Notes on governing AI agents.
What we're learning from assessments and from teams putting agents into production.

What Should a CISO Tell the Board About AI Agents?
The board wants one answer about AI agents: when one goes wrong, can you show you had control. Four things prove it: see it, stop it, trace it, prove it.
By Josh Woodruff

Why Your Security Team Should Govern Its Own AI Agents First
Your security team is likely the first team running AI agents in production. Seven client calls in summer 2026 showed the same shape. Govern those agents first.
By Josh Woodruff

Why Does Your AI Review Board Only See Finished Work?
AI review boards fire on intake, and AI work never arrives through intake. Move the trigger earlier and register intent before any code exists.
By Josh Woodruff

Who Owns AI Governance When Four Teams Each Own a Piece?
AI governance stalls when four teams each hold a defensible piece of it. A federated model fixes that: one center owns the standard, the units execute.
By Josh Woodruff

How Does a Small Security Team Govern AI?
Extend what you already run instead of building a separate AI security program. Treat AI as a change to identity, data, software delivery, and network access.
By Josh Woodruff

Every AI Agent Needs One Accountable Human
Put one named person on every AI agent, or the program stalls. An agent can't be held accountable for anything. The person who turned it on can.
By Josh Woodruff

AI Agent Sprawl: Why You Can't Control the AI Agents You Never Counted
AI agent sprawl is when a company runs more AI agents than it can count or shut off. Most firms can't say how many they run. The fix starts with one list.
By Josh Woodruff

What Is Zero Trust for AI Agents, in Plain English?
Zero Trust is one idea: never trust, always verify. For AI agents, being inside your network earns no free pass. Every action must still prove itself.
By Josh Woodruff

What Is an AI Agent, and How Is It Different From a Chatbot?
A chatbot gives you an answer. An AI agent takes an action. That one difference changes everything about how you manage, trust, and secure it.
By Josh Woodruff

How Do You Respond When an AI Agent Goes Rogue?
When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.
By Josh Woodruff

Is AI Agent Regulation Already Here, and What Does It Cost?
The EU AI Act can fine violators up to 35 million euros or 7% of global revenue, whichever is higher. AI agent regulation isn't coming. It's already here.
By Josh Woodruff

Why Are AI Agents Already Outnumbering Your Employees?
Automated accounts already outnumber people 10 to 1, and up to 92 to 1 in some companies. By 2030, humans could be the minority in your systems.
By Josh Woodruff

What Should Your First 90 Days of Agentic AI Look Like?
Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.
By Josh Woodruff

What Is the Agentic Trust Framework for Securing AI Agents?
The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.
By Josh Woodruff

How to Tell What Level Your AI Agents Are Actually Running At
AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.
By Josh Woodruff

How Should You Govern a New AI Agent? Start It as an Intern.
Govern a new AI agent like a new hire. Give it an identity it can't fake, log every move, and grant access in stages it has to earn. Start it as an intern.
By Josh Woodruff

Why Zero Trust Needs More for AI Agents (and How to Fix It)
Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.
By Josh Woodruff

What Is Trusted Agents? AI Agent Security for Business Leaders
Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.
By Josh Woodruff

What are CISOs saying about AI agents in 2026?
Ditch the vendor hype. Here is what CEOs and CISOs are actually saying about AI agent deployment, security risks, and the 95% failure rate in 2026.
By Josh Woodruff

What Is Shadow AI and How Do You Find It Before It Finds You?
The biggest AI security threat isn't a nation-state hacker. It's the employee who uploaded files to make their job easier. See how to find and govern shadow AI.
By Josh Woodruff

AI Agents Are Failing: Why Your Data is the Real ROI Killer
30% of GenAI projects will be abandoned by 2026. Discover why your data—not the AI—is the real reason for failure and how to fix it with our 5-step audit.
By Josh Woodruff

Zero Trust for AI Agents: Why Your Identity Model is Obsolete
You solved Zero Trust for humans. Now it's time for AI agents. Learn the 5 principles to extend your security framework to the autonomous future.
By Josh Woodruff

My book is here! Check out Agentic AI + Zero Trust.
It's here! My book is published! The book I spent most of this year writing, "Agentic AI + Zero Trust: A Guide for Business Leaders", is available.
By Josh Woodruff

Why Microsoft 365 Copilot's Hacking Shows the Need for Zero Trust
In our rush to adopt AI, we forgot everything we every learned about security. Learn how all AI agents are vulnerable and need Zero Trust security.
By Josh Woodruff

Your AI Agents Are Like Employees Who Never Talk. Here's the Fix.
It's critical to have AI agents that actually work together. The question isn't whether to adopt MCP but whether you'll do it quickly. -
By Josh Woodruff

John Kindervag Is Right: We're in the Cooing Stage of AI
John Kindervag says we're at the 'cooing stage' of AI. His foreword for our book explains why Zero Trust is the foundation we need while AI grows up.
By Josh Woodruff