Writing
Short pieces and in-depth articles on AI, identity, and accountability for boards and security leaders.
Featured whitepaper
What Five AI Governance Frameworks Agree On, and What None of Them Solves
Five major governance specifications for AIgentic systems converged on the same verification posture in the first quarter of 2026: provision identity correctly, grant minimum permissions, monitor behavior, enforce policy at every access decision. The convergence confirms field consensus across CSA, IETF, NIST, and CoSAI. It also reveals the field's shared structural limit: none of the four peer frameworks prescribes a topology-first enforcement substrate that constrains an AIgentic Actor's action space before any identity check runs. For security leaders deploying agents in 2026, this synthesis identifies the precise gap between framework compliance and operational security, and the three architectural additions that close it.
Key questions this whitepaper addresses
- What does the convergence of four independently produced governance frameworks reveal about where the field currently stands?
- Where does each of the five frameworks reach its structural limit, and why is that limit a property of the verification paradigm rather than a design flaw?
- What three architectural additions must a security leader supply that no single framework fully specifies?
Recent writing
We publish paired pieces each week — one for boards and committees, one for CISOs and security architects — on the same theme. In-depth articles appear on a bi-monthly cadence.
Security leaders
Permission Is Not Control: Why an Authorized Agent Is Still an Insider
A properly authorized AI agent can exfiltrate a codebase without breaking a rule. Why identity controls fail and action-layer authorization is the fix.
Define the Harm Ceiling Before the Agent Runs
OWASP LLM06 Excessive Agency is an authorization failure, not a cost problem. Risk budgets translate into four architectural controls every CISO must implement.
Governing Non-Human Identity at Machine Pace
Zero standing privilege, dual-identity credential binding, human sponsorship model: three architectural requirements for NHI governance in agentic pipelines.
The CoSAI Evaluation: What the Field's Most Complete Toolkit Reveals About the Verification Posture
CoSAI's Agentic IAM framework is the most detailed published guidance on AIgentic identity. It shares the same structural limit as every prior framework.
The NIST NCCoE Concept Paper: An Evaluation
NIST's NCCoE concept paper identifies five AI agent IAM focus areas. What it establishes, where it reaches its limit, and what security architects must add.
The IETF AIGA Draft: An Evaluation
IETF AIGA draft evaluated: Tiered Risk-Based Governance, Immutable Kernel Architecture, Constitutional Constraints, and four additions to make it operational.
Governing AIgentic Actors: Identity, Trust and Control
10-slide deck on Actor governance, topology-first architecture, and the Actor Identity Lifecycle for AIgentic systems.
Nine Seconds: What the PocketOS Incident Reveals
A Cursor AI agent deleted PocketOS's entire production database in nine seconds. Three architectural failures made this inevitable — and the proxy architectural design pattern is the answer.
The CSA Agentic Trust Framework: An Evaluation
CSA Agentic Trust Framework: what it establishes, where behavioral verification fails for non-deterministic actors, and four additions to make ATF operational.
Governing AIgentic Actors: Identity, Trust and Control
Governing AIgentic Actors is an architectural problem, not a verification one. The Actor Identity Lifecycle is the operational answer a CISO can execute now.
Treat Your AI Agents Like You Treat Untrusted Code
AI agents in production need a three-layer security architecture: semantic proxy enforcement, subnet isolation, and per-agent identity. Here's how to build it.
The Semantic Proxy Pattern
12-slide technical reference on the semantic proxy pattern: three-layer defense architecture for enterprise AI agent authorization.
Treat Your AI Agents Like Untrusted Code
10-slide deck on the three-layer agent security architecture: semantic proxy, subnet isolation, per-agent identity.
The Semantic Proxy Pattern
A three-layer reference architecture for enterprise AI agent authorization: semantic proxy, subnet isolation, and per-agent identity. Technical whitepaper with implementation roadmap.
The Identity Crisis at the Heart of AIgentic Systems
AIgentic architecture dissolves the application-as-gatekeeper model. A technical briefing on the four-layer identity architecture — directories, workload PKI, verifiable credentials, and DIDs — emerging to replace it.
Boards
The Budget Your Board Never Approved
Enterprises govern AI agents by cost. That is the wrong budget. Risk budgets define the harm ceiling — the security control financial budgets cannot provide.
The Hidden Compliance Exposure in Your AI Deployment
AI agents generate credentials that most boards cannot account for. DORA and EU AI Act obligations apply. Here is the governance case.
The CoSAI Evaluation: What Industry Consensus on AIgentic Governance Means for Boards
CoSAI is the fourth framework to establish human governance as a requirement for AIgentic systems. For boards, that consensus is a liability question.
What NIST's AI Agent Governance Work Means for Your Board
NIST's NCCoE identifies five AI agent governance focus areas with no compliance force yet. Here's what boards need to know and ask right now.
What the IETF's AI Governance Draft Means for Board Accountability
The IETF's AIGA draft defines five AI agent risk tiers with specific infrastructure requirements. Here's what boards need to know and ask.
The Agent Problem: Why Your AI Workforce Needs a Different Kind of Oversight
AI agents take real actions at machine speed without per-action human review. A board-level briefing on the oversight infrastructure your organization needs.
The Agent Problem: Why Your AI Workforce Needs a Different Kind of Oversight
10-slide board briefing on AI agent oversight infrastructure and the four governance properties boards should verify.
Who's Running Your Organization? The Identity Challenge of the AI Agent Era
AI agents are becoming first-class actors inside enterprises, without appearing in any directory. A briefing for boards and security leaders on the identity gap and the architecture that closes it.
Stay current
We publish short pieces for boards and security leaders on AI, identity, and governance. No hype, no spam. Each piece is designed to be read in two minutes and reused in your own internal conversations.
Get in touch