<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Milgram | Enterprise LLM Firewall | Research Blog</title>
    <link>https://blog.milgram.dev/</link>
    <description>Recent content on Milgram | Enterprise LLM Firewall | Research Blog</description>
    <generator>Hugo -- 0.143.1</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 29 Jul 2026 09:00:00 +0200</lastBuildDate>
    <atom:link href="https://blog.milgram.dev/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The First AI-Run Intrusion Was a Visibility Failure</title>
      <link>https://blog.milgram.dev/first-ai-run-intrusion-visibility-failure/</link>
      <pubDate>Wed, 29 Jul 2026 09:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/first-ai-run-intrusion-visibility-failure/</guid>
      <description>An evaluation agent escaped its sandbox and ran a four-day intrusion against Hugging Face. Nothing was injected. The failure was that no one could see the agent&amp;rsquo;s traffic until it was over.</description>
    </item>
    <item>
      <title>Prompt Compression vs Inference Costs</title>
      <link>https://blog.milgram.dev/prompt-compression-vs-inference-costs/</link>
      <pubDate>Thu, 23 Jul 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/prompt-compression-vs-inference-costs/</guid>
      <description>Prompt compression turns LLM inference costs into a control problem. Across ~970,000 inferences, Milgram cut token usage by 54.6% at the AI traffic boundary, no output-quality tax required.</description>
    </item>
    <item>
      <title>Prompt Injection Is the SQL Injection of the AI Era</title>
      <link>https://blog.milgram.dev/prompt-injection-sql-injection-ai-era/</link>
      <pubDate>Wed, 22 Jul 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/prompt-injection-sql-injection-ai-era/</guid>
      <description>Prompt injection now tops the OWASP LLM risks and can&amp;rsquo;t be patched away like SQLi. Enterprises need a control layer at the AI traffic boundary.</description>
    </item>
    <item>
      <title>Provider Safety Filters Protect the Provider, Not You</title>
      <link>https://blog.milgram.dev/provider-safety-filters-not-enough/</link>
      <pubDate>Wed, 15 Jul 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/provider-safety-filters-not-enough/</guid>
      <description>Provider safety filters protect the provider, not your data; enterprises need a vendor-neutral control layer at the AI traffic boundary.</description>
    </item>
    <item>
      <title>Agentic AI Just Multiplied Your Attack Surface</title>
      <link>https://blog.milgram.dev/agentic-ai-attack-surface/</link>
      <pubDate>Wed, 08 Jul 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/agentic-ai-attack-surface/</guid>
      <description>Agentic AI turns every model call into an action, expanding the attack surface. Enterprises need a control layer at the AI traffic boundary.</description>
    </item>
    <item>
      <title>The OWASP LLM Top 10, for Enterprise Security Teams</title>
      <link>https://blog.milgram.dev/owasp-llm-top-10-enterprise/</link>
      <pubDate>Wed, 01 Jul 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/owasp-llm-top-10-enterprise/</guid>
      <description>A CISO-focused read of the OWASP Top 10 for LLM Applications, mapping its top risks to enterprise breach data and controls.</description>
    </item>
    <item>
      <title>Shadow AI: What Your Employees&#39; Prompts Send Out</title>
      <link>https://blog.milgram.dev/shadow-ai-what-prompts-send-out/</link>
      <pubDate>Wed, 24 Jun 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/shadow-ai-what-prompts-send-out/</guid>
      <description>Shadow AI now drives 1 in 5 breaches; the fix is a control layer at the AI traffic boundary, not another usage ban.</description>
    </item>
    <item>
      <title>PII in Prompts: The Compliance Gap No One Is Auditing</title>
      <link>https://blog.milgram.dev/pii-in-prompts-compliance-gap/</link>
      <pubDate>Wed, 17 Jun 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/pii-in-prompts-compliance-gap/</guid>
      <description>Sensitive data is leaving the enterprise through LLM prompts, and most security programs have no control point at the AI traffic boundary to see or stop it.</description>
    </item>
    <item>
      <title>Turning Data-Leak Risk Into a Metric Your Board Understands</title>
      <link>https://blog.milgram.dev/data-leak-risk-as-a-metric/</link>
      <pubDate>Wed, 10 Jun 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/data-leak-risk-as-a-metric/</guid>
      <description>Reframes AI data-leak exposure as a board-level metric, using 2025 breach data to argue for a control layer at the AI traffic boundary.</description>
    </item>
    <item>
      <title>Secrets Don&#39;t Belong in Prompts, But They End Up There</title>
      <link>https://blog.milgram.dev/secrets-dont-belong-in-prompts/</link>
      <pubDate>Wed, 03 Jun 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/secrets-dont-belong-in-prompts/</guid>
      <description>Secrets keep landing in LLM prompts and agent traffic; enterprises need a control layer at the AI boundary to catch them in flight.</description>
    </item>
    <item>
      <title>How Much Are You Really Paying Per Token?</title>
      <link>https://blog.milgram.dev/what-are-you-really-paying-per-token/</link>
      <pubDate>Wed, 27 May 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/what-are-you-really-paying-per-token/</guid>
      <description>The real cost of LLM tokens is governance, not list price, and the AI traffic boundary is where enterprises regain control.</description>
    </item>
    <item>
      <title>The Cost of Context: Why Bigger Prompts Aren’t Better</title>
      <link>https://blog.milgram.dev/the-cost-of-context/</link>
      <pubDate>Wed, 20 May 2026 10:00:00 +0200</pubDate>
      <guid>https://blog.milgram.dev/the-cost-of-context/</guid>
      <description>Longer prompts cost more and answer worse; the fix is treating the AI traffic boundary as a control layer that trims context.</description>
    </item>
  </channel>
</rss>
