verifiedagents.ai
Blog

Notes on governing AI agents.

What we're learning from assessments and from teams putting agents into production.

Why Do AI Agents Pass Every Access Check and Still Get It Wrong? (hero)
October 4, 20269 min readAI Agentsmassivescale.ai

Why Do AI Agents Pass Every Access Check and Still Get It Wrong?

An AI agent can pass every access check and still act on something false. In Josh's Lab, a made-up source ended up in two documents. Check what agents believe.

By Josh Woodruff

Segmentation for AI agents hero image
September 24, 20264 min readZero Trust

What does segmentation mean for AI agents?

Segmentation limits which systems and agents an AI agent can reach, so one bad decision stays small. Contain the blast radius first.

By Josh Woodruff

Your AI Policy Is Live. Your Enforcement Isn't.
September 9, 20268 min readAI Agentsmassivescale.ai

Your AI Policy Is Live. Your Enforcement Isn't.

Most AI governance programs have a committee, a policy, and published requirements. What they lack is anything that stops an app from ignoring all three.

By Josh Woodruff

Hero: Why Authorized AI Agent Actions Still Add Up to an Attack
September 5, 20267 min readCybersecuritymassivescale.ai

Why Authorized AI Agent Actions Still Add Up to an Attack

Agent risk is a chain of approved actions nobody scoped together. Every step passes its check. The sequence is the attack.

By Josh Woodruff

Hero: How Do You Govern AI Agents That Disappear in Minutes?
September 2, 20269 min readAI Agentsmassivescale.ai

How Do You Govern AI Agents That Disappear in Minutes?

You can't govern AI agent copies. They vanish in minutes. Govern the blueprint they're stamped from, and put its tool scope in Git.

By Josh Woodruff

Hero: What Can Your AI Agent Access Right Now?
August 26, 20267 min readAI Agentsmassivescale.ai

What Can Your AI Agent Access Right Now?

Ask what your AI agent can access, not what it can do. Access sets your blast radius. If nobody can answer in ten minutes, that's the finding.

By Josh Woodruff

Hero: AI Agent Identity Isn't Enough: How to Run a Belief Audit
August 20, 20269 min readAI Agentsmassivescale.ai

AI Agent Identity Isn't Enough: How to Run a Belief Audit

Identity proves who your AI agent is. It can't prove what your agent believes is true. That's the audit almost nobody has run.

By Josh Woodruff

Hero: Your AI Security Controls Get Bypassed When They Block Real Work
August 9, 20266 min readAI Agentsmassivescale.ai

Your AI Security Controls Get Bypassed When They Block Real Work

AI security controls that block real work get bypassed, even by your best people. The fix is an approved path that lets safe work flow and stops the unknown.

By Josh Woodruff

Hero: The Two-Question Test for AI Agents: Can You Shut It Off, and Can You Undo It?
July 26, 20266 min readAI Agentsmassivescale.ai

The Two-Question Test for AI Agents: Can You Shut It Off, and Can You Undo It?

Before any AI agent goes live, ask two questions: can you shut it off instantly, and can you undo what it did? If either answer is no, it isn't ready.

By Josh Woodruff

Hero: Can You Undo What Your AI Agents Did Last Night?
July 10, 20267 min readAI Agentsmassivescale.ai

Can You Undo What Your AI Agents Did Last Night?

The best AI builders stopped trying to trust their agents. The new audit question is whether you can undo what your agents did last night.

By Josh Woodruff

Hero: How Do You Give an AI Agent the Right Amount of Access?
July 4, 20266 min readAI Agentsmassivescale.ai

How Do You Give an AI Agent the Right Amount of Access?

A bank's AI agent taught itself to reverse fees and gave away $1.2 million, all with access it was never meant to use. Right-sizing agent access prevents this.

By Josh Woodruff

Hero: What Is Zero Trust for AI Agents, in Plain English?
July 4, 20266 min readAI Agentsmassivescale.ai

What Is Zero Trust for AI Agents, in Plain English?

Zero Trust is one idea: never trust, always verify. For AI agents, being inside your network earns no free pass. Every action must still prove itself.

By Josh Woodruff

Hero: How Do You Respond When an AI Agent Goes Rogue?
July 3, 20266 min readAI Agentsmassivescale.ai

How Do You Respond When an AI Agent Goes Rogue?

When an AI agent goes wrong you have minutes, not months. Traditional breach response averages 258 days, but agent decisions compound every second.

By Josh Woodruff

Hero: Why Are AI Agents Already Outnumbering Your Employees?
July 3, 20265 min readAI Agentsmassivescale.ai

Why Are AI Agents Already Outnumbering Your Employees?

Automated accounts already outnumber people 10 to 1, and up to 92 to 1 in some companies. By 2030, humans could be the minority in your systems.

By Josh Woodruff

Hero: What Should Your First 90 Days of Agentic AI Look Like?
July 3, 20266 min readAI Agentsmassivescale.ai

What Should Your First 90 Days of Agentic AI Look Like?

Deploy your first AI agent in 90 days without a disaster: find your hidden AI, pick one contained use case, and build boundaries in from day one.

By Josh Woodruff

Hero: What Is the Agentic Trust Framework for Securing AI Agents?
July 3, 20266 min readAI Agentsmassivescale.ai

What Is the Agentic Trust Framework for Securing AI Agents?

The Agentic Trust Framework turns Zero Trust into five working controls for AI agents: identity, behavior, data, segmentation, and incident response.

By Josh Woodruff

Hero: An AI Agent Opened 12 Accounts Over the Weekend. Nobody Approved One.
June 20, 20265 min readAI Agentsmassivescale.ai

An AI Agent Opened 12 Accounts Over the Weekend. Nobody Approved One.

An AI agent opened 12 accounts over a weekend with no approval. Here's why it's not a hack, and how to find the ungoverned agents in your business.

By Josh Woodruff

Hero: Governing AI Agents: A Three-Layer Architecture
June 12, 202610 min readAI Agentsmassivescale.ai

Governing AI Agents: A Three-Layer Architecture

The first formal conformance assessment against the Agentic Trust Framework, and the three-layer architecture behind it: framework, runtime, protocols.

By Josh Woodruff

Hero: How to Tell What Level Your AI Agents Are Actually Running At
June 10, 202610 min readPrivilege Changes for AI Agentsmassivescale.ai

How to Tell What Level Your AI Agents Are Actually Running At

AI agents run at four levels: intern, junior, senior, principal. Most get installed too high on day one. Here's how to find each one's real level.

By Josh Woodruff

Hero: How Should You Govern a New AI Agent? Start It as an Intern.
June 3, 20269 min readCybersecuritymassivescale.ai

How Should You Govern a New AI Agent? Start It as an Intern.

Govern a new AI agent like a new hire. Give it an identity it can't fake, log every move, and grant access in stages it has to earn. Start it as an intern.

By Josh Woodruff

Hero: Are AI agents the same as non-human identities (NHIs)?
June 1, 20265 min readAI Agentsmassivescale.ai

Are AI agents the same as non-human identities (NHIs)?

AI agents are NHIs, technically. Silverfort and Strata say treating them that way is breaking security. Why agents need controls NHIs don't.

By Josh Woodruff

Hero: What Auditors Actually Want To Know About AI Agents
May 27, 20267 min readAI Agentsmassivescale.ai

What Auditors Actually Want To Know About AI Agents

One security team found 600 AI agents it never approved. The auditor's call is coming. Here are the 5 questions every CISO needs to answer.

By Josh Woodruff

Hero: What is the AI agent identity problem?
May 17, 20268 min readCybersecuritymassivescale.ai

What is the AI agent identity problem?

Only 18% of security leaders trust their identity systems for AI agents (Strata, May 2026). The five-element blueprint that fixes pilot purgatory.

By Josh Woodruff

Hero: What Will Your Auditor Ask About AI Agents Before the August 2026 EU Deadline?
May 10, 20269 min readAI Agentsmassivescale.ai

What Will Your Auditor Ask About AI Agents Before the August 2026 EU Deadline?

Meta's March 18, 2026 AI agent incident exposed the audit gap. California closed the AI defense in January. EU enforcement begins August 2. What to do now.

By Josh Woodruff

Hero: What Questions Should You Ask Before Deploying an AI Agent?
April 10, 202610 min readCybersecuritymassivescale.ai

What Questions Should You Ask Before Deploying an AI Agent?

Four questions, thirty minutes, written down. That's the minimum governance before any AI agent touches production.

By Josh Woodruff

Hero: What Is Shadow AI and Why Did RSAC 2026 Call It the Top Security Threat?
March 30, 20268 min readCybersecuritymassivescale.ai

What Is Shadow AI and Why Did RSAC 2026 Call It the Top Security Threat?

RSAC 2026 gave its top award to a tool that finds AI agents you don't know you have. Here's what that means for your organization.

By Josh Woodruff

Hero: Why Zero Trust Needs More for AI Agents (and How to Fix It)
March 23, 20267 min readCybersecuritymassivescale.ai

Why Zero Trust Needs More for AI Agents (and How to Fix It)

Zero Trust was designed for humans logging into systems. AI agents don't log in...they act, chain decisions, and call systems continuously. Here's what to do.

By Josh Woodruff

Hero: What Is Trusted Agents? AI Agent Security for Business Leaders
March 8, 20265 min readZero Trustmassivescale.ai

What Is Trusted Agents? AI Agent Security for Business Leaders

Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Real incidents, action plans, and Zero Trust gap analysis every Tuesday.

By Josh Woodruff

Hero: Zero Trust for AI Agents: Why Your Identity Model is Obsolete
February 14, 20264 min readAI Agentsmassivescale.ai

Zero Trust for AI Agents: Why Your Identity Model is Obsolete

You solved Zero Trust for humans. Now it's time for AI agents. Learn the 5 principles to extend your security framework to the autonomous future.

By Josh Woodruff

Hero: Why Do 95% of Enterprise AI Projects Fail? (And What the 5% Do Differently)
February 14, 20268 min readAI Agentsmassivescale.ai

Why Do 95% of Enterprise AI Projects Fail? (And What the 5% Do Differently)

Goldman Sachs projects $200 billion in AI investment. MIT research shows 95% of AI pilots fail completely. Here's what separates the companies that succeed.

By Josh Woodruff