Articles

Get the series as it ships

New parts of Agent Access Control, plus analysis of agent identity standards as they move. Roughly monthly. No filler, no cadence promises I won't keep.

Agent Access Control series

Series hub →

Agent identity, security & regulation

AI Agent Governance and Safety: understanding the control points that matter

In late July 2026 I gave a talk in Berlin on AI agent governance and safety, written for people who are new to the space. The topic sprawls across technical, architectural and legal ground, so this written version stays where engineers have real leverage: the control points where vulnerabilities actually happen.

Enterprise-Managed Authorization for MCP: what it actually does, and what it leaves to you

MCP enterprise-managed authorization (EMA) lets the corporate identity provider decide which MCP servers employees can reach, with no per-server consent prompts. A practical, spec-accurate guide to the ID-JAG flow with a build checklist, and a hard line between what EMA secures (the connection) and what it leaves to you (per-action authorization).

Engineering archive (pre-2025)(62)
Browse archive pages →

about

Ehsan Hosseini

Ehsan Hosseini

me [at] ehosseini [dot] info

I work on what AI agents are allowed to do inside companies, and whether you can prove who authorized it. I write about it here, and build it at my company.