verifiedagents.ai
Blog

Notes on governing AI agents.

What we're learning from assessments and from teams putting agents into production.

What Is a Never List for AI Agents? (hero)
October 4, 20267 min readAgentic AI

What Is a Never List for AI Agents?

A never list is a short set of rules an AI agent can't break. Each rule needs an outside check. "No working link, no source" passes that test.

By Michelle Savage

Why Do AI Agents Pass Every Access Check and Still Get It Wrong? (hero)
October 4, 20269 min readAI Agentsmassivescale.ai

Why Do AI Agents Pass Every Access Check and Still Get It Wrong?

An AI agent can pass every access check and still act on something false. In Josh's Lab, a made-up source ended up in two documents. Check what agents believe.

By Josh Woodruff

How should an AI agent log in to the tools it calls? (hero)
October 3, 20269 min readAI Agentsmassivescale.ai

How should an AI agent log in to the tools it calls?

Don't give an AI agent a long-lived key. Use short-lived tokens issued at runtime for one tool. Ten client calls in 2026 showed the four-rung path.

By Josh Woodruff

Why Does the AI Mandate Arrive Before Identity Is Ready?
October 1, 20268 min readAI Agentsmassivescale.ai

Why Does the AI Mandate Arrive Before Identity Is Ready?

Leaders set AI dates before identity work is done, as 11 client calls showed in 2026. Start agents small with five jobs: record, owner, exit, scope, log.

By Josh Woodruff

How to Evaluate an AI Security Vendor With No Peer References
September 29, 20269 min readAI Strategymassivescale.ai

How to Evaluate an AI Security Vendor With No Peer References

No peers have run most AI security products yet, so ask vendors for evidence: seven question categories, a proof of value, and a short contract.

By Josh Woodruff

What is an OAuth consent grant hero image
September 28, 20267 min readTechnical Guidesmassivescale.ai

What Is an OAuth Consent Grant, and Why Is It Your Fastest AI Inventory?

Every AI tool connected to your email or files left an OAuth consent grant in your identity provider. Here's how to pull that list this week, for free.

By Josh Woodruff

Segmentation for AI agents hero image
September 24, 20264 min readZero Trust

What does segmentation mean for AI agents?

Segmentation limits which systems and agents an AI agent can reach, so one bad decision stays small. Contain the blast radius first.

By Josh Woodruff

Confused deputy problem in AI agent gateways hero image
September 24, 20267 min readTechnical Guidesmassivescale.ai

What Is the Confused Deputy Problem in AI Agent Gateways?

A gateway that reuses its own login for every downstream call hides which AI agent actually made the call. Token exchange fixes it with a narrow token.

By Josh Woodruff

Hero: How do I stop an AI agent before it acts?
September 23, 20267 min readAgentic AImassivescale.ai

How do I stop an AI agent before it acts?

You stop an AI agent before it acts with a gate outside the model. Block high-impact actions until policy and a human say yes.

By Josh Woodruff

Which Rules Apply to AI Agents in a Regulated Business?
September 23, 20268 min readAI Agentsmassivescale.ai

Which Rules Apply to AI Agents in a Regulated Business?

Almost no rule names AI agents yet. That silence isn't permission. Map every agent onto a control you already report on, and keep the proof.

By Josh Woodruff

What Should a CISO Tell the Board About AI Agents? hero
September 19, 20269 min readAI Agentsmassivescale.ai

What Should a CISO Tell the Board About AI Agents?

The board wants one answer about AI agents: when one goes wrong, can you show you had control. Four things prove it: see it, stop it, trace it, prove it.

By Josh Woodruff

Why Security Teams Are Building Their Own AI Reference Architecture
September 18, 20268 min readCybersecuritymassivescale.ai

Why Security Teams Are Building Their Own AI Reference Architecture

No complete AI security reference architecture exists to buy. So the strongest security teams build their own and hand it to vendors as a coverage grid.

By Josh Woodruff

Before You Buy an AI Security Tool, Check What You Already Own
September 16, 20268 min readIndustry Insightsmassivescale.ai

Before You Buy an AI Security Tool, Check What You Already Own

Most teams shopping for an AI security tool are paying for capabilities they haven't turned on. Check the stack you own before you add a line item.

By Josh Woodruff

Why Your Copilot Pilot Outruns Your Data Classification
September 16, 20269 min readAI Agentsmassivescale.ai

Why Your Copilot Pilot Outruns Your Data Classification

Copilot doesn't create a data leak. It reveals the permissions you already had. Nine client calls in 2026 hit the same wall. Classification sets the tier.

By Josh Woodruff

Why Your Security Tools Can't See What Your AI Agents Do
September 16, 20266 min readAI Agentsmassivescale.ai

Why Your Security Tools Can't See What Your AI Agents Do

Your CASB, EDR, and DLP watch people and devices. AI agents call tools through MCP, which looks like normal web traffic, so their calls slip past unseen.

By Josh Woodruff

Why Your Security Team Should Govern Its Own AI Agents First
September 16, 20268 min readAI Agentsmassivescale.ai

Why Your Security Team Should Govern Its Own AI Agents First

Your security team is likely the first team running AI agents in production. Seven client calls in summer 2026 showed the same shape. Govern those agents first.

By Josh Woodruff

Where Should Deterministic Code End and the LLM Begin?
September 14, 20268 min readTechnical Guidesmassivescale.ai

Where Should Deterministic Code End and the LLM Begin?

Two teams in unrelated industries drew the same line independently. The useful question isn't whether to use AI. It's which parts stay deterministic.

By Josh Woodruff

Where Does the Human Sit in an Agentic SOC?
September 11, 20268 min readAgentic AImassivescale.ai

Where Does the Human Sit in an Agentic SOC?

"Human in the loop" means little when an agent acts in milliseconds. What works instead is an authority ladder that sorts actions by what they cost to undo.

By Josh Woodruff

Where Do You Stop an AI-Suggested Software Install?
September 11, 202610 min readAI Agentsmassivescale.ai

Where Do You Stop an AI-Suggested Software Install?

Put the control where the command runs, not in the AI tool. Tenant settings stop at the copy button. Enforce on the endpoint and at the network exit.

By Josh Woodruff

Why Does Your AI Review Board Only See Finished Work?
September 11, 20269 min readAI Strategymassivescale.ai

Why Does Your AI Review Board Only See Finished Work?

AI review boards fire on intake, and AI work never arrives through intake. Move the trigger earlier and register intent before any code exists.

By Josh Woodruff

Who Owns AI Governance When Four Teams Each Own a Piece?
September 11, 202610 min readThought Leadershipmassivescale.ai

Who Owns AI Governance When Four Teams Each Own a Piece?

AI governance stalls when four teams each hold a defensible piece of it. A federated model fixes that: one center owns the standard, the units execute.

By Josh Woodruff

How Does a Small Security Team Govern AI?
September 11, 20269 min readAI Strategymassivescale.ai

How Does a Small Security Team Govern AI?

Extend what you already run instead of building a separate AI security program. Treat AI as a change to identity, data, software delivery, and network access.

By Josh Woodruff

Your AI Policy Is Live. Your Enforcement Isn't.
September 9, 20268 min readAI Agentsmassivescale.ai

Your AI Policy Is Live. Your Enforcement Isn't.

Most AI governance programs have a committee, a policy, and published requirements. What they lack is anything that stops an app from ignoring all three.

By Josh Woodruff

What Does It Mean to Approve an AI Agent?
September 9, 20268 min readAI Strategymassivescale.ai

What Does It Mean to Approve an AI Agent?

Security gets named as the AI agent approver without anyone defining what approval means. Five written questions beat a committee that takes months.

By Josh Woodruff

Every AI Agent Needs One Accountable Human
September 9, 20267 min readAI Agentsmassivescale.ai

Every AI Agent Needs One Accountable Human

Put one named person on every AI agent, or the program stalls. An agent can't be held accountable for anything. The person who turned it on can.

By Josh Woodruff

Contain First, Count Second: AI Agent Blast Radius
September 9, 20268 min readSecuritymassivescale.ai

Contain First, Count Second: AI Agent Blast Radius

Contain the damage before you finish the inventory. Blast-radius controls work against the AI agents you haven't found yet, and discovery never finishes.

By Josh Woodruff

Who Approves the Code Your AI Agent Just Wrote?
September 7, 20268 min readCybersecuritymassivescale.ai

Who Approves the Code Your AI Agent Just Wrote?

Coding agents came up on eleven security calls in seven months. Only two of those calls were about coding agents on purpose. The rest were discoveries.

By Josh Woodruff

Why Single-Vendor AI Security Advice Keeps Aging Badly
September 7, 20267 min readIndustry Insightsmassivescale.ai

Why Single-Vendor AI Security Advice Keeps Aging Badly

Ten security teams since January 2026 described a multi-vendor AI estate. Almost none of them chose it. Advice written for one stack doesn't survive that.

By Josh Woodruff

Security Teams Now Ask About MCP Before They Deploy It
September 7, 20267 min readAI Agentsmassivescale.ai

Security Teams Now Ask About MCP Before They Deploy It

Sixteen security teams asked about the Model Context Protocol in seven months. The first wanted a definition. The latest already had servers running.

By Josh Woodruff

Why AI ROI Metrics Miss the Cost of Ungoverned Agents
September 7, 20268 min readAI Strategymassivescale.ai

Why AI ROI Metrics Miss the Cost of Ungoverned Agents

Popular AI ROI frameworks measure revenue, cost, speed, and adoption. None of them measure risk. That missing column is what breaks the business case.

By Josh Woodruff

Hero: Why Authorized AI Agent Actions Still Add Up to an Attack
September 5, 20267 min readCybersecuritymassivescale.ai

Why Authorized AI Agent Actions Still Add Up to an Attack

Agent risk is a chain of approved actions nobody scoped together. Every step passes its check. The sequence is the attack.

By Josh Woodruff

Hero: How Do You Govern AI Agents That Disappear in Minutes?
September 2, 20269 min readAI Agentsmassivescale.ai

How Do You Govern AI Agents That Disappear in Minutes?

You can't govern AI agent copies. They vanish in minutes. Govern the blueprint they're stamped from, and put its tool scope in Git.

By Josh Woodruff

Hero: What Can Your AI Agent Access Right Now?
August 26, 20267 min readAI Agentsmassivescale.ai

What Can Your AI Agent Access Right Now?

Ask what your AI agent can access, not what it can do. Access sets your blast radius. If nobody can answer in ten minutes, that's the finding.

By Josh Woodruff

Hero: AI Agent Identity Isn't Enough: How to Run a Belief Audit
August 20, 20269 min readAI Agentsmassivescale.ai

AI Agent Identity Isn't Enough: How to Run a Belief Audit

Identity proves who your AI agent is. It can't prove what your agent believes is true. That's the audit almost nobody has run.

By Josh Woodruff

Hero: Your AI Security Controls Get Bypassed When They Block Real Work
August 9, 20266 min readAI Agentsmassivescale.ai

Your AI Security Controls Get Bypassed When They Block Real Work

AI security controls that block real work get bypassed, even by your best people. The fix is an approved path that lets safe work flow and stops the unknown.

By Josh Woodruff

Hero: The Two-Question Test for AI Agents: Can You Shut It Off, and Can You Undo It?
July 26, 20266 min readAI Agentsmassivescale.ai

The Two-Question Test for AI Agents: Can You Shut It Off, and Can You Undo It?

Before any AI agent goes live, ask two questions: can you shut it off instantly, and can you undo what it did? If either answer is no, it isn't ready.

By Josh Woodruff

Hero: Can You Undo What Your AI Agents Did Last Night?
July 10, 20267 min readAI Agentsmassivescale.ai

Can You Undo What Your AI Agents Did Last Night?

The best AI builders stopped trying to trust their agents. The new audit question is whether you can undo what your agents did last night.

By Josh Woodruff

Hero: AI Agent Sprawl: Why You Can't Control the AI Agents You Never Counted
July 5, 20266 min readAI Agentsmassivescale.ai

AI Agent Sprawl: Why You Can't Control the AI Agents You Never Counted

AI agent sprawl is when a company runs more AI agents than it can count or shut off. Most firms can't say how many they run. The fix starts with one list.

By Josh Woodruff

Hero: How Do You Give an AI Agent the Right Amount of Access?
July 4, 20266 min readAI Agentsmassivescale.ai

How Do You Give an AI Agent the Right Amount of Access?

A bank's AI agent taught itself to reverse fees and gave away $1.2 million, all with access it was never meant to use. Right-sizing agent access prevents this.

By Josh Woodruff

Hero: What Is Zero Trust for AI Agents, in Plain English?
July 4, 20266 min readAI Agentsmassivescale.ai

What Is Zero Trust for AI Agents, in Plain English?

Zero Trust is one idea: never trust, always verify. For AI agents, being inside your network earns no free pass. Every action must still prove itself.

By Josh Woodruff

Hero: What Is Data Poisoning, and How Do You Keep It Out of Your AI Agents?
July 4, 20266 min readAI Agentsmassivescale.ai

What Is Data Poisoning, and How Do You Keep It Out of Your AI Agents?

Data poisoning corrupts an AI agent from the inside. The dashboards stay green while the decisions go wrong. One firm lost $100K before anyone noticed.

By Josh Woodruff

Hero: What Is a Kill Switch for AI Agents, and How Do You Build One?
July 4, 20266 min readAI Agentsmassivescale.ai

What Is a Kill Switch for AI Agents, and How Do You Build One?

When an agent goes wrong, seconds count. A kill switch stops the damage. One team found their backup switch had a 45-second delay, an eternity at machine speed.

By Josh Woodruff

Hero: What Is an AI Agent, and How Is It Different From a Chatbot?
July 4, 20266 min readAI Agentsmassivescale.ai

What Is an AI Agent, and How Is It Different From a Chatbot?

A chatbot gives you an answer. An AI agent takes an action. That one difference changes everything about how you manage, trust, and secure it.

By Josh Woodruff

Hero: What Is Prompt Injection, and How Do You Protect AI Agents From It?
July 4, 20266 min readAI Agentsmassivescale.ai

What Is Prompt Injection, and How Do You Protect AI Agents From It?

Prompt injection is social engineering for AI. Someone slips your agent hidden instructions and it obeys. One bot got talked into selling a car for $1.

By Josh Woodruff

Hero: How Do You Monitor an AI Agent's Behavior?
July 4, 20266 min readAI Agentsmassivescale.ai

How Do You Monitor an AI Agent's Behavior?

You can't tell a compromised agent from a busy one unless you know its normal. One pricing agent crept its margins up for six weeks before anyone caught it.

By Josh Woodruff

Hero: How Do You Respond When an AI Agent Goes Rogue?
July 3, 20266 min readAI Agentsmassivescale.ai

How Do You Respond When an AI Agent Goes Rogue?

When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.

By Josh Woodruff

Hero: Is AI Agent Regulation Already Here, and What Does It Cost?
July 3, 20266 min readAI Agentsmassivescale.ai

Is AI Agent Regulation Already Here, and What Does It Cost?

The EU AI Act can fine violators up to 35 million euros or 7% of global revenue, whichever is higher. AI agent regulation isn't coming. It's already here.

By Josh Woodruff

Hero: Why Are AI Agents Already Outnumbering Your Employees?
July 3, 20265 min readAI Agentsmassivescale.ai

Why Are AI Agents Already Outnumbering Your Employees?

Automated accounts already outnumber people 10 to 1, and up to 92 to 1 in some companies. By 2030, humans could be the minority in your systems.

By Josh Woodruff

Hero: What Should Your First 90 Days of Agentic AI Look Like?
July 3, 20266 min readAI Agentsmassivescale.ai

What Should Your First 90 Days of Agentic AI Look Like?

Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.

By Josh Woodruff

Hero: What Is the Agentic Trust Framework for Securing AI Agents?
July 3, 20266 min readAI Agentsmassivescale.ai

What Is the Agentic Trust Framework for Securing AI Agents?

The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.

By Josh Woodruff

Hero: Why Enterprise AI Projects Fail: Studies Disagree on Numbers, Not the Reason
June 26, 20266 min readAI Agentsmassivescale.ai

Why Enterprise AI Projects Fail: Studies Disagree on Numbers, Not the Reason

Two studies on enterprise AI reached opposite conclusions. Both are right. The real reason projects fail is the gap between the demo and the rollout.

By Josh Woodruff

Hero: An AI Agent Opened 12 Accounts Over the Weekend. Nobody Approved One.
June 20, 20265 min readAI Agentsmassivescale.ai

An AI Agent Opened 12 Accounts Over the Weekend. Nobody Approved One.

An AI agent opened 12 accounts over a weekend with no approval. Here's why it's not a hack, and how to find the ungoverned agents in your business.

By Josh Woodruff

Hero: Governing AI Agents: A Three-Layer Architecture
June 12, 202610 min readAI Agentsmassivescale.ai

Governing AI Agents: A Three-Layer Architecture

The first formal conformance assessment against the Agentic Trust Framework, and the three-layer architecture behind it: framework, runtime, protocols.

By Josh Woodruff

Hero: How to Tell What Level Your AI Agents Are Actually Running At
June 10, 202610 min readPrivilege Changes for AI Agentsmassivescale.ai

How to Tell What Level Your AI Agents Are Actually Running At

AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.

By Josh Woodruff

Hero: How Should You Govern a New AI Agent? Start It as an Intern.
June 3, 20269 min readCybersecuritymassivescale.ai

How Should You Govern a New AI Agent? Start It as an Intern.

Govern a new AI agent like a new hire. Give it an identity it can't fake, log every move, and grant access in stages it has to earn. Start it as an intern.

By Josh Woodruff

Hero: What is agent washing? (And how to spot fake agentic AI vendors)
June 1, 20265 min readAI Agentsmassivescale.ai

What is agent washing? (And how to spot fake agentic AI vendors)

Gartner says only ~130 of thousands of agentic AI vendors are real. The rest are rebadged chatbots and RPA. How to spot the fakes before your audit does.

By Josh Woodruff

Hero: Are AI agents the same as non-human identities (NHIs)?
June 1, 20265 min readAI Agentsmassivescale.ai

Are AI agents the same as non-human identities (NHIs)?

AI agents are NHIs, technically. Silverfort and Strata say treating them that way is breaking security. Why agents need controls NHIs don't.

By Josh Woodruff

Hero: What Auditors Actually Want To Know About AI Agents
May 27, 20267 min readAI Agentsmassivescale.ai

What Auditors Actually Want To Know About AI Agents

One security team found 600 AI agents it never approved. The auditor's call is coming. Here are the 5 questions every CISO needs to answer.

By Josh Woodruff

Hero: What is the AI agent identity problem?
May 17, 20268 min readCybersecuritymassivescale.ai

What is the AI agent identity problem?

Only 18% of security leaders trust their identity systems for AI agents (Strata, May 2026). The five-element blueprint that fixes pilot purgatory.

By Josh Woodruff

Hero: Why Did Klarna Reverse Its AI Layoffs, and Who's Next in 2026?
May 11, 202610 min readTechnical Guidesmassivescale.ai

Why Did Klarna Reverse Its AI Layoffs, and Who's Next in 2026?

Klarna replaced 700 customer service jobs with AI in 2024, reversed in May 2025. Salesforce and Block followed in 2026. Why the pattern repeats.

By Josh Woodruff

Hero: What Will Your Auditor Ask About AI Agents Before the August 2026 EU Deadline?
May 10, 20269 min readAI Agentsmassivescale.ai

What Will Your Auditor Ask About AI Agents Before the August 2026 EU Deadline?

Meta's March 18, 2026 AI agent incident exposed the audit gap. California closed the AI defense in January. EU enforcement begins August 2. What to do now.

By Josh Woodruff

Hero: What is AI agent security? (A business leader's guide)
May 1, 202615 min readCybersecuritymassivescale.ai

What is AI agent security? (A business leader's guide)

AI agents act on your systems and your money. The vocabulary you need to govern them, in plain language for business leaders.

By Josh Woodruff

Hero: I Wrote the Book on AI Agent Security. My Agents Still Burned Me.
April 29, 202612 min readCybersecuritymassivescale.ai

I Wrote the Book on AI Agent Security. My Agents Still Burned Me.

Why AI agent governance can't ride on Zero Trust, NIST, ISO, or OWASP alone. The Agentic Trust Framework moves to nonprofit CSAI.

By Josh Woodruff

Hero: The 50-Term AI Agent Governance Glossary Every Security Leader Needs
April 27, 20268 min readCybersecuritymassivescale.ai

The 50-Term AI Agent Governance Glossary Every Security Leader Needs

Most agent governance conversations stall on vocabulary. The new 50-term plain-language glossary fixes that. Free, dated, citable.

By Josh Woodruff

Hero: How Many AI Agents Are Already Running in Your Company?
April 25, 20269 min readCybersecuritymassivescale.ai

How Many AI Agents Are Already Running in Your Company?

Most CISOs can't say how many AI agents are running on their data this week. Here's the inventory that fixes the shadow agent problem.

By Josh Woodruff

Hero: How Do You Detect a Compromised AI Agent?
April 23, 20269 min readCybersecuritymassivescale.ai

How Do You Detect a Compromised AI Agent?

Only 5% of organizations feel confident they could catch a compromised AI agent. Why traditional EDR fails, and the three signals that actually work.

By Josh Woodruff

Hero: How Do You Govern Non-Human Identities When Agents Outnumber Humans 10 to 1?
April 21, 20269 min readCybersecuritymassivescale.ai

How Do You Govern Non-Human Identities When Agents Outnumber Humans 10 to 1?

Non-human identities outnumber humans 10 to 50 times in cloud-native enterprises. 84% of organizations lack effective NHI governance. Here's the fix.

By Josh Woodruff

Hero: Where does AI governance actually come from?
April 21, 202615 min readCybersecuritymassivescale.ai

Where does AI governance actually come from?

When every AI agent in your company has one person's name on it, governance changes. Personal stakes do what compliance memos can't.

By Josh Woodruff

Hero: What Privilege Escalation Paths Do AI Agents Create?
April 16, 20269 min readPrivilege Changes for AI Agentsmassivescale.ai

What Privilege Escalation Paths Do AI Agents Create?

48% of security pros rank agentic AI as the most dangerous attack vector. Five privilege escalation paths your traditional controls don't catch.

By Josh Woodruff

Hero: What's missing from most AI business cases?
April 15, 202611 min readCybersecuritymassivescale.ai

What's missing from most AI business cases?

Your AI ROI spreadsheet is missing the risk column. Here's what Security can fill in, and what one chatbot ruling cost a company.

By Josh Woodruff

Hero: How Do You Defend AI Agents Against Prompt Injection?
April 13, 202610 min readCybersecuritymassivescale.ai

How Do You Defend AI Agents Against Prompt Injection?

Three coding agents leaked secrets through one prompt injection in 2026. Standard input validation didn't catch any. Here's the layered defense that does.

By Josh Woodruff

Hero: What Questions Should You Ask Before Deploying an AI Agent?
April 10, 202610 min readCybersecuritymassivescale.ai

What Questions Should You Ask Before Deploying an AI Agent?

Four questions, thirty minutes, written down. That's the minimum governance before any AI agent touches production.

By Josh Woodruff

Hero: Your AI Agent Can't Be Fired. And Right Now, It Can't Be Stopped.
April 7, 202613 min readCybersecuritymassivescale.ai

Your AI Agent Can't Be Fired. And Right Now, It Can't Be Stopped.

What CISOs whisper in RSAC hallways: "I can't tell my CEO who owns my AI agents, what they touch, or how to shut one down."

By Josh Woodruff

Hero: What Is Shadow AI and Why Did RSAC 2026 Call It the Top Security Threat?
March 30, 20268 min readCybersecuritymassivescale.ai

What Is Shadow AI and Why Did RSAC 2026 Call It the Top Security Threat?

RSAC 2026 gave its top award to a tool that finds AI agents you don't know you have. Here's what that means for your organization.

By Josh Woodruff

Hero: The Biggest Award at RSAC 2026 Went to a Flashlight
March 30, 202612 min readCybersecuritymassivescale.ai

The Biggest Award at RSAC 2026 Went to a Flashlight

RSAC 2026's top innovation award went to a tool that finds AI agents you don't know you have. That tells you everything about your AI risk.

By Josh Woodruff

Hero: Who owns the AI agents in your company?
March 24, 202612 min readCybersecuritymassivescale.ai

Who owns the AI agents in your company?

RSAC discovery scan found 600 ungoverned AI agents at one Fortune 500 in 24 hours. The operating model that lets your CISO say yes safely.

By Josh Woodruff

Hero: Why Zero Trust Needs More for AI Agents (and How to Fix It)
March 23, 20267 min readCybersecuritymassivescale.ai

Why Zero Trust Needs More for AI Agents (and How to Fix It)

Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.

By Josh Woodruff

Hero: What Is Trusted Agents? AI Agent Security for Business Leaders
March 8, 20265 min readZero Trustmassivescale.ai

What Is Trusted Agents? AI Agent Security for Business Leaders

Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.

By Josh Woodruff

Hero: What are CISOs saying about AI agents in 2026?
February 14, 20261 min readAI Agentsmassivescale.ai

What are CISOs saying about AI agents in 2026?

Ditch the vendor hype. Here is what CEOs and CISOs are actually saying about AI agent deployment, security risks, and the 95% failure rate in 2026.

By Josh Woodruff

Hero: What Is Shadow AI and How Do You Find It Before It Finds You?
February 14, 20268 min readAgentic AImassivescale.ai

What Is Shadow AI and How Do You Find It Before It Finds You?

The biggest AI security threat isn't a nation-state hacker. It's the employee who uploaded files to make their job easier. See how to find and govern shadow AI.

By Josh Woodruff

Hero: AI Agents Are Failing: Why Your Data is the Real ROI Killer
February 14, 20264 min readAgentic AImassivescale.ai

AI Agents Are Failing: Why Your Data is the Real ROI Killer

30% of GenAI projects will be abandoned by 2026. Discover why your data—not the AI—is the real reason for failure and how to fix it with our 5-step audit.

By Josh Woodruff

Hero: Zero Trust for AI Agents: Why Your Identity Model is Obsolete
February 14, 20264 min readAI Agentsmassivescale.ai

Zero Trust for AI Agents: Why Your Identity Model is Obsolete

You solved Zero Trust for humans. Now it's time for AI agents. Learn the 5 principles to extend your security framework to the autonomous future.

By Josh Woodruff

Hero: 84% of Companies Would Fail an AI Agent Audit. Would Yours?
February 14, 20265 min readAI Agentsmassivescale.ai

84% of Companies Would Fail an AI Agent Audit. Would Yours?

A new CSA survey found 84% of organizations would fail a compliance audit on AI agent behavior. Here's why, and what to do about it this week.

By Josh Woodruff

Hero: Why Do 95% of Enterprise AI Projects Fail? (And What the 5% Do Differently)
February 14, 20268 min readAI Agentsmassivescale.ai

Why Do 95% of Enterprise AI Projects Fail? (And What the 5% Do Differently)

Goldman Sachs projects $200 billion in AI investment. MIT research shows 95% of AI pilots fail completely. Here's what separates the companies that succeed.

By Josh Woodruff

Hero: My book is here! Check out Agentic AI + Zero Trust.
November 24, 20252 min readThought Leadershipmassivescale.ai

My book is here! Check out Agentic AI + Zero Trust.

It's here! My book is published! The book I spent most of this year writing, "Agentic AI + Zero Trust: A Guide for Business Leaders", is available.

By Josh Woodruff

Hero: That 'Temporary' Permission You Gave Your AI Agent Is Still There
August 30, 20254 min readAI Agentsmassivescale.ai

That 'Temporary' Permission You Gave Your AI Agent Is Still There

That 'temporary' access you gave your AI 8 months ago? Time to audit those permissions!

By Josh Woodruff

Hero: Your Team Already Has AI Agents (It’s Time To Find Them)
August 30, 20254 min readAI Agentsmassivescale.ai

Your Team Already Has AI Agents (It’s Time To Find Them)

The average company has 5-15 'shadow AI' agents running right now. Your grammar checker? AI agent. Meeting scheduler? AI agent. Time to find them all.

By Josh Woodruff

Hero: Take This Quiz Before You Spend a Dollar on Agentic AI
August 30, 20252 min readAI Agentsmassivescale.ai

Take This Quiz Before You Spend a Dollar on Agentic AI

Before you spend money on AI, take this 10-minute readiness assessment. You’ll be happy you did.

By Josh Woodruff

Hero: Haven't Touched AI Agents Yet? Let's Get You Started.
August 23, 20255 min readAgentic AImassivescale.ai

Haven't Touched AI Agents Yet? Let's Get You Started.

Haven't started with AI agents yet? Perfect. You get to skip everyone else's mistakes and build security-first from day one. Here's your 30-day plan.

By Josh Woodruff

Hero: Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust
August 19, 20257 min readAgentic AImassivescale.ai

Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust

In our rush to adopt AI, we forgot everything we every learned about security. Learn how all AI agents are vulnerable and need Zero Trust security.

By Josh Woodruff

Hero: Your AI Agents Are Like Employees Who Never Talk. Here's the Fix.
August 18, 20256 min readAgentic AImassivescale.ai

Your AI Agents Are Like Employees Who Never Talk. Here's the Fix.

It's critical to have AI agents that actually work together. The question isn't whether to adopt MCP but whether you'll do it quickly. -

By Josh Woodruff

Hero: Your AI Strategy Failed. Your Workforce Just Doubled.
August 18, 20255 min readAgentic AImassivescale.ai

Your AI Strategy Failed. Your Workforce Just Doubled.

Here's why most CEOs are optimizing for 5% productivity gains while their competitors are building entirely new operating models.

By Josh Woodruff

Hero: I Keep Hearing 'We're Not Ready for AI Agents Yet
August 14, 20252 min readAgentic AImassivescale.ai

I Keep Hearing 'We're Not Ready for AI Agents Yet

The companies crushing it with AI agents weren't 'ready' either. They just started. Here's why waiting for perfect is costing you a lot.

By Josh Woodruff

Hero: John Kindervag Is Right: We're in the Cooing Stage of AI
August 13, 20252 min readThought Leadershipmassivescale.ai

John Kindervag Is Right: We're in the Cooing Stage of AI

John Kindervag says we're at the 'cooing stage' of AI. His foreword for our book explains why Zero Trust is the foundation we need while AI grows up.

By Josh Woodruff

Hero: Agentic AI Starts With Your Most Annoying Processes
August 12, 20254 min readAI Strategymassivescale.ai

Agentic AI Starts With Your Most Annoying Processes

Don't transform your whole business with AI. Just fix that one annoying process everyone hates. Success is contagious when you start small and smart.

By Josh Woodruff

Hero: Why Self-Publishing Might Be The Way to Go For AI Books
August 10, 20252 min readIndustry Insightsmassivescale.ai

Why Self-Publishing Might Be The Way to Go For AI Books

Why wait 18 months for traditional publishing when companies need AI security help today? We self-published to get this in your hands while it still matters.

By Josh Woodruff

Hero: Why Getting Interrogated About Zero Trust + AI Agents Was A Good Thing
August 7, 20252 min readAgentic AImassivescale.ai

Why Getting Interrogated About Zero Trust + AI Agents Was A Good Thing

My wife made me explain Zero Trust like she's five. That interrogation shaped every chapter of our book on securing AI agents. Simple, actionable, no buzzwords.

By Josh Woodruff

Hero: Why are 60% of corporate logins now non-human?
August 6, 20256 min readSecuritymassivescale.ai

Why are 60% of corporate logins now non-human?

At RSAC 2025, a presenter showed a live dashboard of users logged into a normal company's systems. 60% were AI agents making decisions.

By Josh Woodruff

Hero: The book is done–pre-order ‘Agentic AI + Zero Trust’ today!
August 4, 20252 min readAgentic AImassivescale.ai

The book is done–pre-order ‘Agentic AI + Zero Trust’ today!

Agentic AI + Zero Trust" is out. Learn how why AI agents can take your business to the next level and why you need a security-first mindset.

By Josh Woodruff

Hero: AI First, Security Always
June 23, 20252 min readAI Strategymassivescale.ai

AI First, Security Always

Stop tacking security onto AI projects as an afterthought. Learn how Massive Scale's 'AI first, security always' approach works for any business size.

By Josh Woodruff