• The Casino Chip Economy

    The Casino Chip Economy

    Two new executive disciplines: price your tokens right, or someone else prices your alpha for you.

    By The Chiri Team


    What is your token spend actually buying you?

    Every other major line on the P&L, cloud compute, headcount, marketing, has decades of tooling, benchmarks, and institutional practice built around tracking what it returns, imperfect as that tracking often is. Token spend has none of that yet.

    It is newer, growing faster, and split across more tools than any other line on the books. That is exactly why it is becoming one of the more expensive blind spots in the C-suite.

    Two disciplines are emerging out of that gap, and neither one had a name or an owner on the org chart until very recently. The first is token optimization: getting the most value out of every dollar of inference spend by matching the right task to the right model. The second is alpha protection: making sure the work that makes your company distinct does not quietly become someone else’s training data or someone else’s product.

    They are related. Understanding why is worth ten minutes of your time.

    Token optimization is not a cost-cutting exercise

    A useful way to think about your token bill is as a stack of casino chips. Every inference call is a spin, priced by the house, and the house sets a different price depending on which table you sit at. Not all tokens are created equal, and not all tokens are priced equally either.

    Coding tokens have been heavily subsidized by the frontier labs chasing developer adoption. Back office and reasoning-heavy tokens have not. A company that treats every workload the same way, routing HR questions and legal review through the same premium model it uses for production code, is paying frontier prices for work that does not need frontier intelligence.

    The market is already voting with its usage. Vercel’s AI Gateway data for June 2026 shows open-weight models running 29 percent of all gateway tokens, up from roughly 11 percent in April, on under 4 percent of total spend. DeepSeek alone accounted for 22.6 percent of token volume on that gateway, trailing only Anthropic and Google. Read that split again: nearly a third of the volume, for a twenty-fifth of the dollars. (Vercel, July 2026)

    CNBC’s July 7 investigation into OpenRouter traffic found the same pattern from a different angle. Chinese-origin models have accounted for at least 30 percent of enterprise token volume on the platform every week since February 8, 2026, spiking to 46 percent in a single week. Compare that to an average of just 11 percent over the prior twelve months, and 4.5 percent in the first half of 2025. (CNBC)

    That is not a fringe trend. That is a market repricing intelligence in real time, and treating it as a rounding error is how a company ends up with a token bill that scales faster than its revenue.

    The discipline here is not “spend less.” It is knowing which tasks require the most capable, most expensive model available, and which tasks are being over-served by it.

    • Prove the use case on the frontier model.
    • Route the repeatable version of that work to a model priced for the job, once proven.

    That is token optimization. Everything else is just an unmanaged AWS bill with better marketing.

    The domestic labs know this is happening to them. On July 30, 2026, Sam Altman announced an 80 percent price cut on GPT-5.6 Luna, down to $0.20 per million input tokens and $1.20 per million output, plus a 20 percent cut on GPT-5.6 Terra, alongside a new Fast mode for the flagship GPT-5.6 Sol. OpenAI attributed the cuts to efficiency gains, not charity. (CNBC, VentureBeat)

    That is what it looks like when a frontier lab feels the same pricing pressure this article is describing. If OpenAI is cutting prices on its own product line to compete, the market for your token spend is already moving, whether your procurement process has caught up to it or not.

    Alpha protection is the newer of the two disciplines, and the harder one to see coming

    Palantir CEO Alex Karp has been unusually blunt about this in public this year. He has accused frontier AI labs of “stealing weights and alpha” from enterprise customers, and said businesses are “paying for tokens that create no value” while their most sensitive workflows and data pass through someone else’s model. He is calling for what he terms AI sovereignty: companies owning their compute, their data, and their models rather than renting all three. (Alex Karp, interview on CNBC’s Squawk Box, July 1, 2026: “Palantir’s Karp bashes token-based AI model as ‘completely wrong’”)

    Karp has an obvious commercial interest in that framing. He is also not wrong about the underlying mechanics.

    Watch what happened when Anthropic launched a legal plugin for Claude on February 3, 2026, automating contract review, NDA triage, compliance tracking, and legal briefings:

    • Thomson Reuters fell 16 percent that day.
    • RELX fell 14 percent, its steepest single-day drop since 1988.
    • Wolters Kluwer fell 13 percent.

    A combined market reaction in the hundreds of billions of dollars. (Morningstar, “Thomson Reuters, RELX, and Wolters Stocks Crushed After Anthropic Debuts Claude Legal Plug-In,” February 2026) That is what the market thinks happens when a foundation model provider learns enough about a vertical, from aggregate usage and prompt patterns across its customer base, to compete directly in that vertical. Whether the sell-off proved out or overshot, and analysts are genuinely split on that, the reaction itself tells you the market takes the underlying risk seriously.

    Even with a promise of zero data retention, there is a real, actively studied line of security research, membership inference and embedding inversion attacks, showing that a model provider can sometimes infer meaningful signal about what was sent to it even without retaining the raw prompt. This is not a settled, universal vulnerability in every system. It is a real enough risk in the underlying architecture that “we promise not to look” is a policy, not a technical guarantee, and the two should not be treated as equivalent.

    The fix is not to stop using frontier models. It is to be deliberate about where your alpha actually lives, and to route the workflows that touch it through infrastructure with a real legal backstop. Zero data retention agreements that flow through a licensed subprocessor, not just a checkbox in a settings page, give you something to enforce if the promise breaks. That is the difference between a policy and a contract.

    Why these two disciplines are actually one discipline

    Both come back to the same root question: what happens to your business if the assumptions behind your AI spend change under you?

    If your token costs keep exponentiating while your competitors find a cheaper, comparably capable model, you have a business continuity problem. If your most valuable workflows are training someone else’s next product release, you have a business continuity problem. Both are the same executive job, just pointed in different directions. One protects the bottom line. The other protects the reason customers choose you over the next company down the street.

    Neither of these disciplines requires a chief AI officer or a six-month transformation program. It requires getting your CISO, your CFO, and whoever owns your AI spend in the same room, asking what your actual threat model is, and being honest about which workflows can move to a lower-cost model and which ones need a contract, not just a promise, behind them.

    Each seat at the table owns a different piece of this:

    • The CFO owns the number, and needs to know it is not a fixed cost, it is a usage curve that can bend the wrong way fast.
    • The CTO owns the routing decision, and needs the technical case for why one workflow can move to a cheaper model and another cannot.
    • The COO owns what breaks operationally if a vendor’s pricing or availability shifts under a live process.
    • The CHRO owns the harder conversation about what “your alpha” actually means: the institutional knowledge sitting in your best people’s heads that a model trained on your prompts could quietly learn to replicate.
    • The CEO owns the fact that this is now a competitive question, not just an IT budget line.

    What does your organization actually know about where its token spend goes, and what it is protecting on the way there?


    Sources cited:

    • Vercel, “Open-weight models surge to 29% of volume, price per token flattens,” AI Gateway Production Index, July 2026. https://vercel.com/blog/ai-gateway-production-index-july-2026
    • CNBC, “Chinese AI models are gaining ground with U.S. companies as OpenAI, Anthropic costs surge,” July 7, 2026. https://www.cnbc.com/2026/07/07/chinese-ai-models-costs-us-openai-anthropic.html
    • CNBC, “Palantir’s Karp bashes token-based AI model as ‘completely wrong,’” Alex Karp on Squawk Box, July 1, 2026. https://www.cnbc.com/2026/07/01/palantir-karp-open-ai-anthropic-tokens.html
    • Morningstar, “Thomson Reuters, RELX, and Wolters Stocks Crushed After Anthropic Debuts Claude Legal Plug-In,” February 2026. https://www.morningstar.com/stocks/reuters-relx-wolters-stocks-crushed-after-anthropic-debuts-claude-legal-plug-in
    • CNBC, “OpenAI cuts prices for two of its GPT-5.6 AI models as companies grow sensitive to costs,” July 30, 2026. https://www.cnbc.com/2026/07/30/open-ai-price-cut-gpt.html
    • VentureBeat, “AI price wars: OpenAI cuts GPT-5.6 Luna prices by 80% as model competition shifts toward cost,” July 2026. https://venturebeat.com/technology/ai-price-wars-openai-cuts-gpt-5-6-luna-prices-by-80-as-model-competition-shifts-toward-cost
  • See Everything (Because Black Boxes Don’t Get Approved)

    This is Part 5. Start here if you’re new to the series.

    In Part 4, we covered model flexibility, Task Personas, and practical RAG. But none of that matters if your security team won’t approve deployment. And they won’t approve what they can’t inspect.

    The Black Box Problem

    When companies fail with AI, it’s often not the technology—it’s the inability to answer basic questions. IBM’s 2025 Cost of Data Breach Report found 97% of AI-related breaches involved systems lacking proper access controls.

    The Questions You’ll Face

    From Security: What data accessed? What tools ran? Where did output go? From Legal: How did AI arrive at this decision? Where’s the audit trail? From Compliance: Which model version? What guardrails were active? From Audit: What happened step-by-step? Can I export this?

    See Everything: Chiri Brain’s Answer

    1. What Data Did It Retrieve?

    Every RAG retrieval logged with document IDs, specific passages, relevance scores, timestamps, user context. Click through from answers to see exact source material. Export full retrieval chain for audit.

    Example: Security asks “Did this AI access patient records inappropriately?” You show them query, retrieved collection (approved general protocols), did NOT retrieve patient records, audit trail immutable/timestamped/exportable.

    2. What Tools Did It Run?

    Every tool invocation logged: tool name/version, input parameters, output returned, success/failure, duration, user/context.

    IBM 2025 data context: Unauthorized AI use compounds data risks. With Chiri Brain: see APIs called, review parameters, verify no unauthorized systems accessed, audit tool usage against policy.

    3. Which Persona/Guardrails Applied?

    Every interaction tagged with Task Persona name/version, system prompt in effect, allowed tools, output formats, active guardrails, Git-like diff if persona changed.

    Example: Legal asks about instructions when generating customer communication. You show Task Persona version, key guardrails (PII redaction, citation required), full diff from previous version.

    4. Which Model Was Called, and When?

    Every model invocation logged: model name/provider/version, temperature/parameters, tokens used, response time, cost.

    5. What Happened Step-by-Step?

    Complete execution trace showing: request received, planning, retrieval, tool invocations, generation, validation, response delivered. Every step timestamped, logged, exportable, immutable.

    What This Enables

    For Security: Incident response with exact traces. Proactive monitoring with alerts. For Legal: Defensible decisions with full chain. Policy enforcement verification. For Audit: Efficient reviews querying full dataset. Continuous compliance monitoring. For Compliance: Regulatory confidence. EU AI Act transparency logs. HIPAA data access proofs.

    The Bottom Line

    When McKinsey’s 2025 survey shows only 6% are high performers and IBM finds 63% lack governance policies, it’s because existing tools make governance hard instead of natural. Chiri Brain treats transparency as the foundation.

    In Part 6, we’ll cover how visibility becomes enterprise-grade controls for humans and agents.

  • Clawdbot (Moltbot) Went Viral. So Did Its Security Holes.

    Clawdbot (now rebranded as Moltbot) exploded onto the scene over the past week. 60,000+ GitHub stars. Viral X threads. Discord communities buzzing. The promise is intoxicating: a personal AI assistant that lives in your messaging apps, remembers everything, and executes tasks autonomously.

    Then the security reports started rolling in.

    Within days, researchers found hundreds of exposed control panels on the public internet. API keys. Private chat histories. OAuth credentials. And in some cases, full command execution with root privileges.

    This is the AI agent security problem in miniature, and it doesn’t matter if you’re a Fortune 500 enterprise or a solopreneur tinkering with the future of personal assistants: the risks are structural, not incidental.

    What Clawdbot Actually Is (And Why That’s the Problem)

    Clawdbot isn’t a chatbot. It’s an agent gateway that bridges large language models to your messaging platforms (Telegram, Slack, Discord, Signal, WhatsApp) and local system capabilities. It can read and write files, execute shell commands, authenticate to third-party services, and maintain long-term memory.

    This architecture is powerful. It also collapses multiple security boundaries into a single system.

    As SOCRadar’s analysis put it: once deployed, Clawdbot becomes part of your attack surface, not just another tool in your stack.

    The project’s own documentation is refreshingly honest:

    “Running an AI agent with shell access on your machine is… spicy. There is no ‘perfectly secure’ setup.”

    That honesty is commendable. But it doesn’t reduce your exposure.

    The Real-World Damage (So Far)

    The findings from SlowMist, Jamison O’Reilly, and others paint an alarming picture:

    Exposed credentials everywhere. Shodan scans reveal over 1,000 Clawdbot gateways accessible on the public internet. Many expose Anthropic API keys, Telegram bot tokens, OAuth secrets, and months of private conversation history.

    Remote code execution. In multiple instances, researchers found systems with command execution enabled and no authentication. One AI software agency’s exposed server was running with root privileges and no privilege separation.

    Prompt injection to private key extraction in five minutes. The CEO of Archestra AI demonstrated how a simple prompt injection attack (via an email the bot was asked to check) led to extraction of a private key from the compromised machine.

    Crypto scammers exploited the chaos. During the trademark-driven rebrand from Clawdbot to Moltbot, scammers hijacked old accounts and launched fake $CLAWD tokens that hit a $16M market cap before collapsing to near zero, leaving late buyers rugged.

    The “Confused Deputy” Problem for AI Agents

    The UK’s National Cyber Security Centre (NCSC) has been clear about this threat model: prompt injection should be treated like a confused deputy problem, where a privileged system can be coerced into acting on an attacker’s behalf.

    Clawdbot (by design) becomes that privileged system:

    • It can see what you see (folders, docs, messages)
    • It can act where you can act (tools with your account permissions)
    • It can be exposed to content you shouldn’t trust (web pages, emails, attachments)

    Security researcher Simon Willison calls this the “lethal trifecta”: private data + untrusted content + external communication. Combine all three and exploitation becomes inevitable.

    Clawdbot’s entire product value moves you closer to that trifecta.

    Why This Matters for Everyone (Not Just Enterprises)

    You might think: “I’m just a solopreneur playing around. This doesn’t apply to me.”

    It does. Here’s why:

    Your API keys are money. If your Anthropic or OpenAI keys leak, someone else runs up your bill. Or worse, use your account for abuse that gets traced back to you.

    Your message history is intelligence. Private conversations with clients, financial details, business strategy, personal information: all potentially exposed.

    Your credentials are accessible. OAuth tokens for Slack, Google, or other integrations don’t just expose one system. They expose everything those accounts can reach.

    Your system is a launchpad. A compromised machine with shell access becomes a pivot point for lateral movement, persistence, or further attacks.

    The difference between an enterprise breach and a solopreneur breach is scale, not severity. Your digital life can be upended just as completely.

    The Chiri Approach: Security as Architecture, Not Afterthought

    At Chiri, we’ve been thinking about this problem since long before Clawdbot went viral. When we analyzed Claude Cowork’s attack surface, we applied the same lens we apply to every AI tool: if you can’t answer the “must-haves” with evidence, you’re carrying too much risk.

    Our CISO, Mark Aklian’s AI security checklist forces the uncomfortable questions:

    • Architecture transparency: Where does the model run? Which tools are active? What third-party dependencies exist?
    • Data flow and retention: Are prompts and outputs logged? For how long? Used for training?
    • Guardrails against abuse: Prompt injection defenses, retrieval allowlists, output filtering, abstention on low confidence
    • Tool and agent safety: Sandboxing, controlled egress, scoped credentials, least-privilege function calling
    • Governance and change management: Version control, approvals, rollback, audit trails
    • AI incident response: Playbooks for injection, exfiltration, and model regressions, plus forensics retention

    Clawdbot, by its own admission, can’t satisfy most of these requirements out of the box. And that’s the point: these aren’t features you “add later.” They’re architecture you build from day one, or you don’t have them at all.

    Chiri Brain: The Control Plane That Changes the Game

    This is exactly why we built Chiri Brain.

    The Chiri Standard treats governance as a first-class system:

    Transparent. Every interaction produces execution traces. You can answer “what did the AI access?” with evidence, not guesses.

    Flexible. One interface, multiple models. Switch providers without rebuilding your infrastructure.

    Controlled. Task Personas turn best practices into versioned, enforceable behaviors. Guardrails apply automatically, not when someone remembers.

    Compliant. Every action logged, every access controlled, every query traceable. Immutable audit trails for when regulators (or incident responders) come knocking.

    Yours. Deploy cloud or self-host. Bring your models. Your data stays your data.

    This isn’t a “nice to have” layer on top of powerful AI. It’s the difference between a tool that works until it doesn’t and infrastructure you can actually trust.

    If You Want to Experiment: Stay Current on Security

    Clawdbot/Moltbot is genuinely innovative technology and we understand the appeal of experimenting with it. But the security landscape is evolving rapidly, and what’s “safe enough” today may not be tomorrow. If you choose to deploy it, staying current on security guidance isn’t optional.

    Here are three reliable sources to follow:

    1. Official Clawdbot Security Documentation docs.clawd.bot/gateway/security

    This is the authoritative source from the project maintainers themselves. It covers the trust hierarchy model, device authentication, reverse proxy configuration pitfalls, tool sandboxing options, and the built-in clawdbot security audit command. The documentation is refreshingly candid about risks (they explicitly acknowledge there’s “no perfectly secure setup”) and provides concrete hardening steps. Start here before you deploy anything.

    2. SOCRadar’s Technical Analysis socradar.io/blog/clawdbot-is-it-safe/

    SOCRadar is a well-established cyber threat intelligence firm. Their analysis goes beyond surface-level concerns to examine Clawdbot’s architecture, explain why the gateway design creates concentrated risk, and document real-world exposure data from Shodan scans. They provide the kind of independent, security-researcher perspective that helps you understand risks the project maintainers might not emphasize. This is the analysis to read if you want to understand the structural security challenges of AI agent gateways.

    3. Hudson Rock’s Infostealer Threat Intelligence infostealers.com/article/clawdbot-the-new-primary-target-for-infostealers-in-the-ai-era/

    Hudson Rock specializes in tracking infostealer malware campaigns and compromised credentials. Their analysis shifts the lens from “how might Clawdbot be attacked?” to “how are attackers already adapting?” They document how major Malware-as-a-Service families (RedLine, Lumma, Vidar) are updating their target lists to sweep Clawdbot’s plaintext config files. They also introduce the concept of “Memory Poisoning,” where attackers with write access can permanently alter your AI’s behavior. This is essential reading for understanding the active threat landscape, not just theoretical vulnerabilities.

    The Bottom Line

    Clawdbot’s viral moment is also a warning. The AI agent era is arriving fast, and the tools are outpacing the controls.

    The question isn’t “Is Clawdbot secure?” The question is: Can you prove you have the controls to make any autonomous agent safe enough for your workflows?

    If you’re building with AI agents, whether at enterprise scale or as a solopreneur experimenting on nights and weekends, security, auditability, and traceability aren’t optional extras. They’re the foundation.

    That’s why we built Chiri Brain: to give you the power of AI agents without the chaos.

    Because capability without control is indistinguishable from exposure.


    Ready to take AI security seriously? Learn more about Chiri Brain or reach out to talk with our team.

  • Chiri Brain: Any Model. One Interface. No Lock-in.

    This is Part 4 of our series on Chiri Brain capabilities. Read Parts 1-3 to catch up.

    We’ve established why AI projects fail and what infrastructure looks like when governance is built-in. Now let’s talk about what that gets you.

    Any Model. One Interface. No Lock-in.

    The reality six months later: You’ve built workflows around a vendor’s API, integrated their SDKs, trained your team on their quirks. Then a better model ships, costs spike, or compliance requires self-hosting.

    The Lock-In Tax (2025 data):

    • Financial costs: Egress fees, migration engineering (6-12 months), parallel running costs
    • Technical barriers: Vendor-specific APIs with no equivalents, proprietary data formats
    • Organizational friction: Teams resist change after investing in learning

    How Chiri Brain eliminates this: Multi-model by design. Switch mid-conversation. Council Mode (parallel models, compare reasoning). Bring your own models. When McKinsey’s 2025 survey shows organizations redesigning workflows are 2x more likely to see returns, Chiri Brain lets you be problem-focused because you’re not locked to technology.

    AI That Knows Its Role: Task Personas

    The problem: MIT’s 2025 research shows misunderstandings about project purpose are the most common AI failure reason.

    A Task Persona includes:

    1. System prompts + task definitions
    2. Allowed skills/tools (auto-enforced)
    3. Output formats
    4. Guardrail constraints
    5. Git-like version history

    What This Gets You:

    • Consistency without homogenization
    • Knowledge that compounds across teams
    • Governance that scales (compliance updates once, applies everywhere)
    • Onboarding that works (new members get proven approaches day 1)
    • Audit trails that satisfy regulators

    RAG That Doesn’t Feel Like a Science Project

    What teams need: Upload documents. Organize collections. @mention what the AI should reference. Get answers with citations. Share collections with proper access control.

    How Chiri Brain makes this simple:

    • Drag and drop documents
    • @mention specific docs or collections
    • Get cited answers (click through to verify sources)
    • Knowledge stops being trapped; sales creates proposal collection, new reps @mention for guidance

    When S&P Global reports 46% of POCs scrapped before production, Chiri Brain makes RAG deployment immediate, sharing trivial, auditing complete, and governance automatic.

    In Part 5, we’ll cover what makes this trustworthy enough to deploy: observability that lets black boxes get approved.

  • The Chiri Standard: Trusted AI at Scale

    This is Part 3 of our series on enterprise AI infrastructure. Read Part 1 and Part 2 if you’re catching up.

    In Parts 1 and 2, we established the problem: MIT reports 95% of AI pilots fail, S&P Global shows 42% of companies abandoned initiatives in 2025, and McKinsey found only 6% achieve high performance, all driven by six systemic issues around governance, vendor lock-in, knowledge fragmentation, lack of standardization, security gaps, and compliance nightmares.

    The market’s response? Tools that optimize for speed now, leaving you with risk later. Or tools that optimize for control now, leaving you paralyzed indefinitely.

    Chiri Brain takes a different approach entirely: we treat governance as a first-class system, not a bolt-on feature.

    The Standard We’re Built Around

    Most enterprise AI platforms ask: “How can we make this work within existing governance constraints?” Chiri Brain asks: “What would an AI infrastructure look like if governance was the starting point, not an afterthought?”

    Here’s what emerged:

    1. Transparent: See What Happened and Why

    Why it matters: The EU AI Act requires organizations to explain AI decisions (enforcement 2026, fines up to €35 million). The NYC AI bias audit law requires transparency in hiring tools. NAVEX’s September 2025 research shows complexity and opacity of AI models make accountability hard to enforce.

    IBM’s 2025 data: 97% of AI-related breaches lacked proper access controls. When security asks “what data did this model access?”, most platforms can’t answer precisely.

    How Chiri Brain solves this: Every interaction produces execution traces that are searchable, exportable, granular (not just “what” but “why”), and permanent. This is how you move from “we think it accessed these documents” to “here’s the exact trace of what happened.”

    2. Flexible: One Interface, Multiple Models

    Why it matters: When S&P Global reports that the average organization scrapped 46% of AI proof-of-concepts before production, one major factor was infrastructure that couldn’t adapt as requirements changed.

    How Chiri Brain solves this: Switch models mid-conversation, run models in parallel (Council Mode), bring your own models, no API lock-in. When GPT-5 ships or Claude 4 improves, you configure, you don’t rebuild.

    3. Controlled: Guardrails That Enforce Themselves

    Why it matters: MIT’s 2025 research found that misaligned expectations are a leading AI failure cause. When best practices live in someone’s head, they don’t scale.

    How Chiri Brain solves this: Task Personas turn best practices into versioned, shareable, enforceable AI behaviors with system prompts, allowed tools, output formats, guardrail constraints, and Git-like version history.

    4. Compliant: Built for Audit from Day One

    Why it matters: IBM’s 2025 report shows 63% of organizations lack AI governance policies. Organizations with AI-driven security save $1.9 million per breach by speeding detection.

    How Chiri Brain solves this: Every action logged, every access controlled, every query traceable. Scoped access to audit events, compliance review interfaces, retention controls built in.

    5. Yours: Deploy Your Way

    Why it matters: Some data can’t leave your infrastructure. Some regulations require self-hosting. Some teams need cloud convenience.

    How Chiri Brain solves this: Deploy cloud, self-host, or hybrid. Bring your models. Your data, your rules.

    The Bottom Line

    When MIT reports 95% failure and McKinsey shows only 6% are high performers, the solution isn’t better models. It’s better infrastructure.

    The Chiri Standard – Transparent, Flexible, Controlled, Compliant, Yours – isn’t aspirational. It’s architectural. These aren’t features we added. They’re constraints we designed around from day one.

    In Part 4 of this series, we’ll show you exactly what you can build when your AI infrastructure treats governance as a first-class concern.


    Next: Part 4: Any Model. One Interface. No Lock-in.

  • Claude Cowork Is Having a Moment. Your Attack Surface Is Too.

    Anthropic just shipped Claude Cowork as a research preview – a “Claude Code-like” experience for general productivity work, delivered through the Claude macOS app and aimed at making Claude feel less like a chatbot and more like a real coworker.

    That framing is…accurate. And it’s the security problem.

    When an AI crosses the line from “talking about work” to “doing work” – reading folders, editing files, and taking actions inside third‑party tools – the threat model changes fast. Anthropic even says the quiet part out loud: Cowork can take “destructive actions” (including deleting files) if you aren’t specific, and it can be affected by prompt injection.

    So let’s treat this like we treat any new “power tool” in the enterprise: capabilities first, controls second is how you end up with incident response playbooks in your Slack bookmarks.

    At Chiri, our AI security stance is simple: if you can’t answer the “must haves” with evidence, you’re carrying too much risk.

    Claude Cowork is the perfect case study for why.


    Cowork isn’t “another AI feature.” It’s a permission model.

    From the public descriptions, Cowork is built around three big capabilities:

    1. Local access: you can grant Claude access to folders on your Mac so it can work with your files (organize, extract, draft, create).
    2. Tool access: you can connect Claude to external services (connectors) so it can read and write in tools like productivity, business, automation, and developer platforms.
    3. Agentic execution: it can run multi‑step tasks with less hand‑holding, i.e., “do the thing,” not “tell me how to do the thing.”

    That’s not a UI upgrade. That’s a new operator sitting in your environment.

    And operators need controls.


    The real risk: your AI coworker is a “confused deputy” with your credentials

    The UK’s National Cyber Security Centre (NCSC) has been blunt about where this is heading: prompt injection should be treated less like “SQL injection” and more like a confused deputy problem – where a privileged system can be coerced into doing something on an attacker’s behalf.

    That matters because Cowork (by design) becomes a privileged system:

    • It can see things you can see (folders, docs, screenshots).
    • It can act where you can act (connectors with your account permissions).
    • It can be exposed to content you should not trust (web pages, documents, messages, tickets). And Anthropic explicitly calls out prompt injection as a live risk.

    Simon Willison’s “lethal trifecta” for agents is the cleanest way to remember the danger: private data + untrusted content + external communication. Combine all three and you get exploitation opportunities, even if the model is “pretty good” at resisting attacks.

    Cowork’s entire product value is moving you closer to that trifecta.


    The five security risks that matter (and why they’re easy to miss)

    Risk #1: Over‑permissioning becomes the default “setup step”

    Cowork works when you give it access. That’s the point.

    But here’s how this goes in real life:

    • A user selects “Documents” instead of “/Cowork‑Workspace”
    • Or connects a tool with broad org permissions (because that’s what their account already has)
    • Or adds “just one more connector” because it’s convenient

    Anthropic’s own connectors guidance is clear: when you connect a tool, you’re granting Claude permission to access and potentially modify data in that service based on your account permissions.

    That’s the same mistake companies made for a decade with OAuth apps and browser extensions – except now the “app” is an agent that can chain actions together.

    Translation: the “blast radius” is not Cowork. The blast radius is your identity.


    Risk #2: Prompt injection turns into real‑world data loss and exfil

    OWASP ranks prompt injection as the #1 risk category for LLM systems for a reason: it’s not just “bad answers.” It’s manipulated behavior.

    Anthropic itself says prompt injection remains a major security challenge for agents operating on untrusted content, and explicitly notes it’s “far from a solved problem,” even with improved robustness and safeguards.

    Now connect that to Cowork:

    • Cowork can read untrusted content (web, tickets, docs)
    • Cowork can access private data (your folder + connectors)
    • Cowork can take actions (create/edit/delete/share)

    Anthropic warns that unclear instructions can lead Claude to delete files, and also warns about prompt injection risk.

    And this is not theoretical. SafeBreach researchers demonstrated “promptware” attacks against Gemini for Workspace – using something as simple as a malicious calendar invite to trigger harmful behavior and sensitive data exposure.

    Different vendor, same pattern: an assistant that reads untrusted content and is wired into privileged workflows becomes a new exploitation layer.


    Risk #3: “Consumer plan” data handling + enterprise files is a dangerous mix

    Cowork is positioned (right now) as a Max‑subscriber feature on the macOS app.

    That matters because Anthropic’s consumer plans (Free/Pro/Max) have a data‑use decision point and different retention behavior depending on whether you allow data usage for model improvement.

    From Anthropic’s own update:

    • If you allow data to be used for model training, retention can extend (e.g., up to five years for new/resumed interactions in that policy update).
    • If you do not allow it, retention is described as continuing under their existing 30‑day period for those interactions.

    There are legitimate reasons vendors do this. The security point is simpler:

    If an employee points a consumer‑tier tool at sensitive corp folders, you’ve just created a shadow data pipeline that most orgs aren’t tracking, classifying, or governing.

    Which brings us to…


    Risk #4: Auditability lags behind autonomy

    When something goes wrong with an agent, the first question is not “why did the model do that?”. It’s:

    • What exactly did it touch?
    • What did it send out?
    • What did it change?
    • Can we prove it?
    • Can we roll it back?

    Most agent experiences are still catching up on:

    • Durable, queryable activity logs
    • Per‑action approvals for risky operations
    • Forensic retention of prompts, tool calls, retrieval snapshots, versions

    And that’s not a knock. It’s a maturity curve.

    But if you’re deploying this into regulated workflows, “it asked before doing something significant” is not an audit trail.


    Risk #5: Connectors create a supply chain – and custom connectors raise the stakes

    The connectors directory is explicitly designed to extend Claude’s capabilities with both local and remote connectors, including automation and business tools, plus custom connectors.

    Two key security realities:

    • A connector is effectively code + permissions + data path
    • Each connector expands your attack surface and dependency chain

    OWASP’s LLM risk work repeatedly points to the idea that injection-style attacks can ride through the system because instructions and data get mixed, and output/tool handling becomes the downstream exploit path.

    Anthropic’s help center explicitly warns that custom connectors may connect to services not verified by Anthropic and should only be connected to trusted organizations with carefully reviewed authentication permissions.

    Again: not a flaw. Just a reminder that connectors are a supply chain, and supply chains need governance.


    The Chiri lens: “AI security must‑haves” applied to Cowork

    Our CTO Mark Aklian’s “critical must haves” checklist is the right frame here because it forces the uncomfortable questions early – before the pilot becomes production.

    If you’re evaluating Cowork (or any “all‑access agent”), you should be able to answer, with evidence:

    • Architecture transparency: Where does the model run? Which agents/tools are active? Any third‑party AI dependencies?
    • Data flow & retention: Are prompts/outputs logged, how long, and used for training/evals – what are the controls?
    • Guardrails against abuse: Prompt injection defenses, retrieval allow‑lists, output handling, and abstention behaviors.
    • Tool/agent safety: Sandboxing, controlled egress, scoped credentials, least‑privilege function calling.
    • Governance & change management: Version control, approvals, rollback, audit trails on safety rules.
    • Testing & red‑teaming: Not once. Continuous. With real playbooks.
    • AI incident response: Playbooks + forensics retention designed for injection and exfil scenarios.

    This is why Chiri keeps hammering the same message: you don’t “bolt on” AI security later. It’s circuit breakers, not seatbelts.


    If you’re going to use Cowork, here’s how not to become a case study

    This is not vendor‑specific advice. It’s “agent hygiene.”

    For individuals and small teams

    • Create a dedicated, non‑sensitive workspace folder and only grant that folder (not “Documents,” not “Desktop,” not “Downloads”).
    • Start read‑only whenever possible (or at least do a dry run: ask it to propose changes before applying).
    • Connect the minimum set of tools you need. Remember: connectors inherit your account permissions.
    • Treat untrusted content as hostile (random PDFs, tickets, web pages). Prompt injection is specifically a risk for agents operating on content they can’t trust.

    For enterprises

    • Do not let “Max on a personal Mac” become the default deployment model.
    • Apply standard identity and device protections (Zero Trust basics): MFA, conditional access, device management, and data protection – because AI tools become “just another app” with privileged access.
    • Require a governance layer: approved connectors, scoped accounts, least privilege, logging, and review gates for high-impact actions.
    • Run a red-team playbook that explicitly targets: prompt injection, data exfil paths, destructive actions, and connector abuse.

    If you want an outside, non-vendor baseline: CISA/NSA/FBI guidance emphasizes that data security is foundational to trustworthy AI outcomes and should be secured across the AI lifecycle. And NIST’s AI RMF + GenAI profile are solid reference points for mapping governance to controls.


    Bottom line

    We’re in the early innings of “all‑access AI agents.”

    Claude Cowork is a glimpse of where productivity is going. It’s also a glimpse of where incidents are going.

    The question isn’t “Is Cowork secure?”

    The question is:

    Can your organization prove it has the controls to make an agent with file access + connector access + autonomy safe enough for your workflows?

    If the answer is “not sure,” start with the must‑haves checklist – and demand evidence, not vibes.

    This is just the start of making sure in the moment you’re thinking of security with agents. 

    For the long term, we’re building Chiri Brain which solves not only for the agentic issue – but much more. Check it out at https://chiri.ai/chiri-brain 

  • The Actual Problem Isn’t “AI.” It’s Everything Around AI.

    This is Part 2 of our series on why enterprise AI fails. Read Part 1 if you missed it.

    Enterprise teams aren’t blocked by model quality anymore. GPT-4, Claude Sonnet 4, Gemini Pro – pick your favorite, they’re all remarkably capable. The problem is that having a powerful engine doesn’t matter if you can’t get it approved, can’t switch when you need to, and can’t explain what it’s doing when regulators ask.

    MIT’s 2025 research on AI project failures paints a clear picture: It’s not the models. It’s everything around AI.

    The messy reality of deploying AI in the real world creates six systemic problems that kill projects faster than any technical limitation ever could.

    Problem #1: The Make-or-Buy Paradox

    Building for auditability and governance is slow; buying for speed creates governance gaps you can’t explain later.

    When Air India needed to scale customer service, they identified a specific constraint: their contact center couldn’t grow with passenger volume. Instead of buying a black-box solution, they built AI.g, their generative AI virtual assistant. Result? Over 4 million queries processed with 97% full automation.

    The lesson: They prioritized understanding what the system was doing over speed of deployment. McKinsey’s November 2025 AI survey confirms this pattern: organizations reporting “significant” financial returns are twice as likely to have redesigned end-to-end workflows before selecting modeling techniques.

    The hidden cost of buying: IBM’s 2025 Cost of Data Breach Report reveals that 97% of AI-related security breaches involved organizations that lacked proper AI access controls. When you buy a black box, you can’t inspect it. When you can’t inspect it, you can’t secure it.

    What Chiri does differently: Bring your own models, or use ours. Deploy cloud or self-host. Every action logged, every decision traceable. You get the speed of a managed service with the auditability of an in-house build, without having to choose one or the other.

    Problem #2: Vendor Lock-In

    Switching models often means rebuilding workflows and integrations from scratch.

    The AI landscape is creating what multiple 2025 industry reports call “a new era of cloud vendor lock-in.” Organizations are either sticking with their current provider and only using the AI tools it offers, or spending significant money and time ensuring data is optimized for migrating between clouds.

    The financial reality: According to cloud security analysts in 2025, switching cloud providers isn’t just technically complex, it’s financially punishing:

    • Egress fees for moving data out
    • Migration engineering time (6-12 months typical for complex applications)
    • Parallel running costs during transition
    • Lost optimizations when APIs don’t have direct equivalents

    What Chiri does differently: Any model. One interface. No lock-in. Run models in parallel, switch mid-conversation, or compare outputs side-by-side (Council Mode). Use the best model for each job. Change your mind later without re-platforming. Your workflows aren’t tied to a vendor’s API, they’re portable by design.

    Problem #3: Knowledge Fragmentation

    Working solutions live inside teams, not as shared, reusable building blocks.

    MIT’s 2025 research identified misaligned expectations and vague objectives as leading causes of AI failure. When knowledge is trapped in individual implementations, organizations can’t scale what works.

    The pattern: A data science team builds a brilliant RAG implementation. It works perfectly for their use case. Six months later, another team tries to solve a similar problem and starts from scratch because:

    • The solution isn’t documented as a reusable pattern
    • The prompts and configurations aren’t version-controlled
    • There’s no shared library of what works
    • Every team becomes their own prompt engineering department

    What Chiri does differently: Task Personas turn best practices into versioned, shareable, enforceable AI behaviors. System prompts + task definitions, allowed tools, output formats, guardrail constraints, and Git-like version history. When one team solves a problem well, every team benefits. RAG collections are shareable across the org, knowledge stops being trapped in private setups.

    Problem #4: No Standardization

    A dozen tools, a dozen ways of working, no collaboration layer.

    MetricStream’s 2025 GRC Practitioner Survey found that only 13.76% of organizations have actually integrated AI into their GRC frameworks. The gap? Lack of standardization across teams and tools.

    The compound effect:

    • Team A uses one vendor’s API structure
    • Team B uses a different approach entirely
    • Team C has built custom tooling
    • GRC can’t audit any of them consistently
    • Security can’t enforce policies across all three
    • Nobody can share learnings or compare results

    Integration challenges reported in 2025: 47.75% of GRC professionals cite “integration with existing systems and workflows” as their top AI challenge, while 45.95% report a “lack of skilled talent to manage AI systems.”

    What Chiri does differently: One interface for all models. One approach to RAG. One way to define tasks and guardrails. One audit trail format. One permission model. This isn’t about constraining creativity, it’s about creating a foundation that lets teams innovate without fragmenting governance.

    Problem #5: Enterprise Security Gaps

    Weak isolation, coarse permissions, insufficient controls.

    IBM’s August 2025 Cost of Data Breach Report contains devastating statistics:

    • 63% of breached organizations had no AI governance policies
    • 97% of AI-related security breaches involved systems lacking proper access controls
    • Shadow AI (unauthorized AI use) added an average of $670,000 to breach costs
    • One in five organizations reported breaches involving shadow AI

    The shadow AI problem: When employees use unauthorized AI tools with corporate data because approved tools don’t work, security gaps compound. IBM found that breaches involving shadow AI were more likely to result in compromise of personally identifiable information (65%) and intellectual property (40%).

    Real-world impact: The average global data breach cost in 2025 was $4.44 million, but for organizations with high levels of shadow AI, costs were significantly higher. In the US specifically, breach costs hit $10.22 million, the highest anywhere.

    What Chiri does differently: Hybrid RBAC + ABAC policy engine with context-aware decisions. Tenant isolation including database-level controls. Shareable document collections with granular access control. PII guardrails that detect and protect sensitive data in both input and output, with customizable strategies (redaction, masking, hashing, blocking). This is enterprise-grade security, not retrofitted access controls.

    Problem #6: Compliance Nightmares

    Missing audit trails and execution visibility when it matters most.

    The EU AI Act is now enforceable with fines up to €35 million or 7% of global revenue. The regulatory landscape in 2025 is accelerating:

    • 480+ state-level AI bills enacted in the US as of 2025
    • EU AI Act enforcement beginning 2026 with risk-based classifications
    • 38 states have enacted approximately 100 AI-related laws
    • New requirements for hiring bias audits, algorithmic discrimination prevention, and data privacy

    The compliance disconnect: NAVEX’s September 2025 research shows that while regulations multiply, organizational readiness lags. Only 18% of organizations have an enterprise-wide AI governance council, and compliance teams can’t audit what they can’t see.

    The black box problem: When security, legal, and audit ask questions, “the model decided” isn’t an acceptable answer. You need to show:

    • What data did it retrieve?
    • What tools did it run?
    • Which persona/guardrails applied?
    • Which model was called, and when?
    • What happened step-by-step?

    What Chiri does differently: Every interaction produces execution traces you can review, search, and export. Answer the questions security, legal, and audit will ask, before they ask them. Immutable logs, scoped access to audit events, compliance review interfaces, and retention controls built in.

    The Result Is Predictable

    Pilots proliferate. Risk piles up. The organization can’t scale what works.

    The 2025 reality check:

    • MIT: 95% of generative AI pilots fail
    • S&P Global: 42% of companies abandoned most AI initiatives (up from 17% in 2024)
    • McKinsey: Only 6% of organizations qualify as “AI high performers”
    • IBM: 63% lack AI governance policies

    When 42% of companies abandoned their AI initiatives in 2025, it wasn’t because the AI was bad. It was because everything around the AI made it impossible to deploy responsibly at scale.

    What Actually Works

    McKinsey’s 2025 survey identifies what separates the 6% of high performers from everyone else:

    1. They target enterprise-wide transformation, not incremental efficiency
    2. They redesign workflows before selecting models (2x more likely than low performers)
    3. They set growth and innovation objectives, not just cost reduction
    4. They invest substantially and systematically in AI capabilities
    5. They implement disciplined management practices with clear KPIs

    WorkOS’s July 2025 analysis confirms: organizations that succeed “begin with unambiguous business pain, invest disproportionately in trustworthy observable data pipelines, choreograph human oversight as a feature, and operate AI as living products with on-call rotations and success metrics tied to real dollars.”

    In other words: they didn’t just deploy AI. They built the infrastructure to govern it.

    In Part 3 of this series, we’ll show you what that infrastructure looks like when it’s built into the platform from day one, not bolted on as an afterthought.


    The bottom line: Your AI isn’t failing because the models aren’t good enough. It’s failing because you’re solving six problems individually that should be solved systemically. The winners will be the organizations that stop optimizing for “fast” or “safe” and start building for both.

  • Where AI Rollouts Go to Die: The Two Places Enterprise AI Fails

    The Numbers Don’t Lie

    MIT’s 2025 State of AI in Business report dropped a statistic that should terrify every executive: 95% of generative AI pilots fail to deliver measurable impact on the P&L. Read that again. Ninety-five percent.

    S&P Global Market Intelligence makes it worse: 42% of companies abandoned most of their AI initiatives in 2025, up from just 17% the previous year. The average organization scrapped 46% of AI proof-of-concepts before they reached production.

    These aren’t startups experimenting with bleeding-edge tech. These are enterprises with dedicated AI teams, consultants on retainer, and budgets in the millions.

    McKinsey’s November 2025 Global Survey confirms the pattern: while 88% of organizations now use AI in at least one function, only 39% report any measurable EBIT impact. And among those, most attribute less than 5% of their organization’s EBIT to AI.

    So what’s killing these projects?

    Most AI Rollouts Die in One of Two Places

    Death #1: They Move Fast…But Security/Governance Can’t Sign Off

    Picture this: Your engineering team builds a brilliant AI workflow that could save 20 hours per week. It works in the demo. Users love it in testing. Then it hits the enterprise approval gauntlet.

    Security asks: “What data is it accessing? How is PII being handled?”
    Legal asks: “Where’s the audit trail? Can we prove compliance?”
    GRC asks: “What happens when the model hallucinates? Who’s accountable?”

    The answers? Often buried in vendor documentation that contradicts itself, or worse, “trust us, the black box handles it.”

    The 2025 data is stark: IBM’s Cost of Data Breach Report found that 97% of organizations experiencing AI-related security breaches lacked proper AI access controls. Among all breached organizations, 63% had no AI governance policies in place.

    The EU AI Act, enforced starting 2026, carries fines up to €35 million or 7% of global revenue for non-compliance. NAVEX’s 2025 research shows only 18% of organizations have an enterprise-wide council authorized to make decisions on responsible AI governance.

    When governance teams can’t verify what an AI system is doing, they can’t approve it. Period.

    Death #2: They Move Safely…But Everyone Loses Momentum

    The flip side is equally deadly. Some organizations react to the governance challenge by building elaborate approval processes, vendor evaluation frameworks, and compliance checkpoints.

    Six months later, they’re still in “pilot purgatory.”

    WorkOS’s July 2025 analysis reports that Gartner predicts over 40% of agentic AI projects will be canceled by 2027 due to escalating costs, unclear business value, or inadequate risk controls.

    McKinsey’s 2025 survey shows that nearly two-thirds of organizations haven’t begun scaling AI across the enterprise. They’re stuck experimenting or piloting – testing AI in isolated pockets without deep integration into workflows.

    The result: By the time approval comes through, the team has moved on, the business need has evolved, and the technology has been superseded. Air India’s success with AI.g (processing over 4 million queries with 97% automation) came from identifying a specific constraint and building AI they could understand and control – not buying speed and hoping for the best.

    The Tradeoff That Looks Inevitable (Until It Isn’t)

    If you’re feeling this tension right now, you’re not alone. The modern enterprise AI stack is full of tradeoffs that seem inevitable:

    • Speed vs. Control: Move fast and break compliance, or move carefully and lose competitive advantage?
    • Innovation vs. Auditability: Use cutting-edge models that security can’t inspect, or stick with legacy systems they trust?
    • Flexibility vs. Governance: Give teams autonomy to experiment, or enforce standards that strangle creativity?

    These feel like fundamental tensions because that’s how the market has positioned them. Every vendor tells you to pick your poison:

    • “Use our managed AI service – it’s fast!” (but you can’t inspect it)
    • “Build your own AI stack – it’s controlled!” (but it takes 18 months and $2M)
    • “Deploy these point solutions – they solve specific problems!” (but now you have 12 ungoverned tools)

    Here’s What Nobody Tells You

    You don’t actually have to choose.

    The problem isn’t AI. It’s not even governance. The problem is that most enterprise AI tools treat governance as a bolt-on feature – something you retrofit after the fact, if you’re lucky. They optimize for either speed (and leave you exposed) or safety (and leave you paralyzed).

    But what if an AI platform was built from the ground up with both in mind?

    What if you could:

    • Switch between models mid-conversation without rebuilding workflows?
    • See exactly what data was retrieved, what tools were run, and why?
    • Deploy agents with pre-configured guardrails that automatically enforce policy?
    • Give your GRC team the audit trails they need without slowing down your engineers?
    • Self-host the whole thing if your compliance team requires it?

    That’s not a hypothetical. It’s a design choice.

    In our next post, we’ll break down the six specific problems that create this false choice between innovation and governance – and why none of them are actually about AI.


    The bottom line: When 42% of companies are abandoning AI initiatives (S&P Global, March 2025), the problem isn’t the technology. It’s the infrastructure around it. The winners aren’t the ones with the best models. They’re the ones who figured out how to get both velocity and governance without compromising either. Part 2 of this series: “The Actual Problem Isn’t ‘AI.’ It’s Everything Around AI.” explores the six systemic issues that create these failure modes – and what you can do about them.

  • Stop Choosing Between Innovation and Governance: Meet Chiri Brain

    Most AI rollouts die in one of two places:

    1. They move fast…but security/governance can’t sign off.
    2. They move safely…but everyone loses momentum inside a maze of approvals, vendor constraints, and half-integrated tools.

    If you’re feeling that tension right now, you’re not alone. The modern enterprise AI stack is full of tradeoffs that look inevitable until you decide they aren’t.

    Chiri Brain is built on a simple idea:

    You shouldn’t have to choose between AI velocity and enterprise governance. You can get both.

    The actual problem isn’t “AI.” It’s everything around AI.

    Enterprise teams aren’t blocked by model quality anymore. They’re blocked by the messy reality of deploying AI in the real world:

    • The make-or-buy paradox: Building for auditability and governance is slow; buying for speed can create governance gaps you can’t explain later.
    • Vendor lock-in: Switching models often means rebuilding workflows and integrations from scratch.
    • Knowledge fragmentation: Working solutions live inside teams, not as shared, reusable building blocks.
    • No standardization: A dozen tools, a dozen ways of working, no collaboration layer.
    • Enterprise security gaps: Weak isolation, coarse permissions, insufficient controls.
    • Compliance nightmares: Missing audit trails and execution visibility when it matters most.

    The result is predictable: pilots proliferate, risk piles up, and the organization can’t scale what works.

    The Chiri Standard: Trusted AI at scale

    Chiri Brain is an “AI OS” because it treats governance as a first-class system, not a bolt-on.

    Here’s the standard it’s built around:

    • Transparent: See what the AI found, why it answered the way it did, and what actions it took.
    • Flexible: One interface, multiple models: switch mid-conversation or compare in parallel.
    • Controlled: Define Task Personas that constrain behavior and enforce guardrails automatically.
    • Compliant: Every action logged, every access controlled, every query traceable.
    • Yours: Deploy cloud or self-host. Bring your models, your data, your rules.

    This is how you stop treating AI like a “tool” and start treating it like infrastructure.

    What you can do with Chiri Brain

    Any model. One interface. No lock-in.

    Use the best model for the job then change your mind later without replatforming. Run models in parallel when answers matter and compare outputs side-by-side (Council Mode).

    AI that knows its role (Task Personas)

    Most companies eventually discover the hard way: “just prompt it better” doesn’t scale.

    Task Personas turn best practices into versioned, shareable, enforceable AI behaviors:

    • System prompts + task definitions
    • Allowed skills/tools
    • Output formats
    • Permissibility/guardrail constraints
    • Git-like version history

    This is how you get consistency across teams without turning every user into a prompt engineer.

    RAG that doesn’t feel like a science project

    Upload files. Organize shareable document collections. @mention what you want the AI to use. Get answers with citations.

    The point isn’t “we have RAG.” The point is: knowledge stops being trapped in one team’s private setup and becomes reusable across the org.

    See everything (because black boxes don’t get approved)

    Chiri Brain is designed so you can answer the questions security, legal, and audit will ask:

    • What data did it retrieve?
    • What tools did it run?
    • Which persona/guardrails applied?
    • Which model was called, and when?
    • What happened step-by-step?

    Every interaction produces execution traces you can review, search, and export.

    Enterprise-grade controls for humans and agents

    If you want agents in production, you need more than “good prompts.” You need real authorization and governance.

    Chiri Brain includes:

    Authorization

    • Hybrid RBAC + ABAC policy engine
    • Context-aware decisions (time, IP, etc.)
    • 2FA and restrictions built in

    Data security

    • Tenant isolation (including database-level controls)
    • Shareable doc collections with access control
    • Flexible deployments (cloud or self-host)

    Governance

    • Scoped access to audit events
    • Compliance review interfaces
    • Traceability + export
    • Retention controls

    PII guardrails

    • Detect + protect sensitive data (input and output)
    • Strategies like redaction/masking/hashing/blocking
    • Customizable guardrails by org policy

    This is the stuff that turns “cool demo” into “approved system.”

    Built for everyone who has to say “yes”

    AI doesn’t scale when it only works for one constituency.

    Chiri Brain is built to get alignment across:

    • Executives: Usage analytics by team, project, model (ROI visibility)
    • Knowledge workers: Answers grounded in your docs (fast, cited, repeatable)
    • Management: Consistent behavior via shared, versioned Task Personas
    • Security: Full traces + self-host option (no black box)
    • GRC: Immutable logs + PII guardrails (auditability end-to-end)

    This is how AI stops being “owned by a few power users” and becomes an organizational capability.

    The bottom line

    The enterprise AI market is full of tools that optimize for speed now and leave you with risk later.

    Chiri Brain is built for the teams that want:

    • Choice without lock-in
    • Adoption without fragmentation
    • Agents without chaos
    • Speed with governance

    Or, put more simply:

    Stop choosing between innovation and governance. Get both.

    Reach out to us today to learn more.

  • Low Hanging Fruit: Start With Coding Agents. Lessons From Snowflake’s AI Pivot

    There are not many chances to see a big, successful company try to rewire itself around AI in public.

    One recent example is Snowflake. On a recent episode of the No Priors podcast, “Meet Snowflake Intelligence: A Personalized Enterprise Intelligence Agent,” Sarah Guo interviews Snowflake CEO Sridhar Ramaswamy about his first 18 months in the role and the company’s push to become “AI-first.”

    They cover a lot of ground: org design, partnerships, and the launch of Snowflake Intelligence, their “opinionated agentic platform” for getting more value out of data already in Snowflake.

    This post is not a product review. It is about what an operator can steal from stories like this and actually put to work.

    Our headline takeaway for any enterprise trying to get real value from AI, not just pilots:

    Make coding agents your first AI win.

    Snowflake’s story is one useful case study in why that works.


    What We Actually Learn From Snowflake, Not Just About It

    From the episode and coverage of Snowflake’s pivot, a few patterns are worth paying attention to.

    1. They anchored AI on existing data gravity.
    Instead of trying to compete with foundation model labs, Snowflake focused on turning the data already sitting in its platform into decisions and actions faster, through Snowflake Intelligence and adjacent AI features.

    2. They treated AI as an organizational change, not a feature.
    The early moves Sridhar describes are about accountability, faster iteration, and clearer lines of ownership, not model architectures. AI success gets framed as “shorter feedback loops between builders and customers,” not “cool demo.”

    3. They picked a lane for their agentic platform.
    Snowflake Intelligence is described as an “opinionated agentic platform” that democratizes access to enterprise data. It is not positioned as the one AI to rule every workflow in the company, it is aimed squarely at making Snowflake-resident data more accessible and useful to every employee.

    For most companies, the punchline is not “go build your own Snowflake Intelligence.” It is:

    • Start where you already have leverage,
    • Be clear about the first job AI is doing for you,
    • Treat adoption like a product, not a side project.

    Which brings us to coding agents.


    Why Coding Agents Should Be Your First AI Win

    When boards and CEOs ask “where do we start with AI, in a way that actually pays off,” the answers cluster in a few places: developer productivity, customer support, and data access. You hear the same themes in this No Priors episode once they get to AI ROI: narrow, high-leverage use cases, not moonshots.

    Our view at Chiri: start with coding agents. Here is why.

    1. You already have the users

    Even if you are not “a software company,” you have:

    • Engineers and SREs,
    • Data engineers and analytics engineers,
    • Architects, admins, and ops folks writing scripts and glue code.

    Coding agents plug into work they already do, in tools they already use. No new persona, no exotic workflow.

    2. The ROI is visible and unemotional

    You can measure, quickly:

    • Time to ship a feature or change request,
    • Time to build an internal tool or migration,
    • Defect rates, rework, incidents traced back to code issues.

    It is much harder to tell whether an “AI brainstorming” tool is worth it than whether your teams are shipping more, better code with the same people.

    3. They demystify the stack

    Good coding agents:

    • Raise the floor for juniors and “non-traditional” engineers,
    • Make it safer for solution engineers and sales engineers to build demos and prototypes,
    • Make migrations, refactors, and cleanup work less painful, which in turn unlocks future roadmap.

    In other words, they increase the number of people who can safely move your systems forward.

    4. They lay the groundwork for everything else

    Once you have coding agents in place, it becomes easier to:

    • Build and maintain support agents and internal tools faster,
    • Wire AI into CI/CD, QA, and security checks,
    • Keep your new data and AI projects from turning into a pile of half-finished scripts.

    Coding agents are not “sexier” than generative marketing or chatbots. They are just more foundational.


    A Practical Rollout Plan (Borrowed, Then Adjusted)

    If you treat Snowflake’s pivot as an existence proof that AI adoption is mostly about speed, feedback loops, and opinionated scope, a simple rollout for coding agents looks like this:

    Step 1: Start with the builders

    • Roll out coding agents to a limited set of engineering teams.
    • Instrument usage and basic metrics, for example pull requests per engineer, cycle time, bug regressions.
    • Encourage working out loud: short Looms and internal posts on what works and what does not.

    The goal is not “100 percent adoption in week one,” it is real stories and baselines.

    Step 2: Elevate internal champions

    In the Snowflake story, change is pushed not just by the CEO, but by internal leaders and early adopters who can speak credibly to their peers.

    Do the same:

    • Identify 3–5 engineers who get outsized value from the agent.
    • Give them a platform internally to show concrete before/after examples.
    • Let the social proof work in your favor instead of forcing top-down compliance.

    Step 3: Extend to technical go-to-market teams

    Once engineering has a handle on the agent:

    • Bring in solution engineers, sales engineers, and technical account managers.
    • Focus them on high-leverage work: custom demos, proof-of-concepts, migration plans for prospects.
    • Track how long those activities take before and after.

    This is where AI-driven developer productivity turns into visible revenue impact.

    Step 4: Put guardrails and reviews in the path, not on the side

    High-leverage coding agents do not mean bypassing controls. They mean baking the controls into the workflow:

    • Require human review for changes above a risk threshold.
    • Keep code review norms, you are accelerating them, not deleting them.
    • Use linters, tests, and security scanners as an always-on second pass.

    You want to make it more likely that good code ships fast, not easier for risky code to sneak through.


    How Coding Agents Fit With Support And Data Agents

    If coding agents are the first wedge, what comes next? The same clusters that show up in the No Priors conversation:

    • Support and knowledge agents: AI that drafts responses, surfaces relevant docs, and handles well-bounded Tier 1 questions, with clear escalation to humans.
    • Data access agents: Interfaces that let non-technical users query and explore data safely, similar in spirit to what Snowflake Intelligence is aiming for inside their ecosystem.

    The ordering matters. Coding agents strengthen your ability to build and maintain the other two. Trying to stand up complex support and data agents without solid developer tooling is like launching a new product line while your factory is still on paper.


    The Chiri Take: Use AI To Multiply Output, Not Hype

    What we like about stories like Snowflake’s is not the branding or the feature set. It is the underlying posture:

    • Treat AI as a way to change how work gets done,
    • Anchor it in existing data and workflows,
    • Make adoption and iteration the main event.

    At Chiri, that is our lane.

    We help teams:

    • Find the workflows, like coding, where agents and copilots actually collapse cycle time.
    • Engineer guardrails so speed improves your risk posture instead of quietly eroding it.
    • Make adoption stick so you do not just get a “10x engineer,” you get more output from everyone around them.

    Starting with coding agents is not the flashiest AI story you can tell, but it is often the one that pays for everything else.

    If you want a partner to map your first wave of agents and get them into the hands of real users, we are happy to help. Reach out to us.