Milgram Research Blog
Notes from building an enterprise LLM firewall: AI traffic filtering, prompt-injection detection, prompt compression, and data-exfiltration measurement.

Model-as-a-Judge Has Its Own Prompt Injection Problem
Research shows attackers can manipulate AI judges. Smaller models, larger models, and typed decisions each carry security and performance tradeoffs.

The First AI-Run Intrusion Was a Visibility Failure
A frontier-model evaluation produced an autonomous intrusion. Milgram's replay shows …

Prompt Compression vs Inference Costs
Prompt compression turns LLM inference costs into a control problem. Across ~970,000 …

Prompt Injection Is the SQL Injection of the AI Era
Prompt injection now tops the OWASP LLM risks and can't be patched away like SQLi. …

Provider Safety Filters Protect the Provider, Not You
Provider safety filters protect the provider, not your data; enterprises need a …

Agentic AI Just Multiplied Your Attack Surface
Agentic AI turns every model call into an action, expanding the attack surface. …

The OWASP LLM Top 10, for Enterprise Security Teams
A CISO-focused read of the OWASP Top 10 for LLM Applications, mapping its top risks to …

Shadow AI: What Your Employees' Prompts Send Out
Shadow AI now drives 1 in 5 breaches; the fix is a control layer at the AI traffic …

PII in Prompts: The Compliance Gap No One Is Auditing
Sensitive data is leaving the enterprise through LLM prompts, and most security programs …

Turning Data-Leak Risk Into a Metric Your Board Understands
Reframes AI data-leak exposure as a board-level metric, using 2025 breach data to argue …

Secrets Don't Belong in Prompts, But They End Up There
Secrets keep landing in LLM prompts and agent traffic; enterprises need a control layer at …

How Much Are You Really Paying Per Token?
The real cost of LLM tokens is governance, not list price, and the AI traffic boundary is …

The Cost of Context: Why Bigger Prompts Aren’t Better
Longer prompts cost more and answer worse; the fix is treating the AI traffic boundary as …