Friday, 26 December 2025

AI in Medicine: Connecting the Dots Across Medical Data

One of the areas where AI can genuinely help is medical science.

The modern medical industry generates massive volumes of data in many different forms: text, PDFs, structured data, scans, X-rays, videos, EEGs, ECGs, and more. Traditionally, each of these data sources contributed only a part of the overall picture, often leading to separate conclusions and individual courses of action.

Today, AI in medicine can bring all these diverse data types together into a single, integrated view. Instead of treating each input in isolation, AI can analyze them collectively and suggest a course of treatment that balances all available information for the best possible outcome. This is something that may not be achievable even for a panel of experienced doctors.

Not because doctors are incompetent or inexperienced, but because of the sheer volume of data involved and the difficulty of analyzing it all at once to identify subtle patterns that may point to an emerging crisis.

Listen to this podcast, based on verified sources. These is strictly informational and not meant to be any medical advice/ guidance/treatment. 

Listen to AI in Cardiac

Sources: 

https://www.foreseemed.com/artificial-intelligence-in-healthcare

https://www.scirp.org/journal/paperinformation?paperid=148222

https://pmc.ncbi.nlm.nih.gov/articles/PMC11374272/

https://iris.who.int/server/api/core/bitstreams/f780d926-4ae3-42ce-a6d6-e898a5562621/content

https://amwa-doc.org/wp-content/uploads/2025/10/Power-of-AI-in-Improving-Early-Diagnosis-and-Care-for-Alzheimers-Disease-and-Dementia.pdf

https://arxiv.org/pdf/2307.00067

Why Is Secrets Sprawl a Growing Security Risk and How Can AI Help?

We’ve all done this, and more. We create accounts everywhere: OTT platforms, banks, NBFCs, gaming apps, e-commerce, quick commerce, telecom, and social media. Then we forget about them. Worse, we reuse the same passwords across platforms. In security terms, this expands the attack surface and creates easy openings for hackers.

The same problem exists inside enterprises. It’s often called “secret sprawl.” Credentials, passwords, API keys, tokens—they spread quietly across codebases, documents, and tools. 

The problem begins small. A developer hard-codes a key into source code to meet a deadline. The code is pushed to a repository, copied into logs, shared over email, pasted into tickets or fed into AI coding tools for debugging. Each step creates a new, unmanaged copy. Over time, the secret travels—across teams, tools and platforms—without oversight.

This is what makes secrets crawl dangerous. The attack surface expands quietly. Even when a key is rotated, older versions often remain active elsewhere. According to industry estimates, exposed secrets are now among the leading causes of cloud breaches, API abuse and supply-chain attacks.

The rise of generative AI has accelerated the risk. Employees routinely paste production code—and sometimes live credentials—into chatbots, pushing secrets beyond enterprise security perimeters. Its now big enough an issue that CISO/ Cyber security and IT policies take note ( see infographic) .

source: Gitguardian; Gitlab, Media Reports, NIST

AI plays a dual role in managing secrets sprawl. It is both a powerful tool for detection and, paradoxically, a contributor to the problem itself. On the defensive side, AI can help in in real time monitoring at scale, potentially expanding the ability of teams to detect and action;  real time risk based assessments, triggering alerts/ defensive action much faster than ever; Ai could also be crafted for automated key rotation at scale, thereby reducing one attack vector. 

AI can also be the problem! It could suggest insecure patterns or detection. And it may generate keys- compounding the very problem it was created to solve! 

Clearly AI is not a one-stop solution. It still needs a lot of human intelligence and final control. 

Thursday, 25 December 2025

What Are Non-Human Identities (NHIs) and Why They Matter in Cyber Security (and AI)

What are Non-Human Identities and why are these an urgent focus these days in cybersecurity?  

Non-Human Identities (NHIs) are digital identities used by machines, not people.They allow applications, bots, scripts and systems to access data, APIs and infrastructure.

Put simply: humans log in with usernames and passwords; machines log in with keys and tokens.


source: microsoft, Amazon, Reco.ai, media reports. Infographic created by my own prompt.

NHIs are everywhere in modern tech stacks:

  • API keys used by apps to talk to each other

  • Service accounts running background jobs

  • Automation scripts and bots

  • Cloud workloads such as VMs, containers and serverless functions

  • DevOps tools like CI/CD pipelines

  • IoT devices and sensors

In most enterprises today, non-human identities vastly outnumber human users! 

Unlike humans, NHIs don’t use passwords or MFA. They rely on:

  • API tokens

  • OAuth tokens

  • Certificates

  • SSH keys

  • Cloud IAM roles

These credentials are often long-lived, shared and rarely rotated. 

NHI can be a risk for four reasons: increased attack surfaces because of high use of cloud / IOT. Failure of authentication which is designed for humans, and not faceless bots; bots gain access where they shouldn't without human review, and by virtue of their omnipresence, a prime target for hackers, as these are non-traditional surfaces not easily monitored. 

This is the simple summary of HI vs NHI: 

source: microsoft, Amazon, Reco.ai,  IBM, media reports. Infographic created by my own prompt.

AI agents have a deep impact- even transformational- on NHI and security. We will explore this in next posts. 

India AI Governance: Balancing Innovation, Safety and Trust in the Age of Artificial Intelligence

The Indian government published the India AI Governance Guidelines on November 25 2025. 

Source: India AI Governance Guidelines : Enabling Safe and Trusted AI Innovation (PDF) on PIB website. Infographic generated by own prompt. 

Source: India AI Governance Guidelines : Enabling Safe and Trusted AI Innovation (PDF) on PIB website; infographic generated by own prompt. 

My take : India’s AI governance approach is pragmatic, pro-innovation and risk-aware. The focus is not on banning or tightly controlling AI, but on using existing laws, voluntary frameworks and digital public infrastructure to guide safe adoption. 

The government recognises real risks—deepfakes, bias, data misuse and national security—but believes these can be managed through graded accountability, techno-legal tools and strong institutions, not blanket regulation.


Source: India AI Governance Guidelines : Enabling Safe and Trusted AI Innovation (PDF) on PIB website. Infographic generated by own prompt. 

The big message is clear: build trust, expand access, skill people, and regulate only where harm is proven. AI is seen as a growth engine for healthcare, education, agriculture and governance—especially for Bharat, not just India’s metros.

Shadow AI Explained: The Hidden Risk Inside Your Organisation

Shadow AI refers to the use of artificial intelligence tools by employees without formal approval, oversight, or governance from their organisation.

In practice, it means staff using public or unsanctioned AI systems to generate reports, presentations, analyses, code, or insights using internal company data. This use is often well-intentioned, not malicious. Employees are usually trying to save time, meet deadlines, or improve productivity. The risk comes from how the tools are used, not why.

To get useful output, AI systems need input. That input often includes:

  • Internal reports

  • Pricing or inventory spreadsheets

  • Strategy decks

  • Customer or partner information

  • Operational or financial data

Once this information is entered into an external AI system, control over that data is effectively lost. Even when providers claim privacy or non-retention, the organisation has no practical way to verify how data is stored, reused, logged, or incorporated into future models.

Shadow AI can show up anywhere:

  • A rushed manager generating a board deck

  • An analyst uploading a spreadsheet for faster insights

  • A salesperson polishing a proposal with sensitive client data

  • A junior employee using AI because it feels natural and efficient

  • A hospital employee uploading reports or researching using patient data. 

Each instance may seem harmless, even noble in the pursuit of efficiency and commitment. But at scale, it becomes a serious data exposure risk.

Shadow AI is expanding faster than traditional IT controls can keep up with. AI tools are:

  • Easy to access

  • Cheap or free

  • Familiar to younger, AI-native employees

  • Useful even to non-technical staff

As new generations enter the workforce, AI usage becomes instinctive. Policy, firewalls, and monitoring often lag behind real-world behaviour.

The answer is not banning AI. That rarely works.

Instead:

  • Define a clear AI policy: what tools are allowed, which are not, and why.

  • Specify data boundaries: what can never be uploaded, even to approved tools.

  • Be explicit about monitoring: what is logged, tracked, and audited.

  • Apply rules consistently: including to senior management.

  • Educate employees: most Shadow AI happens through ignorance, not intent.



source: reco.ai, media reports, my own prompt to generate infographic 

AI is a powerful efficiency tool. But when data control becomes fragmented, the risk of leaks, competitive loss, regulatory exposure, and carelessness rises sharply.

Risk Type
What It Means
Real-World Example
Data Security & IP Leaks
Employees accidentally upload sensitive, confidential, or proprietary information (like source code, financial data, or future product plans) to public AI tools.
Samsung engineers leaking proprietary source code into ChatGPT.
Legal & Compliance Violations
Using unapproved AI can violate data privacy laws (like HIPAA for patient data) or lead to professionals relying on inaccurate, AI-generated information.
Lawyers getting sanctioned for using fake legal cases created by an AI in a court filing.
Expanded Attack Surface
Unvetted AI tools, especially browser extensions, can contain malware or have security flaws, creating new ways for cybercriminals to attack a company's network.
A Chrome extension named "Quick access to Chat GPT" was found to be malware that hacked users' Facebook accounts.

source : Media reports, reco.ai,  Forbes (https://www.forbes.com/sites/siladityaray/2023/05/02/samsung-bans-chatgpt-and-other-chatbots-for-employees-after-sensitive-code-leak/) 

Regardless of privacy statements or assurances, nothing shared with external AI systems should be assumed private. Data always leaves your control in some form.

With AI, the rule is simple: user beware.

How AI Is Used in Cybersecurity

Cybersecurity has moved beyond firewalls and antivirus software. It is now about behaviour, patterns and speed. This is where artificial intelligence has become critical (see infographic).  At Jetmetaphy Labs, our product WardenAI is at the forefront of leveraging AI for forensics, detection, prevention and diagnosis. 



Across Indian banks, insurers, telecom companies and digital platforms, AI continuously studies what “normal” activity looks like—user logins, network traffic and data access. When behaviour shifts, risk is flagged early. Most cyberattacks do not announce themselves. They creep in. AI catches the early signals.

Threat detection is no longer signature-led. AI watches how files behave. If a program starts encrypting data, altering systems or contacting unknown servers, it is blocked—even if the attack is new. This has become essential as ransomware incidents rise across hospitals, manufacturing units and government systems.

Email fraud remains a major weakness. AI scans language patterns, sender behaviour and links to stop phishing, fake invoices and CEO fraud—common attack routes for Indian enterprises.

AI also protects digital identities. It learns how users normally log in—device, location and timing. Unusual access triggers additional checks or blocks accounts, reducing fraud in banking, UPI and insurance platforms.

When attacks do occur, AI speeds up response. Systems are isolated, access is shut down and alerts are triggered in seconds. What once took hours now happens automatically.

The shift is structural. Cybersecurity has moved from rule-based defence to behaviour-led intelligence. Attackers use automation. Defenders now have little choice.

Put simply: AI gives cybersecurity teams speed, scale and foresight—now essential, not optional.

Wednesday, 24 December 2025

How Underwriting Works—and How AI Is Improving It

While researching the insurance industry, I took a closer look at underwriting and the balance of art and science behind it. I found that underwriting blends data analysis, professional judgment, corporate strategy, personality, and risk management. One insight that stood out was the idea that weak underwriting amplifies risk, while strong underwriting multiplies profits.

Underwriting is the process through which companies decide whether to take on risk, how much to charge for it, and under what conditions

In insurance, this means evaluating details like age, health, driving history, location and past claims before issuing a policy. 

The same logic exists in other industries too. 

Banks underwrite loans by checking income and credit history before deciding interest rates and limits. Investment banks underwrite IPOs and bond issues by pricing risk before selling securities to investors. 

BNPL (buy now pay later) firms do instant underwriting at checkout, approving or rejecting customers in seconds. 

Leasing and asset finance companies underwrite based on asset value and usage risk, while reinsurance involves large-scale underwriting across geographies and climate exposure. 

Even in startups, the investor underwrites tech, people costs, and other costs in the hope of disproportionate returns, or at worst, capped losses. 

In every case, the principle is identical: price risk correctly or pay for it later.

Traditionally, underwriting has been manual, slow and rule-based. Decisions depended heavily on individual judgement, limited data and fixed risk slabs. 

AI changes this completely (see infographic) . 


source: myself; infographic created using my own prompt 

AI-led underwriting systems analyse large volumes of data in real time, identify patterns humans often miss, and score risk in seconds. 

Low-risk cases are approved automatically, while complex cases are escalated to human underwriters. 

Pricing becomes more precise, fraud is flagged early at the proposal stage, and risk assessment shifts from a one-time activity to a continuous process based on behaviour, usage and external factors. 

The key to always remember : AI does not replace underwriters; it supports them with clearer insights, consistency and speed. The "gut feel", the indefinable experience, the institutional memory of events. circumstances, analysis and outcomes should never be under estimated or belittled. Nothing can replace the HUMINT- Human Intelligence. 

Rogue AI in the real world: Hollywood Saw This Coming. We Just Didn't Believe It.

If there was ever a moment for an "I told you so," this is it. For more than four decades, Hollywood has repeatedly warned us abo...