Ehsan Hosseini

Ehsan Hosseini

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it.

For AI agents, authentication is largely solved. Authorization is not. I write about the identity, delegation, and audit primitives that decide what an agent is actually allowed to do, and I build them at my company.

Currently

  • - Writing Agent Access Control: Pilot → Production, a six-part series
  • - Building an access control layer for enterprise AI at my company
  • - Tracking the IETF drafts on agentic delegation and token attenuation
  • - Working through what the EU AI Act's audit trail requirements mean in practice

Get the series as it ships

New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.

Latest Articles

Enterprise-Managed Authorization for MCP: what it actually does, and what it leaves to you

MCP enterprise-managed authorization (EMA) lets the corporate identity provider decide which MCP servers employees can reach, with no per-server consent prompts. A practical, spec-accurate guide to the ID-JAG flow with a build checklist, and a hard line between what EMA secures (the connection) and what it leaves to you (per-action authorization).

Identity Mesh and Secure AI Agents

Agent Access Control: Pilot → Production, Part 1 of 6. Why production AI agents must execute on behalf of a human or service identity, not with a shared "agent token." Introduces Subject/Actor/Authority and per-action scoped access for auditable tool calls, plus the Identity Mesh concept for consistent per-action policy decisions across tools.

GDPR vs. the EU AI Act: Why This Time, the Stakes Feel Different

Exploring how the EU AI Act extends the principles of GDPR from data protection to system accountability, and why this new regulatory wave feels fundamentally different.

The Future of LLMs and AI Agentic Platforms: Opportunities and Strategies

An in-depth exploration of how Large Language Models (LLMs) and specialized AI agentic platforms will shape the future, examining current challenges, technological advancements, practical use-cases, and strategic insights.

Crucial Considerations for Corporate Data Security: Public Accessibility of Shared AI Conversations

Contrary to common understanding, shared AI conversations often end up being publicly indexed and available. This chapter warns businesses about the real and immediate threats, and guides how to safeguard against data leakage via AI tools.

Advanced Techniques for Planning in AI Agents: A Comprehensive Guide

Planning is a fundamental aspect that transforms AI agents from simple chatbots into intelligent assistants capable of executing complex tasks. This article dives deep into the concept of planning, the challenges it presents, and provides real-world examples.

about

Ehsan Hosseini

Ehsan Hosseini

me [at] ehosseini [dot] info

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it. I write about it here, and build it at my company.

How it works?

I write what I learn while building systems that decide what an AI agent is allowed to do. The thinking, the arguments, and the calls about what's true are mine. I use AI to draft, structure, and speed up research, the same way I'd use any other tool. It doesn't decide what I believe.

I check technical claims against primary sources before a post goes out: the specs, the RFCs, the original documentation, not a model's memory of them. When I'm uncertain, I say so. When something is opinion rather than fact, I mark it as one. If I get something wrong, that's on me.

© 2026 Ehsan Hosseini. All rights reserved.