← back to where I focus
01 Where I focus

Secure generative & agentic AI

Agents are the new attack surface. The work isn't to slow them down — it's to ship them with the controls already in place, so they can move at the speed the business needs.

The shift from copilots to agents

For the last two years most enterprise AI work has been about copilots — humans in the loop, prompts in, completions out. That era is closing. The next wave is agentic AI: systems that plan, call tools, talk to other agents, and act on behalf of the business. They book travel, reconcile invoices, raise pull requests, file tickets, and increasingly take real-world actions across SaaS, data, and infrastructure.

That changes the threat model entirely. A copilot leaks data. An agent does things. The blast radius is no longer a bad answer — it’s a wrong action, executed at machine speed, against production systems.

What I architect for

Every agentic system I design has the same four pillars locked in before any model is wired up:

The patterns that actually work

A few patterns have hardened over the last twelve months and now show up in almost every engagement:

What it unlocks

When the controls are real, the conversation with the CISO changes. Instead of “can we even do this?” it becomes “what do we ship next?” That’s the goal — not friction, not theatre, but a platform where the business can lean into agentic AI confidently because the worst-case scenarios have already been engineered out.

Secure agentic AI isn’t a constraint on ambition. It’s the only thing that lets ambition scale.