Field notes.

Building Doberman in the open: AI agent security, incidents worth learning from, and the case for putting runtime authorization on the execution path.

  1. 6 min read

    Approval Fatigue is a security issue, not a UX problem

    I’ve spent the last two weeks making Doberman ask for approval less often. This increased safety and here’s why.

  2. 4 min read

    An honest comparison: Cisco’s DefenseClaw and Doberman

    Cisco's answer to runtime AI defense — what DefenseClaw gets right, and where a dedicated authorization layer makes a different bet.

  3. 21 min read

    The AI Security Playbook

    Takeaways from RAND's Practical Guide for Securing AI Models — and why AI security is shifting from model safety to execution security.

  4. 11 min read

    When AI Output Stops Being Text

    The Hugging Face incident shows why agent security cannot end with better prompts, safer models or stronger sandboxes.

Prefer email? These posts are mirrored on Substack ↗ — or subscribe to the RSS feed.