Writing
Non-Human Identity: Paper Series
A five-paper series on non-human identity for AI agents in regulated European enterprises. Each paper is published as a LinkedIn long-form article with a full-length version hosted here.
Unifying thesis: AI agents in production require a distinct identity, authorization, communication, audit, and governance stack, not a relabeling of existing service-account, RBAC, and CMDB primitives.
- Agents Are Not Service Accounts . Per-agent identity as the floor. Published April 21, 2026.
- Authorization for AI Agents, Beyond RBAC . Per-task composite-identity authorization with capability tokens. Published April 28, 2026.
- Authorization Without Disclosure . Zero-knowledge proofs for agent-to-agent authorization, plus the AAC reference architecture. Published May 5, 2026. Technical companion: AAC Construction Specification .
- Delegation Without Escalation . Capability tokens, attenuation discipline, and the patterns that survive in production. Published May 12, 2026.
- Auditing Agents Under NIS2, DORA, and the EU AI Act . Compliance by construction, when architecture becomes the audit evidence. Published May 19, 2026.
PQC for AI Agents: Paper Series
A three-paper series on post-quantum crypto-agility for AI agent systems, opened June 2026 and completed July 2026.
Written at executive register for CISOs, risk officers, and boards facing the NIS2, DORA, and EU AI Act compliance windows. It treats post-quantum readiness not as a one-time migration but as a crypto-agility program, measured across the three cryptographic surfaces every agent carries: the identity it presents, the channel it speaks over, and the receipts it leaves behind.
- The Channel Question . Post-quantum substrate for AI agent communication. Published June 17, 2026.
- The Agility Question . A post-quantum maturity model for AI agent systems. Published June 23, 2026.
- The Evidence Question . Regulated agents under DORA and NIS2, and the record that has to outlive them. Published July 15, 2026.
LinkedIn articles
Executive-facing essays on LinkedIn Pulse.
- AI Attacks. AI Defends. Governance Does Neither. (May 21, 2026). Co-authored with Cesar Cerrudo. Four governance gaps that emerge when AI runs both offense and defense (accountability, privacy, intellectual property, cost), and why current frameworks address none.
- What boards get wrong about AI risk (April 7, 2026). Four mistakes boards make when confronting AI risk, and the four actions that follow.