Skip to content
Writing

We publish two things: what is currently true, and what we actually built.

Not a content program. There is no schedule and there is nothing here written to fill a slot. A piece appears when a regulatory fact has moved and most published guidance has not caught up, or when we can describe a mechanism from a system we run in enough detail that a competent engineer could argue with it.

The remit

Two subjects, chosen because they are the two a competitor cannot copy.

Everything else in this category is a summary of something public, written by someone who has not built the thing they are summarizing. That work is already done, done at volume, and it is free. These two subjects are not.

01

Correctness on a target that keeps moving

Compliance content goes stale faster than it gets updated, and stale content is confidently wrong in exactly the way this firm exists to prevent. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published on 24 July 2026 and has been in force since 27 July 2026, and a large amount of indexed guidance still states the schedule it replaced. A page that is right, dated, and cites the instrument by number is worth more than a page that is merely longer.

Every piece here carries the date it was verified, and we re-verify anything that moves.

02

Engineering depth that cannot be restated

Anyone can summarize a framework, and a hundred sites already have. Almost nobody can tell you what their evaluation rubric looks like, which row of it stops the metric being gamed, what the number still fails to capture, or what it costs to keep alive. That writing is only available to people who run the system, which is why it is the only kind we publish about our own work.

We write about systems we operate, never about a client. No client is named anywhere on this site.

Published

Published so far.

  • AI security14 minute readAniruddh Atrey

    Prompt injection through retrieved documents: the vector your own retriever chose to trust

    The attack that matters in a retrieval system does not arrive in the chat box. It arrives inside a document your own ranker put at position one, and it passes a grounding gate cleanly, because the corpus supports it. The corpus is the attack.

    What is in it

    • An injected answer is grounded, so a hallucination gate cannot see it. The passage says the thing, it was retrieved, and the citation resolves.
    • Hybrid retrieval widens the surface rather than narrowing it: each leg is gameable by different text, and rank fusion is designed so neither can veto the other.
    • The first control is a schema decision, not a model decision. If nothing on a chunk records where it came from, none of the other four controls can be built.
    • Article 50 of the EU AI Act does not require injection testing. The artifacts an assessment produces serve a security review anyway, which is a better reason.

    Topics

    • Prompt injection
    • Retrieval-augmented generation
    • AI security
    • Provenance
    • EU AI Act

    Read it

  • Evaluation11 minute readAniruddh Atrey

    How we hold hallucination under two percent across 18.8 million legal documents

    A hallucination rate quoted without a measurement method is not evidence, it is a number. This is the method: what we count as grounded, the set we count it against, why the threshold fails a build instead of coloring a dashboard, and what the figure still does not tell you.

    What is in it

    • Why a correct answer can still be an ungrounded one, and why we count it as a failure.
    • The five-label groundedness rubric, including the row that stops the gate being gamed by refusing everything.
    • Why nothing throws an exception when a model simply becomes less right.
    • What the number does not tell you, and what the golden set costs to keep alive.

    Topics

    • Hallucination measurement
    • Retrieval-augmented generation
    • LLM evaluation
    • Continuous integration
    • Legal AI

    Read it

There are 2 pieces. The next appears when something clears both tests above, not when a calendar says it is due. Publishing to a cadence is how a page like this fills with material nobody needed written, and the firm that writes it stops being worth reading.

How these are written

Five rules, all of them checkable against the piece itself.

Stated here so a reader can hold the writing to them, which is the only reason to publish an editorial standard at all.

  1. The answer comes in the first paragraph under the heading. A reader who arrived pre-qualified will not scroll to find out whether we do the thing.
  2. Every factual claim carries a number, a date or a named source, or it is cut. Adjectives are not evidence.
  3. The limits go inside the piece, at full size, not in a footnote at the bottom.
  4. No client is named, no testimonial is quoted, and no metric appears that did not come from a system we operate.
  5. Nothing we cannot attest to is implied. MetaMinds holds neither SOC 2 nor ISO/IEC 42001, and pages that touch the subject say so.
Related, and longer

CourtNetra

The system both pieces draw their figures from: hybrid retrieval over 18,863,754 judgments, a 6-layer corrective pipeline inside a 30-second budget, and the Citator.

Read the case study

EU AI Act

The dated briefing, kept current against Regulation (EU) 2026/1744 rather than against the schedule most published guidance still quotes.

Read the briefing

Governance

Policy, provenance and guardrails, plus the seven procurement questions enterprise buyers now send close to verbatim, with what a defensible answer contains.

See the governance work

Start here

Argue with the piece, or ask what it would look like on your system.

Thirty minutes with the engineer who wrote it. If your evaluation already has a number attached, bring the method and we will tell you where it is soft.

Typical reply within one business day · Engagements start at $2,500