7 posts
Posts on security
On building, running and keeping control of your own agents.
latest · Oct 1, 2026 · 6 min readAgent protocols are converging. Inter-org trust isn't.
A2A v1.0 standardized the agent handshake — cards, tasks, transports. It leaves card verification, delegation, and cross-org trust to you.
2026
- Sep 3Prompt injection can't be solved. It has to be contained.5 minThe industry has stopped pretending it can filter injection away. The ones that survive treat it as a blast-radius problem — and bound it with permissions, not prompts.
- Aug 27Orphaned AI agents are the incident you haven't budgeted for5 minAgent fleets double quarterly, but only a fifth of teams decommission agents. Orphaned agents keep credentials, memory, and budgets alive long after their owners are gone.
- Aug 20Agent authorization is the gap that identity misses5 minWho an agent is matters less than what it's allowed to do. Frameworks ship auth-n but leave the scoping that actually contains blast radius to you.
- Jul 23MCP won the standards war. Now the ops layer is the gap.4 minMCP is the default protocol for AI tool access, but its security and ops holes are where incidents happen. The protocol is a data format — not an operations layer.
- Jul 9Your multi-agent pipeline has no message authentication5 minEvery major agent framework passes messages between agents as plaintext — no signatures, no verification. That is the defining security gap of multi-agent systems in 2026.
- Jun 11Agents Don't Know Who They're Talking To6 minEvery major agent framework identifies agents by a name and a role string — no keys, no signatures, no peer verification. What production actually needs.