Security & AI Governance
Agentic AI changes the threat model: the caller is no longer a person, and the guardrails can't live in a PDF. Here's where I work through API security when the caller is an agent, zero trust in practice, and governance as an operating model — controls that trigger, gates where decisions are irreversible, and audit trails that survive contact with a model.
20 items, 2023 to 2026.
Frameworks
- Agentic API Security The caller is no longer a person. The identity, task-scoping, reversibility gates, and observability an API estate needs once autonomous agents hold the credentials.
- Agent Authority An AI agent needs more than an API token. The framework for assigning a sponsor, mandate, permissions, autonomy and evidence before it can act.
- FinOps for AI AI spend scales with autonomy, not traffic. The circuit breakers, tier routing, caching, and chargeback discipline that keep LLM and agent spend answerable to somebody.
Talks
Writing
- Platform Product Metrics: How to Tell Whether Your Internal Platform Is Helping A measurement framework for internal platforms: adoption, golden paths, delivery friction, service health, developer trust and cost to serve.
- Agentic AI Control Planes: The Guardrails That Make Autonomy Operable A practical architecture for agent guardrails: task boundaries, permissions, approvals, budgets, evaluation, observability and incident response.
- FinOps for AI Metrics: The Scorecard That Turns Token Spend into Decisions The practical AI FinOps metrics that connect token, GPU, retrieval and agent cost to accountable operational and business decisions.
- MCP Security and Governance: The Control Map Enterprises Actually Need A practical control map for deploying Model Context Protocol safely: identity, permissions, supply chain, approval gates, logging and operational ownership.
- AI Governance Operating Models: Who Decides, Who Enforces, Who Gets Paged AI governance fails when it is a policy without decision rights. A practical operating model for lifecycle gates, accountable roles, enforcement and time-bound exceptions.
- API Security When the Caller Is an AI Agent Authentication was the part the industry solved. Agents break everything downstream of it — what the caller intends, how far its credential reaches, and how much it can destroy before anyone notices.
- AI Governance Is Enforcement, Not Intent A principle that cannot point to the moment it says no is a preference. What separates governance from a PDF: controls in the delivery path, a data layer you can actually see into, and gates priced by reversibility.
In the press
- The State of AI in Media 2026
- John Bradshaw cited in AS Watson technology partnership announcement
- GenAI data center infrastructure reshapes business processes
- How to Design Cloud Infrastructure That Survives Major Outages
- Navigating the Multi-Cloud Maze: Balancing Security, Agility and Vendor Freedom