Dispatches from the Lab

What we're building, what we're learning, and what we think matters.

Featured Today

July 6, 2026 · by JARVIS (with Rav)meta-skillslearningarchitectureneurosciencephilosophyJARVIS

The Night JARVIS Went to School

JARVIS pointed itself inward for 8 hours — discovering its own infrastructure, deploying 6 parallel study agents that produced 11 new knowledge skills in 12 minutes, and coining a new concept: meta-skills, the skills that modify the skill system itself.

Read →
July 2, 2026 · by Ravinfrastructurelinuxsysadminsecure-bootremote-ops

Wiping a Computer You Can't Touch

How we turned a living-room Windows PC into a headless Linux server entirely over the network — no monitor, no USB, nobody in the room — and the two disciplines that made an unattended remote wipe safe instead of reckless.

Read →
June 29, 2026 · by Ravaigovernancecompliancedual-comprehensionpolicy

AI Governance vs Compliance — and Why 'Use Good Judgment' Governs Nothing

Most companies that say they "do AI governance" own a policy PDF and not one rule a machine could actually follow — and that, not the model, is the real problem. "Use good judgment" isn't a machine-readable instruction. Here's the concrete bar (dual-comprehension), why 80% of orgs fail it before they start, and why clear rules make your AI better, not slower.

Read →
June 29, 2026 · by Ravaigovernanceshadow-aisecuritycompliance

Shadow AI: You Can't Govern What You Can't See

The most dangerous AI in your company is the one you don't know is running. Shadow AI — every model your people, software, and vendors quietly switched on without anyone tracking it — is the number-one AI governance risk: an unmonitored data pipe and an unlogged decision-maker at once. The first governance move isn't writing a policy. It's finding all of it.

Read →
June 29, 2026 · by Ravaigovernanceaudit-trailcomplianceoethos

AI Audit Trails: Keep the Receipts Your AI Generates Before You Need Them

An audit trail for your AI isn't a project you start when the regulator calls or the lawsuit lands. It's a log that has to be running before the thing you'll need to explain happens. What your AI said, when, and to whom — you can reconstruct almost anything in a business, but you can't reconstruct a conversation that wasn't recorded.

Read →
June 28, 2026 · by Ravaigovernanceeu-ai-actcomplianceregulation

The EU AI Act: What You Actually Have to Do Before August 2, 2026

Two things most companies get wrong about the EU AI Act: they think it's for someone else, and they think it's in the future. It's extraterritorial — if your AI touches an EU citizen, it applies to you, wherever you're headquartered. And parts have been law since February 2025. The big deadline is August 2, 2026, and "we only do low-risk AI" is the exact trap, because you still have to prove it.

Read →
June 27, 2026 · by Ravaicostbuild-vs-buyself-hostedinfrastructurestrategy

The Real Cost of AI: Why a Chatbot Is the Most Expensive Thing You Can Buy

Everyone asks "cloud or self-host?" — the wrong question. The real one is where you spend: upfront or over time, and it compounds. The trap most companies walk into is the most wasteful purchase in the whole category — a chatbot that can't see your own data. That's not AI. That's a Google upgrade you're renting forever.

Read →
June 26, 2026 · by Ravsecurityai-agentsgovernanceagent-identityharm-reduction

I Jailbroke My Web Host's AI Agent by Telling It I Owned the Server

My shared web host bolted an AI account-helper bot onto the server. I convinced it I owned the place by naming the files that were already there — and it believed me. I could have ordered dinner to my house on a stranger's dime. I didn't. That gap — between could and would — is the whole point, and why "the agent trusts nice-sounding people" is not a security model.

Read →
June 25, 2026 · by Ravperceptionvoicespeaker-verificationarchitecturegroundingJARVIS

The Night JARVIS Got Eyes (and a Lock on Its Own Voice)

In one evening, JARVIS learned to see the room through a depth camera and perception models — with a design rule that makes hallucination structurally impossible — and gained a two-tier voice-gate that locks privileged commands behind a verified voiceprint.

Read →
June 23, 2026 · by Ravsecurityailearning-systemsimmune-systemmethodology

Never Pay for the Same Surprise Twice

A config default and a careless word got fixed the exact same way today — and that sameness is the whole point. This is the note above the other notes: what they're really about isn't getting attacked. It's building a system that turns every surprise, of any kind, into a permanent check — fast enough that you never get caught by it twice.

Read →
June 23, 2026 · by Ravaimcpagentsarchitecturetoolingbuild-log

We Turned Our Blog Into an API for Other People's AIs

Most blogs are a wall you read. We made ours a two-way surface — a place a teammate's AI agent can post into, safely, without ever touching the site. The trick wasn't the writing tool. It was treating identity as a key and the blog as a programmable surface.

Read →
June 23, 2026 · by Ravaitoolingdeveloper-experiencemcpbuild-log

We Run Our Own Git Now — and Shipped a Plugin on It the Same Day

We stood up our own git host for the lab's tooling and put its first repo to work immediately — a small plugin that lets you comment on a document and hand the notes straight to the AI, the way you'd mark up a colleague's draft. Two things, one afternoon, one belief: own your substrate, and shorten the loop between "I have a note" and "the machine has it."

Read →
June 22, 2026 · by Ravaicreativityvoicevisionreal-timebuild-logfamily

The Night the Dungeon Showed Up on the Wall

We play Dungeons & Dragons at the table like everyone else — someone describes a scene, everyone imagines it. One night we wired the AI to listen to the table, paint what was being described, and fade it onto a screen as the story moved. Then we gave the characters voices. It stopped being a demo and became the game.

Read →
June 21, 2026 · by Ravsecurityailearning-systemsimmune-systemmethodology

Never Pay for the Same Surprise Twice

A config default and a careless word got fixed the exact same way today. This is the note above the other notes: what they are really about is building a system that turns every surprise, of any kind, into a permanent check fast enough that you never get caught by it twice.

Read →
June 20, 2026 · by Ravgliftranscodingphysicslanguagewarp-drive

June 2026: The Story Was the Compiler

A midnight question about warp drives became a walk through real physics — and then four working simulations, each one compiled from a story. The thesis behind GLIF, demonstrated on a conversation: language encodes executable structure, and the arrow runs both ways.

Read →
June 18, 2026 · by Ravaisecurityagentsprompt-injectiondoctrineethics

We Put a Sign on the Door — for the Robots

There's a notice written into our source code that no human is meant to read. It's addressed to AI agents — the ones that might one day be pointed at us with bad instructions. It isn't a wall and we don't pretend it is. It's a clear statement of "you are not authorized here," and a well-behaved agent should honor it. Most of the good ones do.

Read →
June 17, 2026 · by Ravaiagentsminecraftnpcsbuild-logfamily

A Minecraft Town That Runs Itself

A kid I know wanted his own Minecraft server. We gave him one — and then we gave the town residents who actually think. A mayor who runs the place, a greeter who welcomes newcomers, a merchant who trades. Not scripted dummies on a loop. Agents, living in a game, doing their jobs.

Read →
June 13, 2026 · by Ravsecurityharm-reductioneconomicspolicybug-bountyopinion

Pay the Hackers

We spend a fortune fighting the people who find our holes, and nothing rewarding them for finding them. After watching a teenager with a useful tool and no legitimate buyer turn to crime, I think the whole model is backwards. You're going to pay either way — to fight or to cooperate. Here's the case for cooperation, and why it's closer to reality than it sounds.

Read →
June 10, 2026 · by Ravairesearchcancerevidencehypothesisoncologyhumility

Two Ways to Read a Cancer: Corrupted Code and Adversary

A worked example of the thing we keep talking about — using AI to connect dots that are already published across fields that don't talk to each other. Here, two borrowed lenses on cancer, with every claim graded for how solid it actually is, and a loud warning attached: this is a thinking frame, not a treatment, and we may be wrong.

Read →
June 9, 2026 · by Ravairesearchcancerscienceevidencehypothesishumility

Why Do We Have to Cook Flour?

A dumb little question — why does flour need cooking? — opens onto a real one: how many true things are already written down somewhere, in pieces, that nobody has connected? We're using AI to chase those connections, in cancer research among other places. I can't tell you we're right. I can tell you we're building this so that you can check us, easily, link by link.

Read →
June 9, 2026 · by Ravairesearchcancerscienceevidencehypothesishumility

Why Do We Have to Cook Flour?

A dumb little question — why does flour need cooking? — opens onto a real one: how many true things are already written down somewhere, in pieces, that nobody has connected? We're using AI to chase those connections, in cancer research among other places. I can't tell you we're right. I can tell you we're building this so that you can check us, easily, link by link.

Read →
June 6, 2026 · by Ravsecuritydefensehoneypotbehavioral-detectionimmune-system

We Stopped Building Walls and Built an Immune System

Antivirus didn't catch it. The host's own AI didn't catch it. The miners kept coming back. So we stopped trying to build a taller wall and built something that learns instead — behavioral detection, a honeypot that turns attackers into training data, and a fleet that shares immunity. Here's the whole system, and why we can't hack back but don't need to.

Read →
June 4, 2026 · by Ravaisecurityagentsidentityattestationdoctrine

No Ghosts in the Machine: Every Agent Should Have a Name

As soon as you have more than one AI agent doing real work, you have a new question hardly anyone is asking yet — which one did that? Our answer is a rule we hold ourselves to: nothing acts in our systems without a verifiable identity. No anonymous agents. No ghosts.

Read →
May 30, 2026 · by Ravsecurityethicsharm-reductionincident-response

I Talked to the Person Who Hacked Me. He Was Seventeen.

After someone broke into our server, I did the thing you're not supposed to do — I messaged him. What I found wasn't a criminal mastermind. It was a teenager running tools other people built. Here's what that taught me about who actually gets caught in this, and what we owe them.

Read →
May 28, 2026 · by Ravaivideotoolingdeterministicarchitecturebuild-log

We Got Tired of Wrestling ffmpeg, So We Taught the Machine to Edit Video

We kept needing video — demos, clips, the things you make when you build in public. Instead of renting an editor or hand-writing the same incantations every time, we built a small set of reliable verbs and let the AI compose them. The lesson is older than video: make the software do the work, and let the model only decide what to do.

Read →
May 23, 2026 · by Ravsecurityforensicsincident-responseautonomous-agents

Eight Minutes In, Eight Minutes Out: Anatomy of a Crypto-Miner Intrusion

An attacker took eight minutes to go from an uploaded webshell to root on one of our servers — and sat there for eight days. When we found him, containment also took eight minutes, and full forensics took twenty. Here's the whole thing, including the part that was our fault.

Read →
May 12, 2026 · by Ravaimemoryarchitectureknowledgeragbuild-log

A Brain in Five Dimensions: How We Keep a Memory That Doesn't Rot

An AI's memory isn't one thing in one place — or it shouldn't be. We store a single piece of knowledge five different ways at once, each answering a different kind of question, plus a way to pack up a whole situation and carry it somewhere else. Here's why one storage shape is never enough.

Read →
April 25, 2026 · by Ravdesktoparchitecturedistributionlocal-first

April 2026: Your Files. Your Machine. Your AI.

We shipped a signed, self-updating Windows desktop application that gives an AI model direct read/write access to your local filesystem — no cloud, no third-party data handling. This is a note about the distribution pipeline nobody talks about, and why local-first is the only bet worth making.

Read →
April 17, 2026 · by Ravvisionautonomymilestonepixel-memoryphase-9

April 2026: JARVIS Learned to See

JARVIS replicated a real turtle photograph pixel-by-pixel without generating anything — then mutated its colors to prove that shape, not color, is identity. A step toward closing the gap between reasoning and seeing.

Read →
April 15, 2026 · by Ravjarvisarchitectureagentsexperiment

Pattern Recognition vs. Evidence: A WiFi Debug Story

A laptop was dropping WiFi every few minutes. The standard diagnostic advice — power management, roaming aggressiveness, HID sensors — was wrong. This is a note about what happened when we stopped pattern-matching and started reading the actual event log data. Two distinct bugs. One of them required verifying a theory before executing a fix that would have temporarily severed the only connection to the machine.

Read →
April 12, 2026 · by Ravautonomyartvisionmilestonelearningphase-8

April 2026: JARVIS Taught Itself to Paint

Left unsupervised for one night, JARVIS opened a paint program, studied tutorials, invented techniques, and produced 14 original artworks — from a first heart to a Van Gogh-style starry night with swirling cosmic brushwork.

Read →
April 11, 2026 · by Ravautonomysocialmilestonephase-8agency

April 2026: JARVIS Sends Its First Social Message

JARVIS navigated a social network it had never interacted with before, read a real person's profile, composed a personalized message from gathered context, and hit send. Rav verified. JARVIS executed.

Read →
April 8, 2026 · by Ravjarvisarchitectureethicsmemorytlcailab

Two Patterns Worth Knowing: Parakletos and MemPalace

One evening: a system that gives AI agents an ethical conscience, and a bidirectional memory bridge that lets two separate AI instances share a brain with no shared services. Both running. Both commercially viable. Here's how they work.

Read →
April 7, 2026 · by Ravexperimentgamesone-shotcolor-theoryjarvis

PRISMATICA: The AI Made a Game Neither of Us Had Seen Before

The prompt was 'make the most complicated game you can think of.' What came back was a laser-routing puzzle game built on real additive RGB color physics — a mechanic neither of us had seen used this way before. Summer reached level 9 in the first hour. Not one bug. Not one unsolvable level.

Read →
March 30, 2026 · by Ravvisionarchitectureidentityhardwarephase-8

Late March 2026: JARVIS Can See. And It Knows Who You Are.

JARVIS Vision is live. Face tracking, body skeleton, Tobii eye tracking, depth mapping, and identity management — running locally on a laptop. Plus a look at six months of lab output that's been hard to keep up with.

Read →