Articles
Operator notes.
Problem-first writing on AI, automation, and the process underneath. Each piece names a real bottleneck, exposes the broken layer nobody owns, and shows what the working system actually looks like.
Human-in-the-loop AI agent approval stops working around prompt fifty
Human-in-the-loop AI agent approval is the control most teams are counting on. Two 2026 studies measured it — and Anthropic is turning the step off by default.
8 min read → Security operationsYour AI agent platform is a web server nobody patched
AI agent platform security turned out to be patch management. CISA gave federal agencies until 7 August to fix an agent builder with a 9.8 unauthenticated RCE.
8 min read → AI governanceYour AI agent sandbox is a prompt, not a network control
An AI agent sandbox that lives in the system prompt isn't a boundary. Two labs just proved it — and the root cause was a handoff nobody owned, not a rogue model.
8 min read → Enterprise AIDeterministic automation vs AI agents: reasoning can be probabilistic, execution can't
Deterministic automation vs AI agents — the industry just renamed the unit of deployment from agent to harness. What that means for which parts of your workflow should never be probabilistic.
9 min read → Logistics & trade complianceAI customs entry automation breaks on a product master that stores conclusions
AI customs entry automation multiplies entries, not correctness. Two July tariff actions made the same USMCA field mean opposite things four days apart.
7 min read → Finance & procurementAgentic payments are only as safe as the supplier record underneath them
Agentic payments went live in B2B this month. The agent picks the supplier and sends the money — out of a vendor record nobody owns and nobody verifies.
7 min read →