← Back

Blog

Essays on where AI meets identity security. The canonical home for the thinking I syndicate to LinkedIn.

Your AI assistant reads documents your users never could

Your AI assistant reads documents your users never could

66% of enterprises have caught AI over-accessing sensitive data. The root cause is architectural: RAG pipelines strip identity at ingestion, so the vector database cannot enforce a permission it never knew existed. Here is where the ACLs die, and how to put them back.

The MFA bypass hiding in your Google Workspace

The MFA bypass hiding in your Google Workspace

App-specific passwords walk straight past multi-factor authentication and never show up in your audit logs. APT29 weaponized exactly that. Here is how to detect them across every user in your domain.

The AI control plane moves from protocol to principal
The Agentic Identity Control Plane · Part 2

The AI control plane moves from protocol to principal

As MCP goes stateless and base models absorb native capability, the control point for AI moves from the protocol to the principal: the identity, its credentials, and the purpose of its actions.

Your AI agents are privileged identities you forgot to manage
The Agentic Identity Control Plane · Part 1

Your AI agents are privileged identities you forgot to manage

An AI agent is a non-human identity with the lifecycle of a service account. Run every one through the same five gates: provisioning, least privilege, secret rotation, audit, deprovisioning.

You can't secure the AI you never inventoried
Code-Level AI Governance · Part 1

You can't secure the AI you never inventoried

SBOMs became mandatory after Log4Shell proved you cannot secure what you have not inventoried. The same reckoning is hitting AI. Here is what an AI Bill of Materials covers, and why I built a scanner that produces one.

Your SOC 2 dashboard is green and still cannot answer the AI question
Code-Level AI Governance · Part 2

Your SOC 2 dashboard is green and still cannot answer the AI question

Vanta and Drata are excellent at infrastructure compliance. They were never built to scan your code for AI providers, and that is exactly the question enterprise buyers are now asking.

The EU AI Act applies to you through your buyers, not Brussels
Code-Level AI Governance · Part 3

The EU AI Act applies to you through your buyers, not Brussels

US founders keep saying the EU AI Act does not apply to them. It does, through enterprise procurement. I have watched this exact ripple play out three times in thirty years.