Notes on governing AI agents.
What we're learning from assessments and from teams putting agents into production.

How to Evaluate an AI Security Vendor With No Peer References
No peers have run most AI security products yet, so ask vendors for evidence: seven question categories, a proof of value, and a short contract.
By Josh Woodruff

Which Rules Apply to AI Agents in a Regulated Business?
Almost no rule names AI agents yet. That silence isn't permission. Map every agent onto a control you already report on, and keep the proof.
By Josh Woodruff

Before You Buy an AI Security Tool, Check What You Already Own
Most teams shopping for an AI security tool are paying for capabilities they haven't turned on. Check the stack you own before you add a line item.
By Josh Woodruff

What Does It Mean to Approve an AI Agent?
Security gets named as the AI agent approver without anyone defining what approval means. Five written questions beat a committee that takes months.
By Josh Woodruff

Why Single-Vendor AI Security Advice Keeps Aging Badly
Ten security teams since January 2026 described a multi-vendor AI estate. Almost none of them chose it. Advice written for one stack doesn't survive that.
By Josh Woodruff

Security Teams Now Ask About MCP Before They Deploy It
Sixteen security teams asked about the Model Context Protocol in seven months. The first wanted a definition. The latest already had servers running.
By Josh Woodruff

How Do You Respond When an AI Agent Goes Rogue?
When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.
By Josh Woodruff

Is AI Agent Regulation Already Here, and What Does It Cost?
The EU AI Act can fine violators up to 35 million euros or 7% of global revenue, whichever is higher. AI agent regulation isn't coming. It's already here.
By Josh Woodruff

Why Are AI Agents Already Outnumbering Your Employees?
Automated accounts already outnumber people 10 to 1, and up to 92 to 1 in some companies. By 2030, humans could be the minority in your systems.
By Josh Woodruff

What Should Your First 90 Days of Agentic AI Look Like?
Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.
By Josh Woodruff

What Is the Agentic Trust Framework for Securing AI Agents?
The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.
By Josh Woodruff

How to Tell What Level Your AI Agents Are Actually Running At
AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.
By Josh Woodruff

Why Zero Trust Needs More for AI Agents (and How to Fix It)
Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.
By Josh Woodruff

What Is Trusted Agents? AI Agent Security for Business Leaders
Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.
By Josh Woodruff

What are CISOs saying about AI agents in 2026?
Ditch the vendor hype. Here is what CEOs and CISOs are actually saying about AI agent deployment, security risks, and the 95% failure rate in 2026.
By Josh Woodruff

What Is Shadow AI and How Do You Find It Before It Finds You?
The biggest AI security threat isn't a nation-state hacker. It's the employee who uploaded files to make their job easier. See how to find and govern shadow AI.
By Josh Woodruff

AI Agents Are Failing: Why Your Data is the Real ROI Killer
30% of GenAI projects will be abandoned by 2026. Discover why your data—not the AI—is the real reason for failure and how to fix it with our 5-step audit.
By Josh Woodruff

Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust
In our rush to adopt AI, we forgot everything we every learned about security. Learn how all AI agents are vulnerable and need Zero Trust security.
By Josh Woodruff

Your AI Agents Are Like Employees Who Never Talk. Here's the Fix.
It's critical to have AI agents that actually work together. The question isn't whether to adopt MCP but whether you'll do it quickly. -
By Josh Woodruff

Why Self-Publishing Might Be The Way to Go For AI Books
Why wait 18 months for traditional publishing when companies need AI security help today? We self-published to get this in your hands while it still matters.
By Josh Woodruff