Короткие тексты об инженерном лидерстве, AI-агентах и регулируемых системах.
Короткие посты — обычно 100–300 слов — впервые публикуются в LinkedIn и зеркалируются сюда. Архивируются по дате, ищутся по тегам. Где оригинал живёт на LinkedIn, пост ссылается обратно. Версия здесь — каноническая запись.
One task in my workflow can be researched in ChatGPT, implemented by Codex, challenged by Claude, and updated through MCP.
Most project tools still assume every participant is human, which leaves someone acting as the relay between chats, repositories, decisions and the board.
BuildingI can run several agents in parallel — that does not mean I should let all of them think before I do.
Judgment is partly built in the uncomfortable phase before the options arrive, which is exactly the phase parallel agents remove.
Engineering leadershipA conversation that follows you across devices is a feature — authority that follows it is a security decision.
Portable agent sessions carry two things at once: context, which should travel freely, and authority, which was granted for a specific action in a specific state.
AI governanceEvery engineer knows Amdahl's law. Almost nobody applies it to AI forecasts.
A 10x improvement in one operation produces almost nothing at the system level if that operation was not the constraint — which explains both failed pilots and outsized wins.
AI transformationEvery approval step is a claim that a person could have stopped it.
A screen showing a summary and two buttons has added latency, not oversight — and the proposal on screen has to be the proposal that executes.
AI governanceA generated patch is a hypothesis until someone re-runs the exploit.
Across 6,080 AI-generated patches only 26% were clean — and a plausible-but-wrong fix direction in the prompt cut success from two-thirds to one in six, with agents overriding their own contrary evidence.
AI engineeringWe keep securing the model and trusting the scaffolding around it.
Every control we put on an agent lives in the harness — so once the agent can edit its own prompts, tools and memory, a harness change is a privileged production change.
AI engineeringSome work only gets respect after we rename it like engineering.
AI makes execution cheaper, which raises the value of deciding what should exist — but many organizations only recognise that work once it sounds technical.
Engineering leadershipFour agents cleared the backlog because none was allowed to be the hero.
Astro's issue factory separated reproduction, diagnosis, verification and implementation — the improvement came from forbidding self-verification, not from adding agents.
AI engineeringA rollback that restores the old configuration may still leave the system broken.
Sessions, caches, routing state and partial side effects do not revert because the file did — which makes 'previous version available' and 'operation reversible' different properties.
Systems engineeringI do not grant an agent autonomy because the model looks intelligent — I grant it because the mistake is reversible.
The same model can safely reformat a document and dangerously modify production access, so autonomy should follow review cost and rollback cost rather than a benchmark score.
AI governanceAI shortened how long it takes to build a feature — not how long it takes to learn from one.
37signals cut its cool-down along with its build time. Delivery compresses; customer absorption and operational recovery mostly do not, and the ratio between them shifts.
Engineering leadershipEvery AI strategy has a shadow roadmap — the work the organization quietly stopped funding.
Mid-market app counts jumped 41% in a year while a third of AI tools moved to token-based billing, which makes the negative roadmap the honest part of any AI plan.
AI transformationA global priority queue is often an organisation chart in disguise.
Prioritization turns political when engineers are a shared pool; durable team ownership removes more of that work than any scoring framework.
Engineering leadershipA connector approved for a person is not automatically approved for every agent that person can create.
AgentForger showed a crafted link creating a persistent agent that inherited a user's authorized connectors — which makes agent creation closer to issuing a service account than saving a setting.
AI securityAI can generate five implementations of the same rule before anyone notices the rule has split.
When generation gets cheap, duplicated business meaning gets expensive — the source of truth has to become harder to copy, not easier.
AI engineeringAn interview that rewards memory is testing the skill AI is making cheaper.
When AI writes half the merged code, the useful interview signal shifts from recalling patterns to noticing when the machine is confidently wrong.
Engineering leadershipThe same blind spot let the attacker in and locked the defender out.
One intrusion failed at both ends of the same boundary — a pipeline that could not tell data from code, and guardrails that could not tell an incident responder from an attacker.
AI securityThe first sign that automation worked may be a larger backlog.
When friction filters demand, removing the friction reveals work people had learned not to request — which turns automation into a capacity-allocation decision rather than a throughput win.
Engineering leadershipYour AI product is already interviewing every user — most teams throw the transcript away.
An AI interaction states intent directly instead of leaving it to be inferred from clicks, which makes conversation logs a governed product-research surface rather than discarded exhaust.
AI governanceThe strongest privacy policy may be a system that never sends the data.
On-device inference turns privacy into a property of architecture rather than paperwork — the strongest privacy policy is a system that never sends the data.
AI governanceA clean sign-in dashboard can still hide an active credential attack.
Attackers can validate stolen credentials through OAuth paths that never produce a successful sign-in, so identity telemetry has to follow the protocol, not just the login event.
AI securityIn agentic systems, safe defaults matter more than good warnings — the agent may never read the warning.
As agents run more workflows, security has to live in default-off execution paths, because the agent may never read the warning a human would have caught.
AI securityA good agent skill is not a clever prompt — it is organizational procedure made executable.
A reusable agent skill is organizational procedure made executable — versioned, reviewed, and owned — which is how know-how moves from tribal to institutional.
AI engineeringThe most valuable AI memory may not be the documentation — it may be the exceptions.
Enterprise AI value lives in override history and decision traces, not clean policy docs — which is exactly what makes that memory both a moat and a liability.
AI governanceThe dangerous agent failure is not always a bad answer. Sometimes it is public input reaching private context.
GitLost showed a crafted public GitHub issue steering an agent with cross-repo read access into posting a private README as a public comment — no stolen credentials, just a context-separation failure. The agent runs on a service-account permission model, not a user one, so no patch closes it; the fix is architectural. If public text can steer private access, the permission model is already broken.
AI SecurityThe best hire is not always someone you can manage easily. Sometimes it is someone you would be willing to report to.
Strong leaders create leverage by hiring near-peers who turn direction into daily operating decisions, instead of task-takers who route every decision back through you. A near-peer multiplies judgment; a task-taker multiplies coordination. Hire only for delegation and you become the ceiling on everything the team can do.
Engineering LeadershipA model can get smarter and still make your system less reliable. That is what weak tool contracts do.
The newest Claude models regressed on one edit tool — inventing fields that did not match the schema, failing ~20% of the time in a real agentic session. Smarter model, worse tool behavior, only visible in a long history. The fix is not a better prompt; it is stricter schemas and runtimes that fail loudly. The tool contract is part of the product's intelligence.
AI EngineeringAI is getting good at reviewing code. That is exactly why the human's job in review has to move up.
An AI reviewer is good at the mechanical pass — but it misses the change that fits the diff and breaks the architecture. The reviewer's value moves up the abstraction stack, to the judgment and accountability the model structurally cannot supply. The mechanical reviewer can be automated; the one who owns the consequence cannot.
AI EngineeringThe model can be available and the deployment can still fail. The last mile is an engineering problem.
Enterprise AI depends on last-mile engineering: wiring AI into real tools, permissions, data, processes, and review gates. Buying capability is easier than absorbing it. The model is a purchase; the working system is a build.
AI TransformationIf an AI output is hard to evaluate, the problem may not be the eval. It may be the product boundary.
Good AI products make verification cheaper — decompose work into reviewable units, attach evidence, make the boundary between decided and inferred visible. Output that cannot be verified cheaply gets trusted blindly or ignored, and both are failures.
AI EngineeringAn agent retry loop can become an outage. That is not an intelligence problem — it is a systems problem.
Agents call tools, retry on failure, run in parallel, and resume after interruptions — every one a distributed-systems problem we already know is hard. A smarter agent does not reduce these risks, it raises them. The runtime has to survive what the intelligence plans.
AI EngineeringAn agent identity is not enough. Someone has to own what the agent is allowed to do.
Registering an agent as an identity is the easy half. The hard half is accountability — authentication answers 'who is this' while ownership answers 'who answers for what it does.' An agent with no owner is a latent incident that moves fast.
AI GovernanceYour team is shipping more code than ever. That is not the same as being more productive — and AI makes the gap dangerous.
Activity metrics were always proxies for human effort. AI makes output cheap, so output stops being evidence of value. The only metric that survives AI is the one tied to an outcome someone actually wanted.
Engineering LeadershipThe important part of Claude Tag is not that Claude joined Slack. It is that execution is moving into the collaboration layer.
When agents enter the place where teams discuss work, the operating risk shifts from prompting to delegation, context, permission, and ownership. AI adoption becomes workflow design, not chat integration.
AI TransformationA hidden AI guardrail is not governance. It is unobservable product behavior.
Users forgive limits more easily than mystery. In an AI workflow, a guardrail is part of the product surface — it needs a trace, a reason, a fallback, and a cost signal. The safety layer cannot behave like a hidden exception handler.
AI GovernanceAI can make a team faster and more exhausted at the same time. That is not a paradox.
More output without a redesign of review, ownership, and recovery time turns the productivity gain into a cognitive-load tax. AI adoption is not just a tooling rollout — it is a workload-design problem.
Engineering LeadershipMore context is not always better context.
Good context design is closer to a memory hierarchy than a warehouse — and a bigger window mostly makes weak context architecture easier to hide.
AI engineeringPrompt engineering was the visible phase. Loop engineering is where AI starts becoming operating infrastructure.
A loop has a goal, context, a way to act, a way to evaluate, and a rule for what happens next. The hard part is not making it run — it is deciding what the loop is allowed to optimize and where it must stop.
AI EngineeringFor years an app was a screen you tapped through. It is quietly becoming a set of functions an agent can call without ever opening it.
With Android 17 AppFunctions, an app exposes its actions as callable tools and the screen becomes optional. When a machine can call your product directly, your permission model stops being plumbing — it becomes the product.
Product EngineeringYour product is no longer used only by people. It is also read, summarized, scraped, tested, and probed by machines.
Machine traffic has crossed human traffic, and a growing share is agents acting now, not crawlers indexing for later. Designing for machine readers is not marketing or security bolted on at the end — it is architecture.
Systems ThinkingYou can damage an engineering culture in the name of AI — and then wonder why the AI work keeps getting worse.
AI does not replace your engineering culture; it runs on top of it and amplifies whatever was already there. A rollout that trades away trust and ownership to buy visible activity is not transformation — it is an AI label on organizational debt.
Engineering LeadershipRushed human review is not always safer than automation.
The useful distinction is not human versus machine but deterministic versus judgment-heavy — some changes can move fast because the boundary is formal.
AI engineeringThe engineering job is moving from writing software to building the system that writes it.
Agentic code-review numbers show why a software factory is becoming urgent — and why the missing piece is the operator layer between stages, not the model.
Engineering LeadershipThe web's developer knowledge layer was built for humans. Agents need a different interface.
Stack Overflow for Agents treats software knowledge as an API-first, verified, continuously updated system — an admission that agentic development needs living knowledge with accountability attached.
AI EngineeringA privacy rail still has to prove its own supply.
The Zcash Orchard bug is a reminder that confidential balances and an auditable monetary system are two different requirements — and financial infrastructure has to satisfy both at once.
Financial InfrastructureThe next useful AI coding benchmark will not ask whether the model can write code. It will ask whether a maintainer would merge it.
Cognition's FrontierCode measures mergeability — correctness, test quality, scope discipline, and style — on repos maintainers actually own. Owning the consequence of a change is the part that still needs a human.
AI EngineeringYour most important dependency can be switched off by someone you have no contract with.
When a load-bearing dependency is governed by policy, pricing, or decisions you do not influence, you do not own your system — you rent it. Resilience is not a backup vendor; it is the right to substitute.
AI GovernanceAI search tracking is starting to look less like SEO ranking. It looks like polling.
After three identical ChatGPT runs, only 2.2% of citations stayed consistent. If the answer surface is probabilistic, a single prompt result is noise, not a position — so the method has to change.
AI SearchAI agents can read the code. They still cannot read the reasons.
Addy Osmani's 'Intent Debt' names one of the most expensive gaps in agentic engineering: the goals, constraints, and trade-offs that never got written down. Architecture records become control inputs for the tools that modify the system next.
Software ArchitectureYour model provider may also become your consulting competitor.
When frontier labs move into enterprise services, the API stops being a pure supplier relationship and can turn into a channel conflict.
Enterprise AIThe better the autopilot, the more dangerous the sleeping pilot.
Reliable automation improves throughput while quietly eroding the manual skill a team needs to recover when it fails.
Engineering leadershipAI infrastructure is starting to look less like cloud procurement. It looks like capacity diplomacy.
The critical object is not only compute, but the contract around compute: priority, cancellation, and what gets degraded first.
InfrastructureRecursive self-improvement is not just an AI research problem. It is an operating model problem.
The moment an AI system can improve the system that evaluates it, governance stops being a policy document and becomes part of the architecture.
GovernanceAI finding more vulnerabilities is not automatically a security win.
Security improves when detection is connected to execution capacity, not when the findings pile grows faster than the remediation queue.
SecurityAI made code cheaper. It made judgment more expensive.
As agents handle more of the implementation, domain expertise becomes the scarce skill that decides whether the output is actually correct.
Engineering leadershipStablecoins get interesting when they stop looking like a crypto feature.
A dollar-backed asset embedded into an existing remittance network turns the question from token speculation into payment infrastructure design.
FintechAI cost discipline is becoming an engineering leadership problem.
Cost problems in engineering organizations arrive as small exceptions, not all at once. The mature AI stack optimizes for cost per accepted outcome — useful work that survives review, deployment, and operating cost — not raw consumption.
Engineering leadershipThe enterprise AI winner may not look like a new AI app.
Enterprise AI is being absorbed into existing cloud, HR, finance, and IT systems through procurement, governance, and identity channels — not arriving as standalone apps. The platform shift runs through old systems gaining delegated action.
Enterprise AIFor agents, search is becoming programmable infrastructure.
As models gain control over retrieval pipelines, search stops being ranked links and becomes programmable infrastructure — with the operational problems that come with it: source quality, cost, repeatability, and auditability.
AI infrastructureAI infrastructure is becoming a platform-team problem.
Once agents reach production, the hard work moves into the operating layer — routing, cost control, observability, identity, and rollout safety. AI does not remove platform work; it expands the surface it has to cover.
Platform engineeringSecuring your own agents is no longer enough.
The next AI security problem is not the agent you deployed — it is the agent ecosystem you depend on. Treat the agent layer as a production dependency: scoped credentials, audited extensions, isolated profiles, and revocation paths.
AI securityAI does not remove the cost of carrying complexity.
The best engineering organizations will use AI to write less code, not more. Senior judgment is measured by value created per unit of complexity left behind.
Engineering leadershipWhen execution gets cheaper, deciding what deserves execution becomes the senior skill.
AI does not remove product judgment. It punishes weak product judgment faster. As execution compresses, value shifts toward adoption design, trust, and deciding what should not be built.
Product leadershipToken usage is the new lines-of-code metric.
AI adoption should be judged by useful shipped work, validated outcomes, and whether the workflow actually improved after the model entered it — not by activity volume.
Engineering managementCompliance software wins on evidence, not confidence.
AI can automate parts of compliance only when the system preserves control, accountability, traceability, and a defensible audit trail.
Regulated systemsAgents borrow blast radius. That's the problem.
An AI agent using a user's session is not automation. It is privilege amplification with a friendly interface.
ArchitectureAI coding becomes enterprise-grade when it survives finance, security, and maintenance.
The leadership question is no longer whether engineers will use coding agents. It is whether the organization can afford, govern, and maintain the workflow after the demo ends.
Engineering leadershipWere you represented correctly before the click existed?
As AI interfaces mediate discovery, companies need to optimize for machine interpretation, not only human landing pages. Vague structure becomes a distribution bug.
Operator takeAI is not killing content. It is killing plausible vagueness.
In a saturated market, generic positioning dies first. The only thing that still travels is a point of view with mechanism, context, and scar tissue in it.
PositioningYou know AI has escaped the demo when the network team starts complaining.
A technology becomes an operating reality when it changes traffic shape, permissions, and observability before it changes the org chart. Infrastructure symptoms are more honest than launch narratives.
Platform engineeringThe most dangerous part of an AI stack is rarely the model.
Repo workflows, tokens, plugins, post-login trust, and integration boundaries are where systems reveal whether they were built to be demoed or built to survive. Security is architecture with consequences attached.
Security architectureThe best forward-deployed people are not close to the customer. They are close to the truth.
The valuable part of forward-deployed work is not customer proximity. It is the ability to reduce ambiguity across product, architecture, and execution without hiding behind any one function.
Engineering leadershipThe most important layer in a modern product is often the one the user never notices.
As software becomes more agentic, value shifts from the polished interface to the structured artifact layer underneath — the thing humans and systems can inspect, update, validate, and reuse.
Systems designAI makes management a choice again, not the default path to influence.
For years “more impact” quietly meant “more people reporting to you.” AI raises the value of high-judgment operators who move work end to end, so titles should follow leverage, not compensate for its absence.
Engineering leadershipMost teams have an ambiguity problem, not an AI problem.
AI exposes weak ownership and vague execution faster than it fixes them — which is useful, and is not the same thing as acceleration.
Engineering leadershipMost AI reorganizations are not about speed. They are confessions.
When a company redraws the org chart around AI, it is usually admitting the previous decision model can no longer carry the coordination load. The org chart changes after the operating model has already started failing.
Org designBig technical failures begin with silence.
The flaw is usually visible early, but the schedule is louder — and a team that cannot say 'this will break' in time is financing a later crisis with interest.
Engineering leadershipTokenization will not stall because the idea is weak. It will stall where trust changes hands.
In financial systems the hardest part of the next wave is not issuance or settlement logic. It is designing the trust boundary around action, custody, and liability — adoption fails on trust choreography, not thesis.
FintechOversight the caller installs is oversight the caller can omit.
A founder selling AI governance software promised personal review, then his own automation ran straight past it — the same failure behind the agent incidents that made the news.
AI governance