Discussion about this post

User's avatar
Alireza Rahmani Khalili's avatar

"We pin every package to a hash. We let AI agents run with whatever they want." — that asymmetry in one line. We built reproducibility into the dependency layer over decades. We handed the action layer to agents with no equivalent constraint. The security graph is necessary but it's still downstream of the problem. The missing layer is behavioral provenance: what did the agent decide to do, under what context, and could that decision be replicated or audited? Without that, the graph tells you something happened, not whether it should have.

I write about production AI systems and distributed backends. Worth a subscribe here too.

No posts

Ready for more?