<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Mike Carroll</title><description>Essays on where AI meets identity security: non-human identity, the agentic control plane, and code-level AI governance.</description><link>https://carrolldot.com/</link><language>en-us</language><item><title>The MFA bypass hiding in your Google Workspace</title><link>https://carrolldot.com/blog/asp-mfa-bypass-detection/</link><guid isPermaLink="true">https://carrolldot.com/blog/asp-mfa-bypass-detection/</guid><description>App-specific passwords walk straight past multi-factor authentication and never show up in your audit logs. APT29 weaponized exactly that. Here is how to detect them across every user in your domain.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Identity Security</category><category>ITDR</category><category>MFA</category><category>Incident Response</category><category>Google Workspace</category></item><item><title>The AI control plane moves from protocol to principal</title><link>https://carrolldot.com/blog/control-plane-protocol-to-principal/</link><guid isPermaLink="true">https://carrolldot.com/blog/control-plane-protocol-to-principal/</guid><description>As MCP goes stateless and base models absorb native capability, the control point for AI moves from the protocol to the principal: the identity, its credentials, and the purpose of its actions.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>AI x Identity</category><category>MCP</category><category>NHI</category><category>IGA</category><category>AI agents</category></item><item><title>Your AI agents are privileged identities you forgot to manage</title><link>https://carrolldot.com/blog/agents-are-privileged-identities/</link><guid isPermaLink="true">https://carrolldot.com/blog/agents-are-privileged-identities/</guid><description>An AI agent is a non-human identity with the lifecycle of a service account. Run every one through the same five gates: provisioning, least privilege, secret rotation, audit, deprovisioning.</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><category>AI x Identity</category><category>NHI</category><category>IGA</category><category>PAM</category><category>AI agents</category></item><item><title>You can&apos;t secure the AI you never inventoried</title><link>https://carrolldot.com/blog/ai-bill-of-materials/</link><guid isPermaLink="true">https://carrolldot.com/blog/ai-bill-of-materials/</guid><description>SBOMs became mandatory after Log4Shell proved you cannot secure what you have not inventoried. The same reckoning is hitting AI. Here is what an AI Bill of Materials covers, and why I built a scanner that produces one.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate><category>AI governance</category><category>AIBOM</category><category>SBOM</category><category>supply chain security</category><category>Chinese AI</category><category>AI inventory</category></item><item><title>Your SOC 2 dashboard is green and still cannot answer the AI question</title><link>https://carrolldot.com/blog/soc2-tools-dont-cover-ai/</link><guid isPermaLink="true">https://carrolldot.com/blog/soc2-tools-dont-cover-ai/</guid><description>Vanta and Drata are excellent at infrastructure compliance. They were never built to scan your code for AI providers, and that is exactly the question enterprise buyers are now asking.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><category>AI governance</category><category>SOC 2</category><category>Vanta</category><category>Drata</category><category>compliance</category><category>AI inventory</category></item><item><title>The EU AI Act applies to you through your buyers, not Brussels</title><link>https://carrolldot.com/blog/eu-ai-act-through-your-buyers/</link><guid isPermaLink="true">https://carrolldot.com/blog/eu-ai-act-through-your-buyers/</guid><description>US founders keep saying the EU AI Act does not apply to them. It does, through enterprise procurement. I have watched this exact ripple play out three times in thirty years.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>AI governance</category><category>compliance</category><category>procurement</category><category>regulation</category></item></channel></rss>