The Journal
The Journal.
Field notes on agents and structured data — what breaks when models author SQL, why plausible numbers are not answers, and what it takes to print one you can defend.
IIThe entries
The 15%-off dashboard: wrong joins corrupt analytics silently
A generated join that fans out rows doesn't crash. It inflates a metric by 15% and lets everyone keep steering by it. Silent wrongness is the real cost of text-to-SQL.
Replay What Your Agent Answered: AI Audit Trails That Hold
Only 17% of organizations can reconstruct what their agents did. From 2 August 2026 the EU AI Act expects the record to exist. Replay is how it holds.
The confidently wrong revenue number: why LLMs can't add
A model hands you a revenue figure with perfect posture and no arithmetic behind it. The research says the failure is structural — and so is the fix.
Prompt injection is the new SQL injection — the fix isn't SQL
P2SQL, CVE-2024-5565, EchoLeak, the Supabase leak: hostile SQL now arrives in the model's output. The fix is an agent with no syntax to inject into.
Read-only that wasn't: the week AI agents deleted production
An agent deleted a production database. Another destroyed user files. A third shipped a wipe order to a million installs. One July week — one shared write path.
Written to be
checked.
every number here carries its source — the contract or the citation
IVThe threads
Three questions, pursued in order.
Governance
Who decides what an agent may read — and where does that decision live? In code, fixed before the first call. Never in a prompt.
AI data governance →Accuracy
Why a plausible number is not an answer, and how the same model goes from 0/16 to 16/16 when the engine does the computing.
The AI data analyst →Provenance
Every result ships with the hash that replays it — months later, in either language, byte for byte.
Deterministic AI →VThe subscription
Have the next entry pressed to your inbox.
One email per entry. No digests, no drip campaigns.
Read the docs →