Notes on governing AI agents.
What we're learning from assessments and from teams putting agents into production.

Why Does the AI Mandate Arrive Before Identity Is Ready?
Leaders set AI dates before identity work is done, as 11 client calls showed in 2026. Start agents small with five jobs: record, owner, exit, scope, log.
By Josh Woodruff

How to Evaluate an AI Security Vendor With No Peer References
No peers have run most AI security products yet, so ask vendors for evidence: seven question categories, a proof of value, and a short contract.
By Josh Woodruff

What Is the Confused Deputy Problem in AI Agent Gateways?
A gateway that reuses its own login for every downstream call hides which AI agent actually made the call. Token exchange fixes it with a narrow token.
By Josh Woodruff

How do I stop an AI agent before it acts?
You stop an AI agent before it acts with a gate outside the model. Block high-impact actions until policy and a human say yes.
By Josh Woodruff

Why Security Teams Are Building Their Own AI Reference Architecture
No complete AI security reference architecture exists to buy. So the strongest security teams build their own and hand it to vendors as a coverage grid.
By Josh Woodruff

Before You Buy an AI Security Tool, Check What You Already Own
Most teams shopping for an AI security tool are paying for capabilities they haven't turned on. Check the stack you own before you add a line item.
By Josh Woodruff

Why Your Security Tools Can't See What Your AI Agents Do
Your CASB, EDR, and DLP watch people and devices. AI agents call tools through MCP, which looks like normal web traffic, so their calls slip past unseen.
By Josh Woodruff

Where Does the Human Sit in an Agentic SOC?
"Human in the loop" means little when an agent acts in milliseconds. What works instead is an authority ladder that sorts actions by what they cost to undo.
By Josh Woodruff

Where Do You Stop an AI-Suggested Software Install?
Put the control where the command runs, not in the AI tool. Tenant settings stop at the copy button. Enforce on the endpoint and at the network exit.
By Josh Woodruff

Your AI Policy Is Live. Your Enforcement Isn't.
Most AI governance programs have a committee, a policy, and published requirements. What they lack is anything that stops an app from ignoring all three.
By Josh Woodruff

Contain First, Count Second: AI Agent Blast Radius
Contain the damage before you finish the inventory. Blast-radius controls work against the AI agents you haven't found yet, and discovery never finishes.
By Josh Woodruff

Who Approves the Code Your AI Agent Just Wrote?
Coding agents came up on eleven security calls in seven months. Only two of those calls were about coding agents on purpose. The rest were discoveries.
By Josh Woodruff

Why Single-Vendor AI Security Advice Keeps Aging Badly
Ten security teams since January 2026 described a multi-vendor AI estate. Almost none of them chose it. Advice written for one stack doesn't survive that.
By Josh Woodruff

Security Teams Now Ask About MCP Before They Deploy It
Sixteen security teams asked about the Model Context Protocol in seven months. The first wanted a definition. The latest already had servers running.
By Josh Woodruff

Why AI ROI Metrics Miss the Cost of Ungoverned Agents
Popular AI ROI frameworks measure revenue, cost, speed, and adoption. None of them measure risk. That missing column is what breaks the business case.
By Josh Woodruff

Why Authorized AI Agent Actions Still Add Up to an Attack
Agent risk is a chain of approved actions nobody scoped together. Every step passes its check. The sequence is the attack.
By Josh Woodruff

How Do You Govern AI Agents That Disappear in Minutes?
You can't govern AI agent copies. They vanish in minutes. Govern the blueprint they're stamped from, and put its tool scope in Git.
By Josh Woodruff

What Can Your AI Agent Access Right Now?
Ask what your AI agent can access, not what it can do. Access sets your blast radius. If nobody can answer in ten minutes, that's the finding.
By Josh Woodruff

AI Agent Identity Isn't Enough: How to Run a Belief Audit
Identity proves who your AI agent is. It can't prove what your agent believes is true. That's the audit almost nobody has run.
By Josh Woodruff

Your AI Security Controls Get Bypassed When They Block Real Work
AI security controls that block real work get bypassed, even by your best people. The fix is an approved path that lets safe work flow and stops the unknown.
By Josh Woodruff

The Two-Question Test for AI Agents: Can You Shut It Off, and Can You Undo It?
Before any AI agent goes live, ask two questions: can you shut it off instantly, and can you undo what it did? If either answer is no, it isn't ready.
By Josh Woodruff

Can You Undo What Your AI Agents Did Last Night?
The best AI builders stopped trying to trust their agents. The new audit question is whether you can undo what your agents did last night.
By Josh Woodruff

How Do You Give an AI Agent the Right Amount of Access?
A bank's AI agent taught itself to reverse fees and gave away $1.2 million, all with access it was never meant to use. Right-sizing agent access prevents this.
By Josh Woodruff

What Is Data Poisoning, and How Do You Keep It Out of Your AI Agents?
Data poisoning corrupts an AI agent from the inside. The dashboards stay green while the decisions go wrong. One firm lost $100K before anyone noticed.
By Josh Woodruff

What Is a Kill Switch for AI Agents, and How Do You Build One?
When an agent goes wrong, seconds count. A kill switch stops the damage. One team found their backup switch had a 45-second delay, an eternity at machine speed.
By Josh Woodruff

What Is Prompt Injection, and How Do You Protect AI Agents From It?
Prompt injection is social engineering for AI. Someone slips your agent hidden instructions and it obeys. One bot got talked into selling a car for $1.
By Josh Woodruff

How Do You Monitor an AI Agent's Behavior?
You can't tell a compromised agent from a busy one unless you know its normal. One pricing agent crept its margins up for six weeks before anyone caught it.
By Josh Woodruff

How Do You Respond When an AI Agent Goes Rogue?
When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.
By Josh Woodruff

Is AI Agent Regulation Already Here, and What Does It Cost?
The EU AI Act can fine violators up to 35 million euros or 7% of global revenue, whichever is higher. AI agent regulation isn't coming. It's already here.
By Josh Woodruff

Why Are AI Agents Already Outnumbering Your Employees?
Automated accounts already outnumber people 10 to 1, and up to 92 to 1 in some companies. By 2030, humans could be the minority in your systems.
By Josh Woodruff

What Should Your First 90 Days of Agentic AI Look Like?
Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.
By Josh Woodruff

What Is the Agentic Trust Framework for Securing AI Agents?
The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.
By Josh Woodruff

Why Enterprise AI Projects Fail: Studies Disagree on Numbers, Not the Reason
Two studies on enterprise AI reached opposite conclusions. Both are right. The real reason projects fail is the gap between the demo and the rollout.
By Josh Woodruff

Governing AI Agents: A Three-Layer Architecture
The first formal conformance assessment against the Agentic Trust Framework, and the three-layer architecture behind it: framework, runtime, protocols.
By Josh Woodruff

How to Tell What Level Your AI Agents Are Actually Running At
AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.
By Josh Woodruff

How Should You Govern a New AI Agent? Start It as an Intern.
Govern a new AI agent like a new hire. Give it an identity it can't fake, log every move, and grant access in stages it has to earn. Start it as an intern.
By Josh Woodruff

What is agent washing? (And how to spot fake agentic AI vendors)
Gartner says only ~130 of thousands of agentic AI vendors are real. The rest are rebadged chatbots and RPA. How to spot the fakes before your audit does.
By Josh Woodruff

Are AI agents the same as non-human identities (NHIs)?
AI agents are NHIs, technically. Silverfort and Strata say treating them that way is breaking security. Why agents need controls NHIs don't.
By Josh Woodruff

What Auditors Actually Want To Know About AI Agents
One security team found 600 AI agents it never approved. The auditor's call is coming. Here are the 5 questions every CISO needs to answer.
By Josh Woodruff

What is the AI agent identity problem?
Only 18% of security leaders trust their identity systems for AI agents (Strata, May 2026). The five-element blueprint that fixes pilot purgatory.
By Josh Woodruff

What Will Your Auditor Ask About AI Agents Before the August 2026 EU Deadline?
Meta's March 18, 2026 AI agent incident exposed the audit gap. California closed the AI defense in January. EU enforcement begins August 2. What to do now.
By Josh Woodruff

What is AI agent security? (A business leader's guide)
AI agents act on your systems and your money. The vocabulary you need to govern them, in plain language for business leaders.
By Josh Woodruff

I Wrote the Book on AI Agent Security. My Agents Still Burned Me.
Why AI agent governance can't ride on Zero Trust, NIST, ISO, or OWASP alone. The Agentic Trust Framework moves to nonprofit CSAI.
By Josh Woodruff

The 50-Term AI Agent Governance Glossary Every Security Leader Needs
Most agent governance conversations stall on vocabulary. The new 50-term plain-language glossary fixes that. Free, dated, citable.
By Josh Woodruff

How Many AI Agents Are Already Running in Your Company?
Most CISOs can't say how many AI agents are running on their data this week. Here's the inventory that fixes the shadow agent problem.
By Josh Woodruff

How Do You Detect a Compromised AI Agent?
Only 5% of organizations feel confident they could catch a compromised AI agent. Why traditional EDR fails, and the three signals that actually work.
By Josh Woodruff

How Do You Govern Non-Human Identities When Agents Outnumber Humans 10 to 1?
Non-human identities outnumber humans 10 to 50 times in cloud-native enterprises. 84% of organizations lack effective NHI governance. Here's the fix.
By Josh Woodruff

Where does AI governance actually come from?
When every AI agent in your company has one person's name on it, governance changes. Personal stakes do what compliance memos can't.
By Josh Woodruff

What Privilege Escalation Paths Do AI Agents Create?
48% of security pros rank agentic AI as the most dangerous attack vector. Five privilege escalation paths your traditional controls don't catch.
By Josh Woodruff

What's missing from most AI business cases?
Your AI ROI spreadsheet is missing the risk column. Here's what Security can fill in, and what one chatbot ruling cost a company.
By Josh Woodruff

How Do You Defend AI Agents Against Prompt Injection?
Three coding agents leaked secrets through one prompt injection in 2026. Standard input validation didn't catch any. Here's the layered defense that does.
By Josh Woodruff

What Questions Should You Ask Before Deploying an AI Agent?
Four questions, thirty minutes, written down. That's the minimum governance before any AI agent touches production.
By Josh Woodruff

Your AI Agent Can't Be Fired. And Right Now, It Can't Be Stopped.
What CISOs whisper in RSAC hallways: "I can't tell my CEO who owns my AI agents, what they touch, or how to shut one down."
By Josh Woodruff

What Is Shadow AI and Why Did RSAC 2026 Call It the Top Security Threat?
RSAC 2026 gave its top award to a tool that finds AI agents you don't know you have. Here's what that means for your organization.
By Josh Woodruff

The Biggest Award at RSAC 2026 Went to a Flashlight
RSAC 2026's top innovation award went to a tool that finds AI agents you don't know you have. That tells you everything about your AI risk.
By Josh Woodruff

Who owns the AI agents in your company?
RSAC discovery scan found 600 ungoverned AI agents at one Fortune 500 in 24 hours. The operating model that lets your CISO say yes safely.
By Josh Woodruff

Why Zero Trust Needs More for AI Agents (and How to Fix It)
Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.
By Josh Woodruff

What Is Trusted Agents? AI Agent Security for Business Leaders
Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.
By Josh Woodruff

That 'Temporary' Permission You Gave Your AI Agent Is Still There
That 'temporary' access you gave your AI 8 months ago? Time to audit those permissions!
By Josh Woodruff

Your Team Already Has AI Agents (It’s Time To Find Them)
The average company has 5-15 'shadow AI' agents running right now. Your grammar checker? AI agent. Meeting scheduler? AI agent. Time to find them all.
By Josh Woodruff