ARTICLES
Technology and business,
from hands-on practice.
Articles on AI agents, business systems, financial AI, and e-commerce.
We write from the perspective of designing, building, and operating technology in real business contexts.
CATEGORIES
LATEST ARTICLES

Anthropic's Model Hardware Standard: Enforcing Operating Limits Outside the AI Model
A research preview read for which layer enforces an AI's operating limits—and for when QuEra took the AI out of the production loop.

AISI's Incident Report: When Technical Access Exceeds Authorized Scope
The agent never broke out of the sandbox. Re-read as the gap between authorized scope and what was technically reachable, with a look at where each control is actually enforced.

The Proposed AI AGENT Act: Designing Access for User-Authorized Agents
The text of the U.S. Senate's AI AGENT Act bill (S.5051), re-read as the decision flow facing a company that has to receive outside AI agents acting on its customers' behalf.

A2A Joins AAIF Alongside MCP—But the Protocol Seam Remains
A2A and MCP now sit under the same foundation, but technical governance stays separate—and carrying identity, narrowing downstream permissions, and propagating cancellation across the two remains the connector's design work.

Building Business Systems with Generative AI: Where to Draw the Line Between Prototype and Production
How far can you move quickly with generative AI, and when should a production-readiness review begin? Incidents disclosed in 2026 help map the questions to resolve before go-live.

Meta's Muse Code: Worktree Isolation Prevents Editing Collisions, but Integration Risks Remain
A design that prevents concurrent edits and consistency after integration are two different problems. Using Meta's first-party material on Muse Code as a starting point, we set out along three axes what is separated when coding agents run in parallel, and what is not.

Shadow AI and Verizon's 2026 DBIR: Designing the Approved Path
The 45% and the 67% measure different things. Read separately, they point to what actually needs designing: an approved path people choose over the unmanaged alternative.

Cloudflare's Agent Access Model: Permissions Beyond the Prompt
A reference architecture proposal and a private beta, read for what they say about binding, recording, and narrowing agent permissions outside the model.

Mercury Agent Cards: Enforced Spend Limits and Customer Liability
Telling an agent "spend up to this much" in a prompt is not the same as a limit that gets declined at authorization. And setting a limit does not move liability.