About
A notebook on securing AI systems, kept in public.
I'm Santiago Bocanegra. Most people call me San.
This site is where I write about securing AI systems. It's a notebook more than a portfolio: what I'm reading, what I'm building, and what I'm still working out.
Why this site exists
Organizations are adopting AI faster than they're governing it. The questions that come with that — who can access a model, what data goes into it, how you know what it did and why — are not entirely new questions. They're the fundamentals of security, applied to systems that behave differently from the ones we're used to: identity, least privilege, visibility, accountability.
I find that easier to think through by writing it down. If it's useful to someone else along the way, better still.
What I write about
- AI security and governance. Frameworks like the NIST AI Risk Management Framework, what they ask for, and what implementing them actually looks like.
- Zero Trust and identity. Access control at enterprise scale, and how it changes when the thing requesting access is an AI agent rather than a person.
- Cross-border operations. Data that moves between Mexico and the United States sits under two regulatory regimes at once. Nearshoring has made that a live problem for a lot of companies, and AI adoption is making it sharper.
- Build logs. Small projects I work through in the open, with write-ups covering what worked, what didn't, and why. The code lives on GitHub.
Everything here is general practice: public frameworks, open-source tools, and my own projects. Nothing draws on any employer's systems, customers, or internal work.
Background
I've spent about twenty years in enterprise security at Fortune 500 companies, moving from hands-on engineering into leading a global team, and more recently into architecture. The last few years have centered on AI: infrastructure for AI workloads and guardrails for large language models. I'm currently a Principal Cybersecurity Enterprise Architect. The full history is on LinkedIn.
I studied Computer Systems Engineering at Universidad Cuauhtémoc in Guadalajara and hold the CISSP certification. More recently I've completed graduate-level programs in AI and machine learning, including one offered in collaboration with UT Austin.
I grew up and trained in Mexico and have spent my career in the United States, which is why so much of my work lands on the seam between the two.
I write in English and Spanish, and I'm based in Dallas, Texas.
Get in touch
If something here is wrong, incomplete, or worth arguing about, I'd like to hear it. You can reach me on LinkedIn or by email.