TomorrowX

TomorrowX We are an Australian company specialising in data access and control technology.

Another day in San Francisco, and another very different set of conversations.Naresh and I started the morning with Maia...
04/09/2026

Another day in San Francisco, and another very different set of conversations.

Naresh and I started the morning with Maia from Austrade at Bluestone Lane on Folsom — where we also caught up with fellow Aussie Chris and his team.

Flat whites and Milo in San Francisco. Hard to complain. 🇦🇺☕️

Our conversations with Maia are becoming genuinely transformational as we explore how TomorrowX’s Data Mediation capability can be accessed at scale across the US enterprise and public sector — working through partners that already collaborate with Austrade.

That opens up some very exciting possibilities.

Then down to Stanford University — always a reminder of the extraordinary concentration of ideas, research and ambition in this part of the world.

We finished with a quick visit to ClawCamp, where we caught up with Nalini from Deloitte and met Christian from WeAreDevelopers.

We’re already working closely with Deloitte, and we’re now exploring how TomorrowX and WeAreDevelopers might collaborate too.

Coffee. Stanford. Developers. Partners.

Not a bad day in the Bay Area. 🇺🇸

A fascinating couple of days in Singapore with the Google Cloud CISO Community.One thing came through very clearly: the ...
03/09/2026

A fascinating couple of days in Singapore with the Google Cloud CISO Community.

One thing came through very clearly: the AI conversation has moved on.

It is no longer simply, “How do we use AI?”

It is increasingly about how enterprises control it, secure it, govern it and scale it with confidence.

What particularly resonated in our conversations was TomorrowX’s approach of putting the AI control plane on the inside of the customer’s security perimeter, rather than introducing another external service through which sensitive prompts, data and model interactions must pass.

For organisations in critical infrastructure and highly regulated industries (banking, telco, energy, government and beyond), that distinction matters.

That is why we are especially excited to be making AI Data Guard available to Google Cloud customers through Google Cloud Marketplace.

The event itself reflected the same themes throughout: AI governance, sovereign risk, securing the AI pipeline, agentic systems and trust.

It was great to reconnect with old friends including Phoram Mehta from PayPal, catch up with friends from Australia including Narelle Devine CSM from Telstra and Gajan Ananthapavan from Bendigo Bank and reconnect with security leaders from across the region.

It was also a real privilege to spend more time getting to know the broader Google Cloud CISO team, including Alicja Cade, Nick Godfrey, Michalis Tsavdaridis and Robert Mechler.

The trust within that community was what made the conversations so valuable.

A massive congratulations and thank you to Daryl Pereira for fostering that environment and creating the space for people to engage so openly.

And if you’re invited to one of these events: go.

Looking forward to Chicago later in the year.

Great to spend time with Chris Ketter, Australia’s Consul-General in San Francisco, at the Australian Consulate.As Tomor...
03/09/2026

Great to spend time with Chris Ketter, Australia’s Consul-General in San Francisco, at the Australian Consulate.

As TomorrowX continues to build its presence in the US, having people who understand the ambition, open doors and actively support Australian companies making the journey matters enormously.

Chris, thank you for your sponsorship, encouragement and belief in what we’re building.

Always good to have a little bit of Australia in San Francisco. 🇦🇺🇺🇸

Austrade North America | Australian Trade and Investment Commission Australian American Chamber of Commerce (AACC San Francisco) AmCham Australia

Knowing what is inside the software your organisation depends upon should be the minimum - not an exceptional request.Th...
02/09/2026

Knowing what is inside the software your organisation depends upon should be the minimum - not an exceptional request.

The Australian Signals Directorate (ASD) has published its 2026 Minimum Elements for a Software Bill of Materials, developed with the Cybersecurity and Infrastructure Security Agency (CISA) and international partners.

This is critical for every customer, particularly organisations operating in highly regulated and mission-critical environments. It represents the minimum that should be expected of software vendors, delivery partners and internal development teams.

At TomorrowX, this discipline is embedded in how we deliver Data Mediation through the Composable Agentic Platform (CAP).

Every CAP release includes a build-generated CycloneDX SBOM covering direct and transitive components, supported by vulnerability scanning, release-integrity controls and open-source compliance practices.

This month our open source licence compliance programme achieved conformance with ISO/IEC 5230, the international standard from the OpenChain Project and TomorrowX joined the OpenChain Community of Conformance alongside organisations such as Fujitsu and Google. Our secure development practices are aligned with the National Institute of Standards and Technology (NIST) Secure Software Development Framework.

OpenChain announcement: https://openchainproject.org/conformance/2026/08/25/tomorrowx-announces-an-openchain-iso-iec-5230-conformant-program

These controls are documented in our new Trust & Assurance resource, giving customers and partners greater visibility into how CAP is built, secured, licensed and distributed: https://tomorrowx.com/trust

This assurance is fundamental to supporting regulated and mission-critical environments and part of why TomorrowX is trusted by partners including Fujitsu, Deloitte Cyber, Amazon Web Services (AWS), Accenture and Carahsoft.

Thank you to the ASD, CISA and especially Allan Friedman, PhD for continuing to raise the standard for software supply-chain transparency.

Read the ASD publication:
https://www.cyber.gov.au/business-government/supplier-cyber-risk-management/managing-cyber-supply-chains/2026-minimum-elements-for-a-software-bill-of-materials

Marcus Thompson, AM, PhD · Rob Parker · Kendy Hau · Aaron Sempf · Justin Stark · Daryl Pereira · Lesley Carhart · Alexander Sullivan · Daven Pettersen · Ella Kell · Josh Kennedy-White · Arie van Bennekum · Alexander Schellong · Dr Dimitrios Salampasis

Token maxxing was never going to last. The shift to controlled AI consumption is inevitable. The question is how you do ...
01/09/2026

Token maxxing was never going to last. The shift to controlled AI consumption is inevitable. The question is how you do it.

Hard limits on users? Or intelligent routing, cost controls and data policies — running inside your own security perimeter, without sending every prompt outside your network?

That’s what TomorrowX enables.

DM if you'd like to see it.

Link: https://thenextweb.com/news/microsoft-tokenmaxxing-ai-spending-limits

Imagine a team — or a group of AI agents — needs to analyse production data, but broad access is unacceptable and creati...
14/08/2026

Imagine a team — or a group of AI agents — needs to analyse production data, but broad access is unacceptable and creating a duplicate data estate introduces cost, delay and more risk.

What if you could give them exactly the access they need, and nothing more, without changing the source system?

That is what fine-grained control in the path makes possible — across production data, IT and OT.

Another perspective on Data Mediation — this time on risk management: turning the impossible into the possible:
https://tomorrowx.com/research-data-mediation-risk-management

The security industry has become exceptionally good at finding risk.Threat intelligence identifies malicious activity. V...
13/08/2026

The security industry has become exceptionally good at finding risk.

Threat intelligence identifies malicious activity. Vulnerability platforms tell us what is exposed. AI can interpret a new disclosure in seconds. EDR, SIEM and cloud security platforms can tell us more about what is happening than ever before.

But there is still a difficult operational question:

What stops the dangerous interaction from reaching the vulnerable system now?

Because knowing about a vulnerability and fixing it are not the same thing.

A critical system may take days, weeks or months to patch safely. It may be too important to take offline. It may be legacy infrastructure that cannot easily be changed at all.

We call this The Zero-Day Inversion.

Instead of asking detection technology to become the control point, its intelligence becomes an input.

Data Mediation then applies an approved preventative control directly in the data path — blocking, constraining, sanitising, redirecting or transforming the dangerous interaction before it reaches the protected system.

The application remains unchanged.

The security team gains time to patch properly.

And the organisation moves from:

“We know we are vulnerable until we can fix it.”

to:

“The vulnerable interaction is controlled while we fix it.”

Detection remains essential.
Patching remains essential.
Modernisation remains essential.

The opportunity is to make the time between them defensible.

Our latest cyber perspective explores the architecture:

The Zero-Day Inversion
https://tomorrowx.com/research-zero-day-inversion

We would welcome the views of CISOs and security architects working on the gap between threat intelligence and operational prevention.

Marcus Thompson, AM, PhD Rob Parker Daryl Pereira Dr Dimitrios Salampasis (PhD, GAICD, FCSI, MSID, MRSV)

One of the most important ideas in the Monetary Authority of Singapore (MAS)’s new Safeguards for Agentic Finance at Run...
10/08/2026

One of the most important ideas in the Monetary Authority of Singapore (MAS)’s new Safeguards for Agentic Finance at Runtime (SAFR) paper is deceptively simple:

If AI agents are going to act, governance has to act too.

Not before deployment.

Not after something has gone wrong.

At runtime — before the action completes.

MAS proposes a governance checkpoint between an AI agent and ex*****on, incorporating Agent Identity, a Controls Repository, a Disposition Engine and an Audit Log.

This is very close to the architectural problem we developed Data Mediation™ to solve at TomorrowX.

Models and agents can provide intelligence and propose actions. But an independent control layer can sit between them and the enterprise systems they want to act upon.

There, the enterprise can:

→ understand the agent, data, context and proposed action
→ apply deterministic policy and risk controls
→ allow, deny, adjust or redirect an interaction
→ escalate where human intervention is required
→ retain operational evidence of what occurred
→ do this across modern and legacy systems, without requiring every underlying application to be rewritten

Importantly, the control does not have to belong to the model provider or agent platform.

The intelligence can be probabilistic. The authority does not have to be.

That becomes increasingly important as financial institutions move from AI that recommends to AI that can transact, approve, update and execute at machine speed.

MAS calls it safeguarding agentic finance at runtime.

We think it points to a broader architectural requirement for enterprise AI: the control plane must sit in the path of action — and it must remain under the enterprise’s control.

That is what Data Mediation enables.

MAS SAFR paper:
https://www.mas.gov.sg/publications/monographs-or-information-paper/2026/safeguards-for-agentic-finance-at-runtime

Our perspective on the architecture:
https://tomorrowx.com/research-control-plane

Why every enterprise AI architecture needs a customer-controlled, vendor-independent enforcement layer in the data path between AI services and enterprise resources.

Frontier AI is changing what boards must demand from cyber assurance. This is not an Australian issue. It is a board-lev...
06/08/2026

Frontier AI is changing what boards must demand from cyber assurance.

This is not an Australian issue. It is a board-level challenge for every organisation, in every jurisdiction.

New guidance from the Australian Signals Directorate and the Australian Institute of Company Directors asks boards to confront a rapidly changing reality:

• AI can identify and weaponise vulnerabilities faster
• multiple minor weaknesses can be chained into a major compromise
• attacks can increasingly operate with limited human oversight
• legacy systems and supply chains may contain risks that conventional reporting does not reveal
• incident response plans designed around human-speed attacks may no longer be sufficient

The full guidance is worth reading: https://www.cyber.gov.au/business-government/protecting-business-leaders/cyber-security-for-business-leaders/frontier-ai-cyber-threat-considerations-for-boards-of-directors

The central governance question is no longer simply: “Do we have the right policies and controls?”

It is: “Can management prove that those controls are operating effectively across modern systems, legacy technology, cloud environments, third parties, AI models and autonomous agents?”

This is the role TomorrowX plays.

Through Data Mediation™, TomorrowX establishes an observable and enforceable control point between systems, data, users, applications, AI models and agents.

It enables organisations to:
• observe data and activity as they move across the enterprise
• enforce security, access and data-handling policies in real time
• introduce compensating controls around legacy systems that cannot immediately be replaced
• restrict what AI models and agents can access or do
• simulate attacks, failures and operational changes before production is affected
• continuously record activity, decisions and control outcomes through a technical “Flight Recorder”

This gives boards and executives more than another dashboard or periodic declaration of compliance.

It provides continuously generated technical evidence to support assurance that controls are present, operating and producing their intended outcomes.

Boards do not need to become cyber engineers.
But they should be able to ask:

- What are our critical exposures?
- What controls are operating now?
- How do we know they work?
- Could the business continue operating during an AI-enabled attack?
- Can you show us the evidence?

As frontier AI compresses cyberattack timelines from days to hours—and potentially minutes—board assurance must become more continuous, more technical and more directly connected to the way the organisation actually operates.

Assurance cannot rely solely on being told that the organisation is protected. Boards must be able to see the evidence.

Address

Richmond
Melbourne, VIC
3121

Alerts

Be the first to know and let us send you an email when TomorrowX posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share