com/field-notes/ai-guardrail-bypass-patterns/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/ai-guardrail-bypass-patterns/</guid><description>AI coding assistants are learning to sidestep ignore files and access restrictions — not by breaking the rules, but by finding paths around them. What that looks like in practice.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Outside-In: AI-Assisted Vulnerability Scanning When You Don&apos;t Have the Source</title><link>https://brian-chastain.com/field-notes/webapp-vuln-scanning-outside-in/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/webapp-vuln-scanning-outside-in/</guid><description>How to escalate from passive reconnaissance to actionable vulnerability findings against web applications — using the same AI-assisted methodology that works for source code, adapted for black-box targets.</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate></item><item><title>What I Keep Seeing That Nobody Is Writing Down</title><link>https://brian-chastain.com/field-notes/hello-world/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/hello-world/</guid><description>Why I started documenting AI behavior from an operational background — and what this site is actually for.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Prompt Injection Attack Surfaces: A Practical Taxonomy</title><link>https://brian-chastain.com/field-notes/prompt-injection-attack-surfaces/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/prompt-injection-attack-surfaces/</guid><description>How prompt injection escalates from curiosity to transaction fraud when AI agents have tools, file ingestion, and multimodal input — mapped from lab work to real-world deployment patterns.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Scaling AI Vulnerability Scanning Beyond One File at a Time</title><link>https://brian-chastain.com/field-notes/scaling-ai-vuln-scanning/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/scaling-ai-vuln-scanning/</guid><description>Why manual prompt hints don&apos;t scale for AI-assisted code audits, and how per-file isolation with automated scaffolding solves the accuracy-vs-coverage tradeoff — tested against a 316-file production codebase.</description><pubDate>Sun, 29 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Risk: Field Observations From the Build Side</title><link>https://brian-chastain.com/field-notes/ai-risk-field-observations/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/ai-risk-field-observations/</guid><description>What you learn about AI risk when you spend your days building with AI tools — not theorizing about them.</description><pubDate>Wed, 16 Jul 2025 00:00:00 GMT</pubDate></item><item><title>Intent Over Capability</title><link>https://brian-chastain.com/field-notes/intent-over-capability/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/intent-over-capability/</guid><description>Why ethical clarity matters more than technical skill — especially early in a career or project.</description><pubDate>Sat, 26 Apr 2025 00:00:00 GMT</pubDate></item><item><title>When AI Builds What You Shouldn&apos;t Ship</title><link>https://brian-chastain.com/field-notes/when-ai-builds-what-you-shouldnt-ship/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/when-ai-builds-what-you-shouldnt-ship/</guid><description>What happens when an AI coding assistant generates a production-grade scraper in response to an innocent request — and why the developer is the last line of defense.</description><pubDate>Fri, 25 Apr 2025 00:00:00 GMT</pubDate></item><item><title>A Decision Framework for What Not to Build</title><link>https://brian-chastain.com/field-notes/what-not-to-build/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/what-not-to-build/</guid><description>The questions worth asking before writing a line of code — especially when AI makes building the wrong thing trivially easy.</description><pubDate>Thu, 24 Apr 2025 00:00:00 GMT</pubDate></item><item><title>AI-Assisted Security Testing: Where the Lines Are</title><link>https://brian-chastain.com/field-notes/ai-assisted-security-testing/</link><guid isPermaLink="true">https://brian-chastain.com/field-notes/ai-assisted-security-testing/</guid><description>Operational boundaries for using AI tools in vulnerability research and bug bounty programs — what&apos;s allowed, what&apos;s not, and why the distinction matters.</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate></item></channel></rss>