Notes on governing AI agents.
What we're learning from assessments and from teams putting agents into production.

What Is a Never List for AI Agents?
A never list is a short set of rules an AI agent can't break. Each rule needs an outside check. "No working link, no source" passes that test.
By Michelle Savage

How do I stop an AI agent before it acts?
You stop an AI agent before it acts with a gate outside the model. Block high-impact actions until policy and a human say yes.
By Josh Woodruff

Where Does the Human Sit in an Agentic SOC?
"Human in the loop" means little when an agent acts in milliseconds. What works instead is an authority ladder that sorts actions by what they cost to undo.
By Josh Woodruff

Who Owns AI Governance When Four Teams Each Own a Piece?
AI governance stalls when four teams each hold a defensible piece of it. A federated model fixes that: one center owns the standard, the units execute.
By Josh Woodruff

Every AI Agent Needs One Accountable Human
Put one named person on every AI agent, or the program stalls. An agent can't be held accountable for anything. The person who turned it on can.
By Josh Woodruff

AI Agent Sprawl: Why You Can't Control the AI Agents You Never Counted
AI agent sprawl is when a company runs more AI agents than it can count or shut off. Most firms can't say how many they run. The fix starts with one list.
By Josh Woodruff

What Is an AI Agent, and How Is It Different From a Chatbot?
A chatbot gives you an answer. An AI agent takes an action. That one difference changes everything about how you manage, trust, and secure it.
By Josh Woodruff

How Do You Respond When an AI Agent Goes Rogue?
When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.
By Josh Woodruff

Is AI Agent Regulation Already Here, and What Does It Cost?
The EU AI Act can fine violators up to 35 million euros or 7% of global revenue, whichever is higher. AI agent regulation isn't coming. It's already here.
By Josh Woodruff

Why Are AI Agents Already Outnumbering Your Employees?
Automated accounts already outnumber people 10 to 1, and up to 92 to 1 in some companies. By 2030, humans could be the minority in your systems.
By Josh Woodruff

What Should Your First 90 Days of Agentic AI Look Like?
Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.
By Josh Woodruff

What Is the Agentic Trust Framework for Securing AI Agents?
The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.
By Josh Woodruff

How to Tell What Level Your AI Agents Are Actually Running At
AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.
By Josh Woodruff

How Should You Govern a New AI Agent? Start It as an Intern.
Govern a new AI agent like a new hire. Give it an identity it can't fake, log every move, and grant access in stages it has to earn. Start it as an intern.
By Josh Woodruff

Why Zero Trust Needs More for AI Agents (and How to Fix It)
Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.
By Josh Woodruff

What Is Trusted Agents? AI Agent Security for Business Leaders
Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.
By Josh Woodruff

What are CISOs saying about AI agents in 2026?
Ditch the vendor hype. Here is what CEOs and CISOs are actually saying about AI agent deployment, security risks, and the 95% failure rate in 2026.
By Josh Woodruff

What Is Shadow AI and How Do You Find It Before It Finds You?
The biggest AI security threat isn't a nation-state hacker. It's the employee who uploaded files to make their job easier. See how to find and govern shadow AI.
By Josh Woodruff

AI Agents Are Failing: Why Your Data is the Real ROI Killer
30% of GenAI projects will be abandoned by 2026. Discover why your data—not the AI—is the real reason for failure and how to fix it with our 5-step audit.
By Josh Woodruff

Zero Trust for AI Agents: Why Your Identity Model is Obsolete
You solved Zero Trust for humans. Now it's time for AI agents. Learn the 5 principles to extend your security framework to the autonomous future.
By Josh Woodruff

84% of Companies Would Fail an AI Agent Audit. Would Yours?
A new CSA survey found 84% of organizations would fail a compliance audit on AI agent behavior. Here's why, and what to do about it this week.
By Josh Woodruff

Why Do 95% of Enterprise AI Projects Fail? (And What the 5% Do Differently)
Goldman Sachs projects $200 billion in AI investment. MIT research shows 95% of AI pilots fail completely. Here's what separates the companies that succeed.
By Josh Woodruff

Your Team Already Has AI Agents (It’s Time To Find Them)
The average company has 5-15 'shadow AI' agents running right now. Your grammar checker? AI agent. Meeting scheduler? AI agent. Time to find them all.
By Josh Woodruff

Take This Quiz Before You Spend a Dollar on Agentic AI
Before you spend money on AI, take this 10-minute readiness assessment. You’ll be happy you did.
By Josh Woodruff

Haven't Touched AI Agents Yet? Let's Get You Started.
Haven't started with AI agents yet? Perfect. You get to skip everyone else's mistakes and build security-first from day one. Here's your 30-day plan.
By Josh Woodruff

Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust
In our rush to adopt AI, we forgot everything we every learned about security. Learn how all AI agents are vulnerable and need Zero Trust security.
By Josh Woodruff

Your AI Agents Are Like Employees Who Never Talk. Here's the Fix.
It's critical to have AI agents that actually work together. The question isn't whether to adopt MCP but whether you'll do it quickly. -
By Josh Woodruff

Your AI Strategy Failed. Your Workforce Just Doubled.
Here's why most CEOs are optimizing for 5% productivity gains while their competitors are building entirely new operating models.
By Josh Woodruff

I Keep Hearing 'We're Not Ready for AI Agents Yet
The companies crushing it with AI agents weren't 'ready' either. They just started. Here's why waiting for perfect is costing you a lot.
By Josh Woodruff

Why Getting Interrogated About Zero Trust + AI Agents Was A Good Thing
My wife made me explain Zero Trust like she's five. That interrogation shaped every chapter of our book on securing AI agents. Simple, actionable, no buzzwords.
By Josh Woodruff

The book is done–pre-order ‘Agentic AI + Zero Trust’ today!
Agentic AI + Zero Trust" is out. Learn how why AI agents can take your business to the next level and why you need a security-first mindset.
By Josh Woodruff