Working at a laptop after dark, city lights and the bay through the window
Home Forward Deployed Security Fabric FAQ Resources Blog About Start a Scoping Call
Basho's Pond

The Island Mountain Blog

Field notes from the work: agentic security and governance, data sovereignty, and what the cloud's meter really costs you.

August 17, 2026 F3 walkthrough #LegalAI

The Docketing Clerk Is Part of the Architecture

It’s 4:47 on a Friday afternoon. Run the tape forward with me; the scenario is invented, the mechanics aren’t.

Read →
August 14, 2026 F4 doctrine clauses #AIDiscovery

Discovery Can Kill the Project

Discovery at Island Mountain runs under six clauses, and we hold every engagement to them. A sales process that can’t fail can’t be trusted, so these exist to make failure possible.

Read →
August 13, 2026 F5 objection ladder #AIAdoption

Onboarding Is Part of the System

“Training is the tour at the end, right?”

Read →
August 12, 2026 F1 field checklist #DataCenterOperations

The Facility Survey Can Sink a Good Deployment

Measure the building before you sign for the machine.

Read →
August 11, 2026 F2 letter to a role #AIGovernance

The Compliance Officer Knows Where the Risk Lives

To the compliance officer who just heard there’s an AI pilot starting:

Read →
August 10, 2026 Strategy Financial

The Smaller System Is Often the Honest Answer

"Buy the biggest box your budget allows. You'll grow into it." I'd like to argue with that in public. Headroom you can't justify bills for power, cooling, and attention from day one, and a maximum-capacity default often hides discovery nobody did. Size from the work, and the honest answer is frequently a smaller machine than the buyer expected.

Read →
August 9, 2026 Technical Financial

Self-Hosted Inference and the Idle-GPU Problem: What Superlinked's SIE Changes

You switched to small models to cut the inference bill and nothing moved, because the cost was never in the calls. It's in the servers, one reserved GPU per model, billed whether traffic arrives or not. Superlinked's open-source SIE serves 85-plus models from one process that loads and evicts by traffic, so a single card runs a rotating working set instead of sitting idle behind one model.

Read →
August 2, 2026 Strategy Industry

When the Expert Retires, the Library Burns: Capturing Institutional Knowledge Without Building Surveillance

Every retirement is a library that burns. The tacit expertise that never made the SOP is the part that hurts to lose, and it walks out the door on a schedule you can already see. AI changes the arithmetic by capturing the work in working form while the expert still runs it, owned by the institution and built to preserve expertise, not to police the people who hold it.

Read →
July 30, 2026 Strategy Industry

AI Is Electricity in 1895, and Everybody's Shopping for the Biggest Motor in the County

Factories met electricity by bolting one giant motor onto the old line shafts, and output didn't much notice; the gains waited four decades for unit drive and redesigned floors. A chatbot subscription over an unchanged workflow is the same play, on a capability curve that compounds in months. Treating AI as a chatbot you subscribe to is meeting electricity and concluding the product is lamps.

Read →
July 28, 2026 Strategy

The Island Mountain Doctrine, Distilled

Most startups begin with a business plan. Island Mountain began with a point of view, and this month I wrote it down: why doctrine exists, the implementation gap it answers, the seven-phase method, the credo's chain of command, and the refusals on the record. The founding document at a fraction of its length.

Read →
July 26, 2026 Technical Strategy

ZimReaper Ran With a Human's Session. So Does Your AI Agent.

TA488's payload never needed privileges of its own. It inherited an authenticated Zimbra session, made only legitimate API calls, and minted itself an app-specific password that survives a password reset. A process with human session authority that provisions its own durable credential is the default shape of an AI agent.

Read →
July 25, 2026 Technical Strategy

Bonsai 27B Runs on a Phone. The Sovereignty Math Just Moved Again.

PrismML rounded a 27B multimodal model down to 1.125 bits per weight: 3.9 GB, phone-resident, 90 percent of its benchmark average intact, Apache 2.0. The floor under private multimodal AI just dropped again, and the category table says the deepest cuts land exactly where agentic work lives.

Read →
July 19, 2026 Strategy

Agentic Scar Tissue: How Long-Running Agents Drift

Long-running agents accumulate workarounds, retry policies, fallback paths, and defensive heuristics until operational history starts rewriting behavior. The case for an immutable Hour Zero, adaptation receipts, and behavioral fingerprints.

Read →
July 16, 2026 Strategy Industry

Education Is the Deployment

The companies pulling away in the AI race aren't necessarily choosing better models; their orgs are learning faster. Forward Deployed Engineering is less a software discipline than an educational one, and a good deployment leaves behind a team approaching its work in a fundamentally different way. Forward Deployed Field Notes No. 001, infographic included.

Read →
July 11, 2026 Technical Strategy

Agentic Infrastructure Is Shedding Its Scaffolding. The Controls Have to Land Somewhere.

Anthropic's platform team went on camera and read you the next year of agents: their own service accounts, agent-to-agent MCP traffic, scaffolding deleted, ambient execution, work you order with a budget attached. Every item on that list quietly moves a security control out of the model and into infrastructure. The only question left is whose building it sits in.

Read →
July 11, 2026 Strategy Industry

Sovereign AI Is Having Its Moment. Now Fund the American Open-Source Lab It Needs.

Palantir and NVIDIA went sovereign on open models, and the industry's loudest voices are suddenly preaching open source. Good. Now comes the money-where-your-mouth-is part: an independent, American, frontier-cadence open-weight lab with no meter attached.

Read →
July 10, 2026 Technical Financial

DGX Spark vs RTX PRO 6000: When a $4,700 Box Is Enough, and When It Isn't

Two DGX Sparks hold 256GB for the price of one RTX PRO 6000 Blackwell, and still generate tokens 6 to 7 times slower per stream. Where Spark and AMD's Strix Halo genuinely win, where they fall over, and the honest sizing call, including for hardware you already own.

Read →
July 10, 2026 Financial Strategy

Self-Hosted AI Inference and the $165,000 Rewrite

Anthropic rewrote Bun from Zig to Rust: 64 parallel Claude agents, 11 days, roughly $165,000 in tokens at API pricing. They never paid it; they own the infrastructure. What the labs' own economics admit about token billing, and what owning inference looks like at your scale.

Read →
July 7, 2026 Technical Strategy

LLM Harnesses, Saddles, and the Paddocks that corral them

The word harness comes from draft animals we couldn't trust with the route. As the models earn it, the scaffolding gives way to a saddle, and the controls that hold, identity, egress, metering, audit, a kill switch, move off the animal and into the paddock. The only question left is whose paddock.

Read →
July 2, 2026 Technical

Agentic Orchestration and Security: The Complete Map of How AI Agents Work, and How They Get Attacked

An animated five-layer map of how AI agents plan, delegate, and act, and how they get attacked. Orchestration patterns, tool trust boundaries, agentjacking, the lethal trifecta, and the deterministic controls that break each attack.

Read →
June 30, 2026 Security Industry

Agentjacking Hit a $250B Company Through a Fake Bug Report. Air-Gapped Buys You Half the Fix.

A single fake Sentry error report hijacked the AI coding agent inside a $250 billion Fortune 100 company and more than 100 other organizations. No breach, no stolen credentials. Air-gapped hardware closes the cloud exfiltration category. It does not close an agent that can't tell trusted data from an instruction.

Read →
June 21, 2026 Technical

AI Search Visibility in 2026: What Three Years of Production AI Taught Me That Most Consultants Haven't Learned Yet

AI search summaries are rewriting who gets found. Three years of production on-premises AI experience, turned on the visibility question itself: why AI answer engines cite what they cite, and what most consultants still get wrong.

Read →
June 14, 2026 Technical

The Sovereign Edge: On-Device LLMs and the Coming Micro-Scale Inference Revolution

Put your phone in airplane mode and the LLM keeps running. Apple, Google, memristors, and quantized MoE models are collapsing the distance between inference and the device in your pocket. The same sovereignty argument Island Mountain makes at rack scale, now at pocket scale.

Read →
June 5, 2026 Compliance Industry

Europe Just Defined AI Sovereignty. The U.S. Is Still Pretending It Does Not Apply to Us.

On June 3, 2026, the EU published the Cloud and AI Development Act, defining four sovereignty tiers for AI infrastructure. The highest tier blocks any provider subject to the U.S. CLOUD Act. Here is what that framework reveals about every regulated industry in America.

Read →
May 29, 2026 Industry Compliance

Landlord or Owner: Tribal Nations, Data Centers, and the Sovereignty Question Nobody's Asking

Over 100 hyperscale data center projects proposed on tribal lands. The Seminole Nation voted 24-0 for a moratorium. The Muscogee Nation rejected a facility on food sovereignty land. The question every tribe needs to answer: landlord or owner?

Read →
May 29, 2026 Financial Strategy

$50K a Month on Cloud AI Is a Hardware Problem, Not a Budget Problem

A 100-person company burning $50,000 a month on Claude tokens can replace that spend with on-premise hardware it owns. Break-even in under two months. Five-year savings exceeding $3.5 million. Here is the math.

Read →
May 14, 2026 Industry

The Grid Is Screaming As Our Aquifers Are Sucked Dry; The Answer Is On-Premises LLM Servers

NERC Level 3 alerts, data centers draining aquifers, and 399 billion gallons of water consumed annually. Local AI inference is the responsible path forward for organizations that refuse to subsidize the cloud.

Read →
May 10, 2026 Technical

Local LLM vs Cloud AI: Every Con on the List Has a Hardware Fix

A developer ran Qwen3.6-35B on a MacBook Pro and documented every limitation honestly. Speed, context depth, quality variance. Dedicated on-premise inference hardware solves each one today, whatever silicon the job calls for.

Read →
May 10, 2026 Industry

The Second Revolution of AI Is Local. The Industry Just Admitted It.

The CEO of Hugging Face ran a 27B model on a laptop in airplane mode and called it the second revolution of AI. For regulated industries paying per-token fees to process sensitive data on someone else's servers, this revolution has been a long time coming.

Read →
May 9, 2026 Industry Compliance White Paper

AI Sovereignty Framework for Tribal Nations: Why On-Premise AI Servers Are a Perfect Match for Tribal Governments

A legal, operational, and strategic framework establishing why on-premise AI infrastructure is the only architecture that satisfies OCAP, HIPAA, the CLOUD Act, and tribal self-determination authority.

Read →
May 5, 2026 Strategy

The MSP Model Sold You Accountability. What You Got Was a Ticket Queue.

Why the Managed Services Provider model mirrors cloud AI subscriptions: recurring fees for tiered access, culpability transfer instead of real service, and data you don't control.

Read →
April 30, 2026 Technical

DeepSeek V4-Flash Just Changed the Game for Local AI

How V4-Flash's mixture-of-experts architecture puts 284 billion parameters on 192GB of VRAM, and what that means for organizations running inference on their own hardware.

Read →
April 23, 2026 Compliance

Attorney-Client Privilege and Cloud AI: The Structural Problem Law Firms Can't Negotiate Away

Model Rule 1.6, third-party disclosure mechanics, and why your cloud AI provider's terms of service do not preserve privilege.

Read →
April 16, 2026 Technical

RTX PRO 6000 Blackwell vs. H100: What the Specs Mean for Your Workload

Memory bandwidth, VRAM capacity, and inference speed explained for the decision-maker who needs to size a deployment honestly.

Read →
April 9, 2026 Financial

Cloud AI vs. Local Hardware: Building the Honest Five-Year TCO

The variables your cloud AI vendor's pricing page omits: compliance overhead, price escalation, vendor lock-in exit costs, and the crossover math.

Read →
April 2, 2026 How-To

OpenWebUI for Administrators: Multi-User Access, Permissions, and Conversation Controls

The admin-side setup guide for the IT person who just received the hardware. User accounts, model access by role, audit logging, and network configuration.

Read →
March 26, 2026 Industry

Tribal Data Sovereignty and the Cloud AI Problem: Why Sovereign Jurisdictions Need Sovereign Infrastructure

OCAP principles, IHS data frameworks, emergency management operational security, and why sovereign jurisdictions need sovereign infrastructure.

Read →
March 12, 2026 Industry

OCAP Principles and the CLOUD Act: Why Tribal Data Requires Local AI Infrastructure

How the CLOUD Act undermines tribal data sovereignty and why OCAP-compliant AI requires on-premise hardware. Ownership, Control, Access, and Possession in the age of AI.

Read →
March 5, 2026 Compliance

ITAR and DFARS AI Self-Assessment: Can Your AI Infrastructure Pass an Audit?

Self-assessment guide for ITAR and DFARS compliance when using AI for defense-related work. CUI handling, CMMC alignment, and air-gapped local AI.

Read →
February 26, 2026 Compliance

OpenAI Discovery Risk: Why Law Firms Face Subpoena Exposure with Cloud AI

Cloud AI providers can be subpoenaed for prompt logs and conversation history. Analysis of discovery risk for law firms using ChatGPT, Claude, and other cloud AI services.

Read →
February 19, 2026 Compliance

HIPAA Technical Safeguards Checklist for Local AI Deployment

Complete HIPAA technical safeguard checklist mapping access controls, encryption, audit logging, and transmission security to on-premise AI hardware configuration.

Read →
February 12, 2026 Technical

On-Premise vs. Colocation vs. Cloud: A Decision Framework for Regulated Industries

Decision framework comparing on-premise, colocation, and cloud AI deployment for organizations with compliance requirements. Cost, control, latency, and regulatory analysis.

Read →

Have a Question This Blog Doesn't Answer?

Tell us whose desk the work runs through and what hurts about it. One conversation, no sales pitch, and a straight answer about whether we can help.

Or call directly: 1-341-441-8740