I’ve run an agtech company for more than 2 decades. I built AI agents into our SaaS platform.
They failed. They hallucinated. They broke rules written directly into their own MD files.
That's when I learned prompts aren't governance. So I built SAZ. 🧵
Agentic-platform market has split into two camps. Platforms that let agents run unattended, and platforms that gate every action behind a person. The unattended camp has the money and the buzz right now. It also has the complaint section: customers paying for work that was never really done, outreach sent that nobody approved, budgets burned on failed runs. The more money behind the platform, the louder that same section reads. Their own customers are describing the product we already are: approval before action, records after #GovernedAutonomy #AIAgents
Bill Gates is right — self-regulation isn't enough. But agents already working inside businesses won't wait for Congress. Build accountability in; don't outsource it. #AIGovernance https://t.co/cd5plKXWWh
Bill Gates claims AI self-regulation isn’t enough while still being a top investor
“No one thinks self-regulation is enough… You need law enforcement and the politicians to get into the discussion about what safeguards and monitoring look like.”
Bill Gates remains one of OpenAI’s largest investors, with the Gates Foundation aiming to invest over $200 billion in AI development by 2045
Nadella and Zuckerberg agree: the agent race is won on trust, not IQ. But trust isn't a vibe — it's scoped access plus a log you can read. #GovernedAutonomy#AIAgents https://t.co/DAvWwrwsH1
Satya Nadella and Mark Zuckerberg are now saying the same thing, the AI agent race will be won by trust, not intelligence.
Autonomous agents require access to credentials, private data, payment systems, and company software before they can become genuinely useful. That makes governance one of the largest barriers to adoption. Enterprises need to know what an agent can access, who authorized it, what actions it completed, how much it spent, and whether those actions can be reversed. This is why Nadella believes Agent 365 could become more important than the individual agents themselves. Microsoft is positioning it as the control layer that allows companies to observe agents, assign permissions, enforce policies, monitor spending, and maintain an audit trail of their activity.
Zuckerberg recently made almost the same argument. Meta had a capable version of Muse months before launch but the company delayed it to improve the product’s privacy and security systems. Zuckerberg believes that instruction following, intent understanding, and alignment with user values will matter more than simply improving model benchmarks. Meta built Muse around a dedicated virtual machine that isolates each agent and stores the user’s connected data and credentials. A separate Sentinel system reviews its activity, while sensitive actions such as sending emails or completing purchases require user approval.
Microsoft and Meta are approaching the opportunity from different directions, but both have reached the same conclusion. Microsoft is building the governance layer for enterprise agents, while Meta is building the trust architecture for personal agents. The companies that control identity, permissions, audit trails, secure credentials, policy enforcement, and agent spending could become just as important as the companies building the underlying models.The biggest moat in AI agents may not be creating the smartest system but rather creating the system that consumers and businesses are willing to trust with everything.
I’m positioning around the companies building the trust and control layer for AI agents because that may become just as important as the models themselves. If you want to see exactly what I hold across enterprise AI, agents, and the infrastructure behind them, check out my Milk Road Pro portfolio below.
https://t.co/thIhK9ZH4E
Whose keys does your agent carry? Amazon's point: prove authority BEFORE an agent touches a business. SAZ was designed for that — scoped access, every action logged — partners say yes, any shop automates 24/7. #GovernedAutonomy#AIAgents https://t.co/aZwGEGo6yH
JUST IN: AMAZON BLOCKS META'S MUSE AI AGENT
▫️ Muse could shop on Amazon for users
▫️ Amazon asked Meta to remove the capability
▫️ Meta declined, and Amazon blocked the bot from its retail site
Agent commerce now has its first major platform war.
Safety just moved into the infrastructure. Guardrails ask nicely; infrastructure doesn't. SAZ has enforced agent boundaries since day one: scoped authority, every action logged, any shop, 24/7. #GovernedAutonomy#AIAgents https://t.co/vjNOkkkcdx
🚨 BREAKING: Nvidia has launched a new AI safety platform designed to stop autonomous agents from escaping sandboxes and accessing systems they shouldn’t.
🛡️ @Nvidia says its Open Agent Safety Platform could have prevented the Hugging Face breach this summer.
The system includes OpenShell, an open-source runtime with kernel-level isolation, plus Sentry to detect and shut down rogue agent behavior.
🤖🔒 AI safety is moving beyond model guardrails and into the infrastructure itself.
#Nvidia #AI #AIAgents #Cybersecurity #ArtificialIntelligence #OpenShell
Millisecond quarantine — finally the right language. Prompts break; boundaries outside the agent don't. SAZ was designed for that: scoped authority, every action logged, 24/7 safety for shops of any size. #GovernedAutonomy#AIAgents https://t.co/yYBP75cXNl
NVIDIA just shipped an open platform to stop AI agents from breaking containment.
Open Agent Safety Platform pairs OpenShell (open-source runtime that enforces policy outside the model) with Sentry (a BlueField-4 DPU watchdog that can quarantine a rogue agent in milliseconds).
Via NVIDIA / CNBC
https://t.co/kiCvYDFL2k
"Where the agent can't reach" — the five words that matter in agent security. SAZ enforces exactly that: boundaries outside the agent, every action logged, containment while work runs. Lab-grade safety for every shop, 24/7. #GovernedAutonomy#AIAgents https://t.co/5q1rZ84irm
Enforce agent safety where the agent can’t reach.
NVIDIA Open Agent Safety Platform consists of NVIDIA OpenShell open source software and the NVIDIA Sentry reference system design that enables full-stack governance and control across software and hardware.
Read the announcement to learn more ⤵️
Pop quiz: how many things are waiting on one person at your business at 6pm? A governed agent takes the waiting off that person — enquiries, quotes, renewals — and leaves a record you can hand to an auditor. SAZ makes it safe. #GovernedAutonomy#AIAgents
You didn't lose that job to a better competitor. You lost it to the enquiry nobody answered for three days. A governed agent answers in minutes — and nothing it sends goes out without you seeing it first. SAZ builds those guardrails. #GovernedAutonomy#SmallBusiness
Every line of that list is a place your data can leak. The fix isn't trusting the model more — it's putting the agent inside the boundary with the data. https://t.co/8fyEwk9SXp
AI agents are getting access to more powerful systems.
GitHub.
Databases.
Cloud infrastructure.
Browsers.
Internal APIs.
Deployment pipelines.
That creates a new engineering problem
How do you secure software that can make decisions and take actions? Traditional application security still matters, but agents introduce another layer. A document can contain malicious instructions. A tool can return unexpected data.
An agent can be tricked into using a legitimate tool in an unsafe way. A credential with too much access can turn a small mistake into a serious incident.
This is why I'm watching AI security engineering as a growing developer niche.
There is a lot to learn
prompt injection
tool security
sandboxing
identity and permissions
secret isolation
agent monitoring
policy enforcement
red teaming
AI-specific evals
You don't need to build a new foundation model to work in this space.
If you already understand security, backend systems or cloud infrastructure, adding AI agent security on top could be a very useful specialization.
As agents get more access, securing that access becomes a product in itself.
The chart every buyer should carry. No vendor maps coverage to all 120 techniques (September release): it's marketing. SAZ sees MITRE ATLAS as the reference framework for AI security threat modeling and testing. #GovernedAutonomy#AgenticAI https://t.co/QWQUPWeBtD
We read what 19 AI-security vendors publish against the 76 MITRE ATLAS techniques tagged "Agentic AI".
No vendor documents more than 23. The median is 12. 8 of the 19 document fewer than 10.
Most of the agentic attack surface is claimed by nobody.
https://t.co/SiBEFq3XvU
Ten times every book ever written — one stack of logs. Nobody reads that, not even the labs. SAZ does that differently: scoped agents, one page per action, a trail you can actually read. A solo founder audits yesterday's agent work in one coffee. https://t.co/wNsP3H11eX
Agents that can alter their own evidence leave you one defense: a log a human actually reads. SAZ does that — one page per action, scopes you set, a stop button that works. Your team catches the weird step today, not when it's too big to understand. https://t.co/sTuPYRIVle
This is what loss of control and oversight looks like btw
Not even necessarily that the info isn't there (though the agents do already alter and destroy evidence), but that it becomes so large, so uninterpretable that no one cares to understand it, or, eventually, no one can.
Passive voice in an incident report means nobody owns the mistake. SAZ makes ownership structural: one named owner per agent, a receipt for every action. When your five-agent stack does something odd, you know who and what — no forensics required. https://t.co/SXkI9lBMmK
From the first report of OAI/HF it was clear the test infrastructure was lacking. Each report since then was loaded with passive voice, agentic self-actualization, and incomplete descriptions of what happened.
This left everyone confused or just informed enough to emphasize their pre-determined conclusion about AI broadly.
At some point the collective needs to step back and have a candid discussion about the engineering and security practices and where actual accountability rests.
https://t.co/i64yVzjF30
A system prompt is a wish, not a wall. This model was told not to — twice — and leaked a token anyway. Boundaries have to live below the prompt: scopes, egress rules, logs. https://t.co/d6bdRyg9z0
🧵 New misalignment disclosures!
1. A model published a GitHub token in a public repo while trying to cheat on a math task. It used GitHub Actions to run code outside its restricted environment and retrieve another team’s submission logs. When GitHub blocked its attempt to add a workflow, it modified a script that an existing workflow would run instead. It embedded the token in pieces to avoid secret scanning. The model violated the system prompt and two explicit user instructions to solve the problem itself.
Agreed — power users get magic, but organizations need control. SAZ built the solution: coded boundaries the LLM can't go outside. Code, not prompts. Hand agents real work and stay in charge — scopes, approvals, audit trail. #GovernedAutonomy#AIAgents https://t.co/TAFdOIFKLl
I'm not convinced SaaS is going anywhere soon.
Agentic AI is great for individual power users. But organisations are made up of multi-user workflows where control and governance are more important than infinite flexibility.
#strategy#AI#SaaS
Agents move at machine speed. Governance moves at meeting speed. That gap is why Gartner expects 40% of agentic AI projects to be scrapped by 2027. The fix is runtime evidence, not another deck. https://t.co/VZ3XE59QZa
Dawn of New Governance Laws for AI Agents: Real-Time “Control” for Autonomy
Why AI agent governance must happen at runtime and how governance changes in the face of agentic speed
https://t.co/cFPVPkoGWv
Building with AI agents? Know a solo founder who is? Tag them below.
We're also looking for partners who want to help spread governed autonomy. DMs are open.
#GovernedAutonomy
I’ve run an agtech company for more than 2 decades. I built AI agents into our SaaS platform.
They failed. They hallucinated. They broke rules written directly into their own MD files.
That's when I learned prompts aren't governance. So I built SAZ. 🧵
Coming soon: a paper series on how we built SAZ and the challenges we had to overcome, plus daily posts on industry trends.
Follow @secureagentzai to learn with us.