I got a "CRITICAL: session hijack detected" email at 4am. it was my own test, but the system didn't know that. it killed the session and blocklisted the token on its own
On every project i set up a stack of security checks before launch: session fingerprinting, rate limits,...
Everyones shipping AI apps fast… but no one’s talking about how often they quietly fail
wrong outputs, 0 guardrails, no monitoring... and users just lose trust
this is not innovation, its risk in disguise
If you are building with AI, build it right.. or do not ship it