[{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/tags/ai/","section":"Tags","summary":"","title":"AI"},{"content":"I use AI at work. Here\u0026rsquo;s what I keep catching myself doing: I treat the output like an answer to the question.\nIt isn\u0026rsquo;t. It\u0026rsquo;s a response - and it arrives looking exactly the same; right or wrong, regardless.\nThat\u0026rsquo;s the part worth sitting with. When a coworker is unsure, I can usually tell. AI gives me no signs. The response always hits with the same fluency. The same confidence. Is this right, wrong, true, false, hallucination? The output can\u0026rsquo;t tell me how much I should trust it.\nAnd the model can\u0026rsquo;t tell me that either. There\u0026rsquo;s no withheld confidence, no hubris, no ego. The model doesn\u0026rsquo;t have introspective access to the process any more than I do.\nSame hole, one layer down.\nI tell AI \u0026ldquo;never guess\u0026rdquo; or \u0026ldquo;always be decisive\u0026rdquo; and I might get what I\u0026rsquo;m expecting. The model never guesses - or rather, the model always guesses. AI is decisive every time. There is no careful-mode switch that some dumbass left in the default off position.\nAnd here\u0026rsquo;s the trap: those instructions aren\u0026rsquo;t ignored. They change the wording. I say \u0026ldquo;don\u0026rsquo;t guess\u0026rdquo; and I get more hedging, more qualifiers, more \u0026ldquo;it depends.\u0026rdquo; The output starts sounding more careful without any more reliability. The pig looks prettier, I\u0026rsquo;ve put blush and eye-liner on and \u0026hellip; the response is a response.\nI dress the same answer in caution, so it reads as I expect. Which is worse than being ignored, because now I\u0026rsquo;ve fooled myself. I added the safeguard rule, the response changed like I expected, and \u0026hellip;\nThat\u0026rsquo;s how source code gets deleted. How bad advice gets taken. How a confident recommendation quietly torches a deal.\nThe safeguard has to be me #Before I act on AI output, I run it through reality. I\u0026rsquo;m the one who gets the bill when it\u0026rsquo;s wrong.\nHere\u0026rsquo;s what I keep having to admit: I want to believe it. The answer arrives clean, complete, and it\u0026rsquo;s the answer I was hoping for. Some part of me treats the thing as all-knowing, all-seeing. That part isn\u0026rsquo;t checking anything. That\u0026rsquo;s the real exposure: I\u0026rsquo;m invested in the response being right. Not that the machine is unreliable.\nMy judgment is a good filter where I have expertise, and I reach for AI hardest on what I don\u0026rsquo;t know. So \u0026ldquo;check the answer\u0026rdquo; is circular: if I could evaluate it, I wouldn\u0026rsquo;t have asked. The response is nuanced. I can\u0026rsquo;t tell whats broken.\nI can check myself. I know when an answer is convenient. I know when I stopped reading closely because it was going my way. That doesn\u0026rsquo;t require knowing the subject. It requires being honest about wanting.\nWhere I can\u0026rsquo;t evaluate, I must ask for the artifact instead of the assurance. \u0026ldquo;Are you sure?\u0026rdquo; reliably produces \u0026ldquo;yes.\u0026rdquo; The source, with a link, either exists and says what was claimed, or it doesn\u0026rsquo;t.\nAI generates. I incorporate the pieces that match. I make the call. I\u0026rsquo;m the \u0026ldquo;never guess\u0026rdquo; and \u0026ldquo;be decisive\u0026rdquo; filter, because the filter has to live outside the machine.\nNone of this is a knock on the tools. Used that way they\u0026rsquo;re genuinely good - fast, tireless, and better than I am at plenty of specific things. But the accountability doesn\u0026rsquo;t transfer. I\u0026rsquo;m the one who has to answer for the decision, which makes me the one who has to check it.\n","date":"July 28, 2026","permalink":"https://scottbrinkmeyer.me/posts/ai-never-guesses/","section":"Posts","summary":"","title":"AI Never Guesses"},{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/posts/","section":"Posts","summary":"","title":"Posts"},{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/tags/","section":"Tags","summary":"","title":"Tags"},{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/tags/personal/","section":"Tags","summary":"","title":"Personal"},{"content":"I had carpal tunnel release surgery recently. It\u0026rsquo;s healing faster than I expected, which is a genuinely nice thing to be able to report.\nThe feeling is coming back in my fingers. Not all at once - it shows up in spurts, and mostly you notice it by noticing something you wouldn\u0026rsquo;t have noticed before.\nDo you know what it\u0026rsquo;s like to touch the tips of your fingers together for the first time?\nTyping. Shaping wood into guitars. Playing those guitars. Things I do with these hands, which have been missing the feeling.\nAnd now I have to wait to get back to the shaping, because I\u0026rsquo;d damage the ligament in ways I don\u0026rsquo;t want to know.\nThat\u0026rsquo;s the good news, and it\u0026rsquo;s real. Here\u0026rsquo;s the other thing.\nI\u0026rsquo;m tired. Not sleepy - weary. The kind where the tiredness sits in the decision-making rather than the eyelids.\nAnd I can\u0026rsquo;t tell you where it\u0026rsquo;s coming from.\nIt could be the healing. A body repairing itself runs a deficit, and nobody hands you an itemized bill for it. It could be that recovery just makes everything louder - you\u0026rsquo;re already operating at reduced capacity, so the ordinary noise costs more than it used to.\nOr it could be July of 2026, and the general condition of things.\nI\u0026rsquo;m not going to litigate the politics here. I don\u0026rsquo;t think my read on it would improve anybody\u0026rsquo;s day, mine included. But I\u0026rsquo;d be lying if I described the last stretch as restful, and I don\u0026rsquo;t think I\u0026rsquo;m unusual in that. Asked directly, something like three-quarters of people say they\u0026rsquo;re exhausted by how much is happening - and most of them say they intend to keep paying attention anyway. That combination is the whole problem. It isn\u0026rsquo;t apathy. It\u0026rsquo;s the cost of refusing to be apathetic.\nSo which one is it?\nI spend my working life on systems where the first job is isolating the variable. Change one thing, watch what moves, learn something. It\u0026rsquo;s a good method, and it does not work here. I can\u0026rsquo;t run a version of the last month where my wrist is fine and everything else is identical. There\u0026rsquo;s one instance, no staging environment, and every input arrives at once.\nWhere I\u0026rsquo;ve landed is that it\u0026rsquo;s probably both, and that the ratio matters less than I want it to. The healing is going well. The weariness is real. Neither cancels the other, and waiting to find out which is which is mostly just a way of not resting.\nSo: the hands are better. That part I\u0026rsquo;m sure about.\n","date":"July 28, 2026","permalink":"https://scottbrinkmeyer.me/posts/two-kinds-of-tired/","section":"Posts","summary":"","title":"Two Kinds of Tired"},{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/tags/ci/cd/","section":"Tags","summary":"","title":"CI/CD"},{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/tags/devsecops/","section":"Tags","summary":"","title":"DevSecOps"},{"content":"","date":null,"permalink":"https://scottbrinkmeyer.me/tags/supply-chain/","section":"Tags","summary":"","title":"Supply Chain"},{"content":"Two years ago I\u0026rsquo;d have told you the whole game was shifting security left. Get the scans into the pipeline, catch things before they ship, done.\nThat wasn\u0026rsquo;t wrong, exactly. But the industry spent a decade pushing security, testing, and deployment onto developers, and somewhere in there it stopped scaling. The pushback that surfaced in 2025 even has a name now - people are calling it shifting down instead of left - and the complaint underneath it is simple: developers didn\u0026rsquo;t sign up to be YAML engineers.\nThat\u0026rsquo;s the most interesting change, and it\u0026rsquo;s a correction rather than a reversal. Early is still right. What we got wrong was assuming early meant somebody else\u0026rsquo;s problem now.\nWhat actually changed #Security stopped being a best practice and became a filing deadline.\nThe EU Cyber Resilience Act takes effect in September 2026, with real vulnerability reporting obligations and SBOM requirements attached (overview). That drags this conversation out of engineering and onto a compliance calendar. If you sell software into Europe, \u0026ldquo;we\u0026rsquo;re planning to get to SBOMs\u0026rdquo; stops being an acceptable answer this year.\nThe SBOM question itself moved, too. Nobody serious asks whether you can generate one - the tooling does that. The question is whether you can act on it when something lands: can you tell me today which deployed environments contain the bad version, and how fast can you get them off it? Generating an artifact nobody reads is theater.\nAI became a dependency you can\u0026rsquo;t scan.\nThis is the genuinely new one. A model in your stack is a third-party dependency, but not one your existing scanners can read - no lockfile to parse, no CVE feed to diff against. Hence the ML-BOM and AI-BOM ideas making the rounds: an inventory of models, where the training data came from, and what the thing is allowed to touch.\nThe attack surface moved to match. Agents commit code. MCP servers execute tool calls on someone\u0026rsquo;s behalf. Malicious packages are being written to target the AI tooling rather than the humans using it.\nI don\u0026rsquo;t think anybody has this solved, mine included. What I\u0026rsquo;d say is that the shape is familiar even when the contents aren\u0026rsquo;t: an under-reviewed thing, holding credentials, doing work inside your pipeline. We\u0026rsquo;ve met that problem before.\nWhat didn\u0026rsquo;t change #The durable parts are boring. That\u0026rsquo;s why they\u0026rsquo;re durable.\nAutomate it, or it didn\u0026rsquo;t really happen. A control that depends on somebody remembering is a control you don\u0026rsquo;t have. That was true before this tooling cycle and it\u0026rsquo;ll be true after it.\nBuild the secure path early, not as a retrofit. Security bolted on at the end just becomes the thing everyone routes around. The correction above doesn\u0026rsquo;t undo this - it means the secure path has to be the easy path. Otherwise you\u0026rsquo;ve built a speed bump and called it a guardrail.\nRepeatable beats documented. A pipeline that does the thing beats a runbook describing the thing. I deliver into customer environments that are all a little different, and the only approach that survives that is making delivery itself repeatable instead of accumulating tribal knowledge about each one.\nWhere I\u0026rsquo;d put the effort #If a team is behind and can only fix one thing: make your inventory real. Not the SBOM artifact - the actual ability to answer where is this version running right now.\nMost of the pain during a supply chain incident isn\u0026rsquo;t the patch. It\u0026rsquo;s not knowing where to apply it. Everything else gets easier once you can answer that question in minutes instead of days.\n","date":"July 28, 2026","permalink":"https://scottbrinkmeyer.me/posts/devsecops/","section":"Posts","summary":"","title":"The State of DevSecOps in 2026"},{"content":"Like to hear from you #Are you curious about something?\nPlease feel free to contact me.\n","date":null,"permalink":"https://scottbrinkmeyer.me/contact/","section":"Home","summary":"","title":"Contact"},{"content":"I spend my working life on systems nobody can see. Outside of it I make things I can actually pick up and hold, which turns out to be the counterweight I needed.\nBuilding electric guitars #Mostly Stratocasters and Telecasters.\nWhat I like about it is that a guitar doesn\u0026rsquo;t care how confident you are. The neck either sits right in your hand or it doesn\u0026rsquo;t. Shaping, fitting, dialing one in until it feels correct is slow work with no shortcuts and no way to fake the result - which is a pretty refreshing change of pace from software.\nThe farm #This is where most of my non-guitar attention goes right now:\nOrchard work Forestation projects Dairy goats Hens Goats and fruit trees operate on their own schedule and are completely indifferent to sprint boundaries. The feedback loop is measured in seasons instead of minutes, and you can\u0026rsquo;t automate your way out of the parts you\u0026rsquo;d rather skip.\nDrones #Still love them, even though they\u0026rsquo;ve been quiet for a while. It\u0026rsquo;s a hobby I keep close and come back to in seasons rather than one I\u0026rsquo;ve given up on.\nWhy any of this #Building physical things keeps me grounded and connected to tangible progress. I\u0026rsquo;ve spent a career on infrastructure that\u0026rsquo;s invisible when it works - there\u0026rsquo;s real value in ending the day with something you can hand to somebody.\n","date":null,"permalink":"https://scottbrinkmeyer.me/hobbies/","section":"Home","summary":"","title":"Hobbies"},{"content":"Cloud engineer and architect. DevSecOps first. CI/CD all the things.\nI help deploy TerraFlow Energy\u0026rsquo;s EMS to customer environments, with a focus on secure delivery, reliable automation, and systems that hold up in the real world.\nOutside of work, I build electric guitars (mostly Strats and Teles) and spend time on the farm with orchard and forestation projects, dairy goats, and hens.\nBuilding physical things helps me stay grounded.\nStart here:\nWork - what I do professionally Hobbies - what I build outside work Contact - how to reach me ","date":null,"permalink":"https://scottbrinkmeyer.me/","section":"Home","summary":"","title":"Home"},{"content":"I\u0026rsquo;m a cloud engineer and architect. DevSecOps first, CI/CD all the things.\nHow I default to working:\nAutomate it, or it didn\u0026rsquo;t really happen Build the secure path early, not as a retrofit Fail fast, fail forward, keep improving the system Now - TerraFlow Energy #I help deliver TerraFlow Energy\u0026rsquo;s EMS (Electricity Management System) into customer environments. Every customer environment is a little different, so the interesting problem is rarely the software - it\u0026rsquo;s making delivery repeatable when the target keeps moving.\nWhat that covers:\nArchitecture and deployment strategy for customer-ready EMS environments CI/CD pipeline design and automation Security-first engineering across build, release, and operations Reliability, observability, and operational hardening Before this #Cloud SRE and architecture work across three industries that look nothing alike.\nOracle - Cloud SRE and architect. Shell - Oil and gas. Nike - Global footwear and apparel. The through-line is the same in all of them: production systems people actually depend on, where being careless has a real cost. Energy, oil and gas, and retail have completely different regulatory shapes and failure modes, and all three punish teams that treat delivery as an afterthought.\nHow I work #DevSecOps first. Security belongs in the delivery workflow from the start. Bolted on at the end, it just becomes the thing everyone routes around.\nAutomation over handoffs. Repeatable pipelines and infrastructure automation beat tribal knowledge and manual runbooks every time.\nLearn-forward. When something breaks, the useful questions are about fast feedback and clear ownership - not who to blame, and not which old habit to revert to.\nWhat I build # Cloud platform patterns for scalable delivery CI/CD pipelines that support frequent, safe releases Secure-by-default workflows and guardrails Deployment playbooks that hold up in production ","date":null,"permalink":"https://scottbrinkmeyer.me/work/","section":"Home","summary":"","title":"Work"}]