THINKING

Position pieces from the founder

On governance, evidence, authorization — and making AI work auditable. Written when there's something worth saying, not on a schedule.

14 AUGUST 2026

Your agent's memory is not your audit trail

There is a genuinely good agent memory pattern making the rounds under the name LVP: an append-only event Ledger, a Policy layer, derived Views, bitemporal timestamps underneath. Then comes the inference — "we already have a ledger and a policy layer, so governance is covered." Same words, opposite sides of a trust boundary. The test is one question — hand your ledger to someone who distrusts you: what can they verify? — and a five-question checklist this piece runs on our own product too, failing part of it in public.

Read →
8 AUGUST 2026

Six gates in a day. Every one caught us first.

We built six governance controls in one day, and within minutes of existing each one found a real defect — in us. A gate that read a plan as an accomplishment, so the stronger wording scored as a downgrade and passed silently. An evidence checker whose first act was to certify a page that does not exist. A safety gate that locked us out of repairing the outage it was guarding, because the fix required the service it had just refused. Not one was found wanting by review; every one was found wanting by being run.

Read →
2 AUGUST 2026

Trust Without Acquaintance

Humans allocate trust by familiarity, not ability, and that layer does not scale: a mid-size company now runs thousands of AI actions a day, and every one is a stranger. Institutions always answered this by manufacturing familiarity, but a SOC 2 report vouches for a company, roughly, once a year, and says nothing about the action at 4:51pm yesterday. On runtime receipts as familiarity manufactured at the resolution of one action, and the distinction that separates testimony from surveillance footage: the only receipts that carry weight are generated by enforcement.

Read →
1 AUGUST 2026

Evidence cuts both ways

Every AI guardrail treats the human approver as ground truth, and the human is the least verifiable component in the loop. My agent asked me to photograph a device because "I tested it" resolved to nothing. It refused a six-second code review and asked for the business-scenario run instead. Why holding the person to evidence makes the model hallucinate less — and why the harder question is whether a decision reaches production at all.

Read →
27 JULY 2026

We send each other our chat logs now

Humans stopped handing off to each other, and it was not because the tools made us antisocial. Human bandwidth stopped meeting the rate agents created, so the medium changed by itself: we exchange AI conversation logs, compressed by a step neither party sees. What breaks in there, the claim gate that already ships, the alignment gate nobody is building, and why execution governance leaves the most consequential step unrecorded.

Read →
27 JULY 2026

It was true. It still wasn't allowed.

My product published a claim about itself that hadn't happened yet. The claim turned out to be true, and that is not a defence. The gate had been firing the whole time; I clicked approve without reading it. What the logs showed, the two measured device rows, why the tier was split instead of loosened, and what a human click is actually worth.

Read →
25 JULY 2026

Who approved that?

Now that AI agents do real work beside humans, authorization and accountability have quietly become the audit question. Why logs can't answer it, a frequency law for approvals (assurance ∝ blast radius ÷ frequency), the R0–R4 assurance ladder with its honest limits — and why the accountability chain has to end at a key your own organization holds.

Read →