<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Stephen Lincoln</title>
    <description>The latest articles on DEV Community by Stephen Lincoln (@stephen_lincol_dd48ddb8ab).</description>
    <link>https://dev.to/stephen_lincol_dd48ddb8ab</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4116893%2F1e024f63-e1f8-4153-b4cc-6001d3025efd.png</url>
      <title>DEV Community: Stephen Lincoln</title>
      <link>https://dev.to/stephen_lincol_dd48ddb8ab</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/stephen_lincol_dd48ddb8ab"/>
    <language>en</language>
    <item>
      <title>The AI Race Is Accelerating .But Are We Building Trust at the Same Speed</title>
      <dc:creator>Stephen Lincoln</dc:creator>
      <pubDate>Sun, 27 Sep 2026 17:48:37 +0000</pubDate>
      <link>https://dev.to/stephen_lincol_dd48ddb8ab/the-ai-race-is-accelerating-but-are-we-building-trust-at-the-same-speed-18j4</link>
      <guid>https://dev.to/stephen_lincol_dd48ddb8ab/the-ai-race-is-accelerating-but-are-we-building-trust-at-the-same-speed-18j4</guid>
      <description>&lt;p&gt;The AI Race Is Accelerating. But Are We Building Trust at the Same Speed?&lt;/p&gt;

&lt;p&gt;Every month, AI becomes more powerful.&lt;/p&gt;

&lt;p&gt;Models are reasoning better.&lt;/p&gt;

&lt;p&gt;Agents are becoming autonomous.&lt;/p&gt;

&lt;p&gt;Organizations are beginning to let AI interact directly with production systems.&lt;/p&gt;

&lt;p&gt;But as AI capabilities grow, so do the challenges.&lt;/p&gt;

&lt;p&gt;We've already seen organizations deal with:&lt;/p&gt;

&lt;p&gt;• AI hallucinations leading to costly mistakes.&lt;br&gt;
• Prompt injection and security attacks.&lt;br&gt;
• AI agents entering unintended execution loops that waste compute and resources.&lt;br&gt;
• Unauthorized or risky actions performed through connected tools.&lt;br&gt;
• Enterprises struggling to understand what their AI systems are actually doing before something goes wrong.&lt;/p&gt;

&lt;p&gt;The industry is asking:&lt;/p&gt;

&lt;p&gt;"How do we build smarter AI?"&lt;/p&gt;

&lt;p&gt;I'm asking a different question.&lt;/p&gt;

&lt;p&gt;"How do we build AI that organizations can trust to act?"&lt;/p&gt;

&lt;p&gt;Introducing Ex&lt;/p&gt;

&lt;p&gt;I'm a non-technical founder exploring an idea called Ex.&lt;/p&gt;

&lt;p&gt;Ex isn't another AI model.&lt;/p&gt;

&lt;p&gt;It isn't another chatbot.&lt;/p&gt;

&lt;p&gt;It isn't another agent framework.&lt;/p&gt;

&lt;p&gt;The vision is for Ex to become an AI Execution Governance Platform—a trust layer that sits between AI agents and the real world.&lt;/p&gt;

&lt;p&gt;Instead of allowing every AI action to execute immediately, Ex evaluates high-impact actions before they happen.&lt;/p&gt;

&lt;p&gt;Think of it like an airport security checkpoint—but for AI actions.&lt;/p&gt;

&lt;p&gt;Without exposing proprietary implementation details, the idea is built around principles such as:&lt;/p&gt;

&lt;p&gt;Evaluating execution requests before they reach production systems.&lt;br&gt;
Enforcing organization-defined policies.&lt;br&gt;
Assigning risk levels to sensitive actions.&lt;br&gt;
Supporting human approval for high-impact operations.&lt;br&gt;
Creating clear audit trails for accountability.&lt;/p&gt;

&lt;p&gt;The goal isn't to make AI smarter.&lt;/p&gt;

&lt;p&gt;The goal is to make autonomous AI more trustworthy.&lt;/p&gt;

&lt;p&gt;I'd love your thoughts.&lt;/p&gt;

&lt;p&gt;Do you believe AI will eventually need a universal execution governance layer, or will every organization continue building its own governance systems?&lt;/p&gt;

&lt;p&gt;Could something like Ex become part of the standard infrastructure for autonomous AI?&lt;/p&gt;

&lt;p&gt;Live Demo&lt;/p&gt;

&lt;p&gt;I'd appreciate any honest feedback on the current MVP:&lt;/p&gt;

&lt;p&gt;Ex Live Demo&lt;/p&gt;

&lt;p&gt;It's still early, and I'm actively learning from the community.&lt;/p&gt;

&lt;p&gt;Looking for a Long-Term Builder&lt;/p&gt;

&lt;p&gt;I'm also looking for someone who believes this problem is worth solving.&lt;/p&gt;

&lt;p&gt;Not just another startup.&lt;/p&gt;

&lt;p&gt;A long-term mission.&lt;/p&gt;

&lt;p&gt;I'm a non-technical founder, and I'm looking for an engineer, researcher, or technical co-founder who believes the future of AI isn't only about making models more intelligent—but also about making them more trustworthy.&lt;/p&gt;

&lt;p&gt;You don't have to agree with my approach.&lt;/p&gt;

&lt;p&gt;In fact, I'd love to hear a different one.&lt;/p&gt;

&lt;p&gt;If you believe AI governance is one of the defining infrastructure challenges of the next decade, let's talk.&lt;/p&gt;

&lt;p&gt;Maybe together we can build something that helps shape the future of autonomous AI.&lt;/p&gt;

&lt;p&gt;Question for the community:&lt;/p&gt;

&lt;p&gt;If you had to design the trust layer between AI and the real world, what would it absolutely need to do?&lt;/p&gt;

</description>
    </item>
    <item>
      <title>The World Is Building Smarter AI. Who's Building the Layer That Makes It Safe to Act?</title>
      <dc:creator>Stephen Lincoln</dc:creator>
      <pubDate>Sun, 20 Sep 2026 20:14:39 +0000</pubDate>
      <link>https://dev.to/stephen_lincol_dd48ddb8ab/the-world-is-building-smarter-ai-whos-building-the-layer-that-makes-it-safe-to-act-inc</link>
      <guid>https://dev.to/stephen_lincol_dd48ddb8ab/the-world-is-building-smarter-ai-whos-building-the-layer-that-makes-it-safe-to-act-inc</guid>
      <description>&lt;p&gt;The AI industry is moving incredibly fast.&lt;/p&gt;

&lt;p&gt;Every week we see better models, more capable agents, and new tools that automate increasingly complex work.&lt;/p&gt;

&lt;p&gt;But the more I study autonomous AI, the more I keep coming back to one question:&lt;/p&gt;

&lt;p&gt;Who governs AI once it starts taking real-world actions?&lt;/p&gt;

&lt;p&gt;Not generating text.&lt;/p&gt;

&lt;p&gt;Not answering questions.&lt;/p&gt;

&lt;p&gt;Actually acting.&lt;/p&gt;

&lt;p&gt;Imagine an AI agent that can:&lt;/p&gt;

&lt;p&gt;approve a payment&lt;br&gt;
deploy production infrastructure&lt;br&gt;
modify cloud resources&lt;br&gt;
access sensitive customer data&lt;br&gt;
control physical systems&lt;/p&gt;

&lt;p&gt;Most discussions today focus on making AI more capable.&lt;/p&gt;

&lt;p&gt;I'm interested in something different:&lt;/p&gt;

&lt;p&gt;How do we make AI trustworthy enough for enterprises to let it act?&lt;/p&gt;

&lt;p&gt;That's the idea behind something I'm exploring called Ex.&lt;/p&gt;

&lt;p&gt;The vision is simple:&lt;/p&gt;

&lt;p&gt;Create a trust layer between AI and the real world.&lt;/p&gt;

&lt;p&gt;A place where every high-impact AI action can be evaluated against policy before execution.&lt;/p&gt;

&lt;p&gt;I'm still researching this problem, and I'd genuinely love to hear from engineers building AI systems today.&lt;/p&gt;

&lt;p&gt;I'm curious:&lt;br&gt;
What AI failures have you experienced in production?&lt;br&gt;
Have you had to build your own approval or governance system?&lt;br&gt;
What's the biggest problem your AI agents create today?&lt;br&gt;
What do you wish existed that doesn't?&lt;/p&gt;

&lt;p&gt;I'm not looking for validation.&lt;/p&gt;

&lt;p&gt;I'm looking for reality.&lt;/p&gt;

&lt;p&gt;If the problem isn't real, I'd rather learn now.&lt;/p&gt;

&lt;p&gt;If it is real, I think it deserves serious attention.&lt;/p&gt;

&lt;p&gt;A second reason I'm posting this&lt;/p&gt;

&lt;p&gt;I'm also interested in meeting people who think long-term.&lt;/p&gt;

&lt;p&gt;Not people chasing the next AI trend.&lt;/p&gt;

&lt;p&gt;People who believe the next decade of AI will require entirely new infrastructure around governance, trust, and execution.&lt;/p&gt;

&lt;p&gt;If that sounds like how you think, I'd genuinely enjoy talking.&lt;/p&gt;

&lt;p&gt;Whether you're an engineer, researcher, security specialist, product builder, or potential co-founder, feel free to reach out.&lt;/p&gt;

&lt;p&gt;Sometimes the best companies begin with a conversation.&lt;/p&gt;

</description>
    </item>
    <item>
      <title>The Missing Layer Between AI and the Real World</title>
      <dc:creator>Stephen Lincoln</dc:creator>
      <pubDate>Sat, 19 Sep 2026 19:28:25 +0000</pubDate>
      <link>https://dev.to/stephen_lincol_dd48ddb8ab/the-missing-layer-between-ai-and-the-real-world-4b4l</link>
      <guid>https://dev.to/stephen_lincol_dd48ddb8ab/the-missing-layer-between-ai-and-the-real-world-4b4l</guid>
      <description>&lt;p&gt;"The Missing Layer Between AI and the Real World." Over the past few months, I've noticed something The AI industry is racing to build models that are smarter, faster, more autonomous.&lt;/p&gt;

&lt;p&gt;But, we talk less about what happens after an AI decides&lt;br&gt;
to act. Not what it writes or answers, but when it deploys infrastructure, moves money, accesses sensitive data, or interacts with the real world. I'm wondering if there's a missing execution layer between an AI's decision and the action itself. So, before building anything, I'd love to talk with AI engineers, researchers, MLOps, security folks. What's the biggest failure you've seen in production? What safety checks did you have to build yourself? I'm not selling. I'm listening, trying to see whether there's a real need for the layer that ex envisions.&lt;/p&gt;

</description>
      <category>agents</category>
      <category>ai</category>
      <category>production</category>
      <category>security</category>
    </item>
    <item>
      <title>The Missing Layer Between AI and the Real World</title>
      <dc:creator>Stephen Lincoln</dc:creator>
      <pubDate>Thu, 10 Sep 2026 18:48:34 +0000</pubDate>
      <link>https://dev.to/stephen_lincol_dd48ddb8ab/the-missing-layer-between-ai-and-the-real-world-n0c</link>
      <guid>https://dev.to/stephen_lincol_dd48ddb8ab/the-missing-layer-between-ai-and-the-real-world-n0c</guid>
      <description>&lt;p&gt;We're Measuring the Wrong Thing in AI Agents&lt;/p&gt;

&lt;p&gt;Everyone seems focused on making AI agents smarter.&lt;/p&gt;

&lt;p&gt;Bigger models.&lt;/p&gt;

&lt;p&gt;Longer context windows.&lt;/p&gt;

&lt;p&gt;Better reasoning.&lt;/p&gt;

&lt;p&gt;More tools.&lt;/p&gt;

&lt;p&gt;More autonomy.&lt;/p&gt;

&lt;p&gt;Those things matter.&lt;/p&gt;

&lt;p&gt;But I think we're overlooking a different question.&lt;/p&gt;

&lt;p&gt;What happens after the AI decides to act?&lt;/p&gt;

&lt;p&gt;Imagine an AI agent with permission to:&lt;/p&gt;

&lt;p&gt;deploy infrastructure&lt;br&gt;
approve refunds&lt;br&gt;
query production databases&lt;br&gt;
purchase inventory&lt;br&gt;
update customer records&lt;br&gt;
modify firewall rules&lt;/p&gt;

&lt;p&gt;The challenge isn't whether the AI can perform these actions.&lt;/p&gt;

&lt;p&gt;The challenge is whether it should perform them.&lt;/p&gt;

&lt;p&gt;Most production systems already answer questions like:&lt;/p&gt;

&lt;p&gt;Is this user authenticated?&lt;br&gt;
Is this API key valid?&lt;br&gt;
Does this service have permission?&lt;/p&gt;

&lt;p&gt;Those are identity questions.&lt;/p&gt;

&lt;p&gt;Autonomous AI introduces a different class of question:&lt;/p&gt;

&lt;p&gt;Should this specific action be allowed under these specific circumstances?&lt;/p&gt;

&lt;p&gt;Those aren't the same problem.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;An AI wants to refund $8,500 to a customer.&lt;/p&gt;

&lt;p&gt;Authentication succeeds.&lt;/p&gt;

&lt;p&gt;The API key is valid.&lt;/p&gt;

&lt;p&gt;The agent has permission to call Stripe.&lt;/p&gt;

&lt;p&gt;Should the refund execute automatically?&lt;/p&gt;

&lt;p&gt;Maybe.&lt;/p&gt;

&lt;p&gt;Maybe not.&lt;/p&gt;

&lt;p&gt;It depends on context.&lt;/p&gt;

&lt;p&gt;Is this production or staging?&lt;br&gt;
Is this a VIP customer?&lt;br&gt;
Has fraud been detected?&lt;br&gt;
Has a human approved refunds above $5,000?&lt;br&gt;
Is another agent already processing the same request?&lt;/p&gt;

&lt;p&gt;None of those questions are answered by authentication alone.&lt;/p&gt;

&lt;p&gt;I think we're moving toward a new architectural pattern:&lt;/p&gt;

&lt;p&gt;Intent&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;Policy Decision&lt;/p&gt;

&lt;p&gt;↓&lt;/p&gt;

&lt;p&gt;Execution&lt;/p&gt;

&lt;p&gt;Instead of allowing AI agents to directly change the real world, every high-impact action crosses a governance boundary first.&lt;/p&gt;

&lt;p&gt;Not because we don't trust AI.&lt;/p&gt;

&lt;p&gt;Because we need systems that businesses can trust.&lt;/p&gt;

&lt;p&gt;I've been exploring this idea through a project called Ex.&lt;/p&gt;

&lt;p&gt;The vision isn't to replace AI frameworks or build another agent platform.&lt;/p&gt;

&lt;p&gt;It's to explore whether autonomous AI needs a dedicated execution governance layer that sits between agents and real-world consequences.&lt;/p&gt;

&lt;p&gt;Think less about making AI more intelligent.&lt;/p&gt;

&lt;p&gt;Think more about making AI safe to operate at enterprise scale.&lt;/p&gt;

&lt;p&gt;I'm curious how engineers are thinking about this.&lt;/p&gt;

&lt;p&gt;If you were designing AI infrastructure for the next decade:&lt;/p&gt;

&lt;p&gt;Where would you enforce trust?&lt;/p&gt;

&lt;p&gt;Inside the model?&lt;br&gt;
Inside every agent?&lt;br&gt;
At the tool/function-call layer?&lt;br&gt;
In middleware?&lt;br&gt;
As a centralized execution control plane?&lt;/p&gt;

&lt;p&gt;I'd love to hear different perspectives.&lt;/p&gt;

&lt;h1&gt;
  
  
  ai #agents #softwareengineering #architecture #devops #security #opensource #machinelearning
&lt;/h1&gt;

</description>
      <category>agents</category>
      <category>ai</category>
      <category>architecture</category>
      <category>security</category>
    </item>
    <item>
      <title>Shadow Agent Problem</title>
      <dc:creator>Stephen Lincoln</dc:creator>
      <pubDate>Wed, 09 Sep 2026 06:33:52 +0000</pubDate>
      <link>https://dev.to/stephen_lincol_dd48ddb8ab/shadow-agent-problem-44cn</link>
      <guid>https://dev.to/stephen_lincol_dd48ddb8ab/shadow-agent-problem-44cn</guid>
      <description>&lt;h2&gt;
  
  
  The Shadow Agent Problem
&lt;/h2&gt;

&lt;p&gt;We've spent years securing who can access our systems.&lt;/p&gt;

&lt;p&gt;The next challenge is governing what autonomous AI is allowed to do once it has access.&lt;/p&gt;

&lt;p&gt;Imagine this:&lt;/p&gt;

&lt;p&gt;A developer creates an AI agent using a personal API key, connects it to internal tools, and gives it permission to read customer data, call internal APIs, deploy code, or trigger business workflows.&lt;/p&gt;

&lt;p&gt;No procurement process.&lt;/p&gt;

&lt;p&gt;No centralized registration.&lt;/p&gt;

&lt;p&gt;No security review.&lt;/p&gt;

&lt;p&gt;The agent authenticates successfully and starts taking actions.&lt;/p&gt;

&lt;p&gt;This is what I think of as the Shadow Agent Problem.&lt;/p&gt;

&lt;p&gt;It's similar to the Shadow IT and Shadow SaaS challenges enterprises faced years ago—but with one critical difference:&lt;/p&gt;

&lt;p&gt;AI agents don't just access information. They act on it.&lt;/p&gt;

&lt;p&gt;They can initiate payments, modify infrastructure, interact with production systems, and automate decisions at machine speed.&lt;/p&gt;

&lt;p&gt;That's why traditional controls aren't always enough.&lt;/p&gt;

&lt;p&gt;Identity, procurement, and access management remain essential, but they primarily answer:&lt;/p&gt;

&lt;p&gt;"Who is allowed to connect?"&lt;/p&gt;

&lt;p&gt;They don't necessarily answer:&lt;/p&gt;

&lt;p&gt;"Should this specific action be allowed to happen right now?"&lt;/p&gt;

&lt;p&gt;I believe governance needs to exist at the execution layer.&lt;/p&gt;

&lt;p&gt;Instead of evaluating only the identity of the agent, evaluate the action itself before it reaches the real world.&lt;/p&gt;

&lt;p&gt;For example:&lt;/p&gt;

&lt;p&gt;Should this payment be approved?&lt;br&gt;
Should this deployment proceed?&lt;br&gt;
Should this API call be allowed?&lt;br&gt;
Should this database query execute?&lt;br&gt;
Should this infrastructure change be blocked?&lt;/p&gt;

&lt;p&gt;Every high-impact action becomes a policy decision.&lt;/p&gt;

&lt;p&gt;Not after execution.&lt;/p&gt;

&lt;p&gt;Before execution.&lt;/p&gt;

&lt;p&gt;A possible architecture could include:&lt;/p&gt;

&lt;p&gt;A policy engine that evaluates every high-impact action against organizational rules.&lt;br&gt;
Approval workflows for sensitive operations.&lt;br&gt;
A complete audit trail explaining what was attempted, why it was approved or rejected, and under which policy.&lt;br&gt;
Real-time interception before external systems are affected.&lt;/p&gt;

&lt;p&gt;One advantage of this model is that it doesn't require security teams to know about every AI agent in advance.&lt;/p&gt;

&lt;p&gt;Instead of trying to catalog every possible agent, you govern the actions they perform.&lt;/p&gt;

&lt;p&gt;As autonomous AI becomes more common inside enterprises, I think this architectural pattern will become increasingly important.&lt;/p&gt;

&lt;p&gt;I'm curious how others are approaching this problem.&lt;/p&gt;

&lt;p&gt;Are you enforcing governance at the tool/function-call layer?&lt;br&gt;
Using policy engines like OPA?&lt;br&gt;
Building middleware around agent frameworks?&lt;br&gt;
Or taking a completely different approach?&lt;/p&gt;

&lt;p&gt;I'd love to hear how you're thinking about execution governance for AI agents.&lt;/p&gt;

</description>
      <category>agents</category>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>security</category>
    </item>
  </channel>
</rss>
