Articles

Operator notes.

Problem-first writing on AI, automation, and the process underneath. Each piece names a real bottleneck, exposes the broken layer nobody owns, and shows what the working system actually looks like.

Enterprise AI

Human-in-the-loop AI agent approval stops working around prompt fifty

Human-in-the-loop AI agent approval is the control most teams are counting on. Two 2026 studies measured it — and Anthropic is turning the step off by default.

8 min read →
Security operations

Your AI agent platform is a web server nobody patched

AI agent platform security turned out to be patch management. CISA gave federal agencies until 7 August to fix an agent builder with a 9.8 unauthenticated RCE.

8 min read →
AI governance

Your AI agent sandbox is a prompt, not a network control

An AI agent sandbox that lives in the system prompt isn't a boundary. Two labs just proved it — and the root cause was a handoff nobody owned, not a rogue model.

8 min read →
Enterprise AI

Deterministic automation vs AI agents: reasoning can be probabilistic, execution can't

Deterministic automation vs AI agents — the industry just renamed the unit of deployment from agent to harness. What that means for which parts of your workflow should never be probabilistic.

9 min read →
Logistics & trade compliance

AI customs entry automation breaks on a product master that stores conclusions

AI customs entry automation multiplies entries, not correctness. Two July tariff actions made the same USMCA field mean opposite things four days apart.

7 min read →
Finance & procurement

Agentic payments are only as safe as the supplier record underneath them

Agentic payments went live in B2B this month. The agent picks the supplier and sends the money — out of a vendor record nobody owns and nobody verifies.

7 min read →