Writing
What I want you to read or look at right now. Below: everything pulled from the feeds, newest first.
01 Featured
- Agent identity isn't solved Every enterprise conversation lands on the same line: agent identity isn't solved. True, but not nothing to hold onto. Four stacked layers: tamper-proof token, proof of which workload is running, a delegation chain that keeps the human as the subject, onboarding to a service it's never met. Climb all four and you've proven who the agent is. Not that what it did was okay.
- DirePhish AI clones of your team running 100 simulated breaches under regulatory time-bounds. A distribution of how you actually behave when the binder goes out the window.
- securing-ralph-loop Security checks bolted into the Ralph coding-agent loop. Scan before commit, fix iteratively, escalate when stuck. The AI-for-security thesis, as code.
◇◇◇
02 Recent
- NPC Nation: what Australia's new AI framework actually covers
- Claude Tag: an agent that acts as itself, not on your behalf
- Kill the God Agent: how we think about agent security
- Agent identity isn't solved. Here's the model I use anyway.
- First credible LLM explainability mechanism in 3 years
- Alignment is a Security Problem, Not an Ethics Problem
- Claude 4.7: Five Layers Blocking Cyber Attacks Before and After
- BodySnatcher and the Missing Identity Layer
- Three Regulatory Philosophies, One Global AI Market
- Identity Crisis in AI Agents: Why Traditional IAM Is Breaking Down
- The $127M Algorithm: When Smart AI Goes Wrong
- Shadow Coding: what, so what, now what?
- Claude 4 Risk Assessment - For enterprise deployment
- Safe AI by Design: Insights from a System Prompt
- How to use safety benchmarks to assess technical and business risk
Source feeds: raxIT Labs, Substack, and recent activity on LinkedIn.