Human Above the Loop: why 'in the loop' is the wrong frame for agentic AI
The AI governance community is reinventing separation of duties and they don't know it. Human-in-the-loop fails at scale. The answer is human-above-the-loop: policy authoring, exception handling, and audit review, not click-to-approve.
The Loud Breach: what OpenAI's containment escape taught me about my own system
I read the HuggingFace/OpenAI incident report. Then I audited the autonomous agent system I operate. Here is what I found, what I changed, and what I am still worried about.
MCP's Security Problem Nobody's Writing About
I run MCP servers in production. The spec has gaps. Token theft portability, no server-side revocation, no audit trail. Here is what I see from the operator seat.
NIST AI RMF in practice: the best framework nobody is implementing
The AI Risk Management Framework is well-structured, well-intentioned, and almost entirely theoretical in most organizations. A practitioner analysis of what works, what is theater, and where the Govern function goes to die.
Zero Trust Applied to AI Systems: NIST SP 800-207 maps onto agentic security if you squint right
ZTA principles map directly onto agentic AI security. Agents are subjects. Tools are resources. The LLM is the policy decision point. Nobody in AI security has read 800-207, and nobody in network security thinks it applies to AI. Both are wrong.