Ehsan Hosseini

Ehsan Hosseini

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it. Based in Berlin.

For AI agents, authentication is largely solved. Authorization is not. I write about the identity, delegation, and audit primitives that decide what an agent is actually allowed to do, and I build them at my company.

Currently

  • - Writing Agent Access Control: Pilot → Production, a six-part series
  • - Building an access control layer for enterprise AI at my company
  • - Tracking the IETF drafts on agentic delegation and token attenuation
  • - Working through what the EU AI Act's audit trail requirements mean in practice

Get the series as it ships

New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.

Latest Articles

AI Agent Governance and Safety: understanding the control points that matter

Governance is the decision about what an agent may do. Safety is whether that decision holds when it runs. A map of the control points across trigger, harness and model, what fails at each, and where the EU AI Act, ISO 42001 and OWASP stop short.

Enterprise-Managed Authorization for MCP: what it actually does, and what it leaves to you

MCP enterprise-managed authorization (EMA) lets the corporate identity provider decide which MCP servers employees can reach, with no per-server consent prompts. A practical, spec-accurate guide to the ID-JAG flow with a build checklist, and a hard line between what EMA secures (the connection) and what it leaves to you (per-action authorization).

Identity Mesh and Secure AI Agents

Agent Access Control: Pilot → Production, Part 1 of 6. Why production AI agents must execute on behalf of a human or service identity, not with a shared "agent token." Introduces Subject/Actor/Authority and per-action scoped access for auditable tool calls, plus the Identity Mesh concept for consistent per-action policy decisions across tools.

GDPR vs. the EU AI Act: Why This Time, the Stakes Feel Different

Exploring how the EU AI Act extends the principles of GDPR from data protection to system accountability, and why this new regulatory wave feels fundamentally different.

The Future of LLMs and AI Agentic Platforms: Opportunities and Strategies

An in-depth exploration of how Large Language Models (LLMs) and specialized AI agentic platforms will shape the future, examining current challenges, technological advancements, practical use-cases, and strategic insights.

Crucial Considerations for Corporate Data Security: Public Accessibility of Shared AI Conversations

Contrary to common understanding, shared AI conversations often end up being publicly indexed and available. This chapter warns businesses about the real and immediate threats, and guides how to safeguard against data leakage via AI tools.

Advanced Techniques for Planning in AI Agents: A Comprehensive Guide

Planning is a fundamental aspect that transforms AI agents from simple chatbots into intelligent assistants capable of executing complex tasks. This article dives deep into the concept of planning, the challenges it presents, and provides real-world examples.

about

Ehsan Hosseini

Ehsan Hosseini

me [at] ehosseini [dot] info

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it. I write about it here, and build it at my company.