The AI Bubble Isn’t Bursting. Its Reflections Are.

This post was originally published in The AI Journal on August 19, 2026. Why the next chapter of AI security will be defined by tokenomics, sovereign models, and normalizing models as first–class software components. Every few weeks, someone asks me if the AI bubble is about to pop. That’s the wrong question to ask. There’s no single “bubble” that will pop and send us back to the pre-GPT ‘stone age’. Rather, there is an ecosystem of ‘AI bubbles’, each inflating on a different timeline, some combining and becoming more ‘stable’, others getting frothy and ready to pop, and each with very different consequences for the security leaders who have to live with the outcomes. ...

August 22, 2026 · Andrew Bolster

The Code Doesn't Care Who Wrote It: Why Context, Not AI Fear, Will Define Modern Application Security

This post was originally published on DevOps.com on April 28, 2026. AI has already arrived in the software development lifecycle; not as a pilot program or controlled experiment, but as an everyday reality. Developers are using AI coding assistants to generate functions, refactor modules, review pull requests, and accelerate delivery, often in direct tension with corporate policies meant to limit or control that use. While it’s tempting to consider this some kind of ‘Shadow AI’ or ‘Governance Failure’, it is a signal of things to come in this brave new world of AI-accelerated software engineering. ...

April 28, 2026 · Andrew Bolster