Perspectives

Three ideas behind every engagement. Argue with any of them.

Security is a dome, not a stack

Why layered AI security fails when the layers do not bear on each other.

Most AI security programs are built the way most security programs are built. A control for prompts, a control for data, a control for access, a control for logging, stacked in the order the vendors arrived. Each one assumes the one below caught what it missed. None of them know the others exist.

A dome works differently. Every tile bears on its neighbors, and the load travels through the whole structure. Remove one and the rest hold, because the geometry was designed for it. That is the test an AI security architecture should pass. Agent identity at the core, so every action has an owner. Pipeline security in the shell, so what ships is what was reviewed. Runtime detection on the surface, so a failure is seen in seconds. AI safety in the foundation, so the system has a floor it cannot fall through.

The practical difference shows up in the incident, not the diagram. In a stack, the first question is which control failed. In a dome, the first question is which tile cracked, and the answer arrives with the rest of the structure still standing. Boards do not buy architecture diagrams. They buy the second question.

 

Agents are the new identity

The access model most enterprises run was designed for people, and agents are not people.

Enterprise identity has one deep assumption. The principal on the other end of a credential is a person, with a role, a manager, and a reason to be there tomorrow. Agents break every part of that. They are created in minutes, act thousands of times an hour, chain tools together in ways no one scoped, and disappear when a job finishes. Giving one a service account and a permission set is giving a sprinter a lifetime pass.

The fix is not tighter scoping. It is moving the authorization decision to the moment the agent acts. Who is this agent, on whose behalf, calling which tool, with what data, inside which task? Those five questions can be answered at runtime for every call, and the answer can be logged as evidence. Scoped once at provisioning, the same questions are guesses that age.

This is also where the commercial upside lives. An enterprise that can answer those five questions for every agent can let agents do more, because it can see what they are doing and stop them in time. The company that scopes tightly ships slowly. The company that authorizes at runtime ships first.

 

Safety is a number, not a report

What changes when the safety posture of an AI estate is computed continuously.

Most AI safety work produces documents. A model card, an impact assessment, a quarterly review. Useful, and already out of date when they are signed. The models they describe have been updated, the agents have new tools, and the incidents that matter have been happening in the gap.

The Safety Health Index is the alternative. One continuously computed score of the safety posture of the whole AI estate, built from streaming telemetry across agent reasoning traces, tool invocations, and identity events, and broken into five indicators. Agent boundary controls, identity integrity, content safety, tool safety, and operational health. Each indicator is its own detection surface. Each one can page someone.

The shift this produces is cultural before it is technical. When safety is a number on the same screen as latency and error rate, engineers treat it as an engineering property, operations treats a safety event as an incident with an SLO, and the board gets a trend line instead of a binder. The report still gets written. It just stops being the only place the truth lives.

Argue with any of this

Thirty minutes. Bring the hardest case in your AI estate and we will test these ideas against it.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.