Ship Happens

Don’t Let AI Go Rogue: Human Governance for Agentic Systems

Episode Summary

As AI systems become more capable of reasoning, using tools, accessing data, and taking action on their own, a new question is becoming impossible to ignore: how much autonomy should we actually give them? In this episode of Ship Happens, host Per Krogslund sits down with Justin Kuiper, Lead Architect at Future Tech, to explore the security and governance challenges of agentic AI—and what engineers can do to keep increasingly autonomous systems within safe and understandable boundaries.

Episode Notes

As AI systems become more capable of reasoning, using tools, accessing data, and taking action on their own, a new question is becoming impossible to ignore: how much autonomy should we actually give them?

In this episode of Ship Happens, host Per Krogslund sits down with Justin Kuiper, Lead Architect at Future Tech, to explore the security and governance challenges of agentic AI—and what engineers can do to keep increasingly autonomous systems within safe and understandable boundaries.

With a background in Air Force space operations and cybersecurity, Justin brings lessons from mission-critical systems to the rapidly evolving world of AI. He explains how different environments prioritize availability, confidentiality, and mission assurance, and why those tradeoffs become even more important when software can make decisions and take actions with real-world consequences.

Per and Justin dig into the importance of human governance, least privilege, agent identity, observability, break-glass controls, and specification engineering. They explore the risk of “confident misalignment”—when an AI system confidently pursues an outcome that isn't actually what its human operators intended—and why giving agents more capability doesn't mean giving them unlimited authority.

The conversation also looks at AI in space, data sovereignty, model selection, token economics, and the emerging challenge of securing entire agent ecosystems rather than individual applications.

The practical message for builders is clear: define what your agents are allowed to do, know who is responsible for their actions, constrain their access, observe what they're doing, document the system, and keep humans in control when the stakes are high.

Because autonomous software can move fast. Your governance needs to move with it.

What You’ll Learn

Episode Chapters

00:00 — Satan in the Workflow
01:25 — Meet Justin Kuiper
03:22 — Securing Software in Space
06:06 — AI Security and Black Boxes
11:33 — Human Governance for Agents
13:51 — Least Privilege for Tools
16:03 — Agent Identity and Accountability
17:27 — Agents in Production Workflows
19:55 — Confident Misalignment Risks
20:52 — Accountability for AI Weapons
22:12 — Technology That Explores
22:38 — Balancing Human Control
24:05 — Losing Institutional Know-How
26:19 — Specification Engineering Guardrails
26:52 — AI in Space: The Timeline
27:44 — Model Choices and Sovereignty
28:44 — Tokenomics and the Data Mesh
30:31 — Securing Agent Ecosystems
34:31 — The Monday Morning Playbook
37:56 — Avoiding Overengineering
40:03 — Trust in Autonomous Software
41:10 — Closing Thanks

Key Takeaways

Autonomy Needs Boundaries

Giving an AI agent the ability to act independently doesn't mean giving it unlimited authority. Engineers need to define the systems, data, tools, and decisions an agent can access—and where human approval is required.

Humans Still Own the Governance

The more autonomous software becomes, the more important it is to establish clear responsibility. Someone needs to understand what the system is designed to do, what constraints are in place, and who is accountable when it behaves unexpectedly.

Least Privilege Should Apply to AI

Agents shouldn't automatically receive broad access simply because they might need it someday. Limiting an agent's permissions to the minimum required for its task can reduce the potential impact of a compromised or misbehaving system.

Agent Identity Matters

If an agent can take actions independently, those actions need to be attributable. Identity allows organizations to understand which agent acted, what it was authorized to do, and where responsibility ultimately sits.

Watch the Workflow

Individual components can appear secure while the interactions between them introduce unexpected risks. As agents move between applications, APIs, data sources, and tools, understanding the entire workflow becomes critical.

Watch for Confident Misalignment

One of the biggest risks isn't necessarily an AI that refuses to work. It's an AI that confidently does the wrong thing because its interpretation of the objective differs from what its human operator actually intended.

Build for Failure

In high-consequence environments, systems need a safe way to stop. Break-glass controls, escalation paths, observability, and fail-closed behavior can provide critical safeguards when an autonomous system reaches the limits of its authority.

About Justin Kuiper

Justin Kuiper is a Lead Architect at Future Tech with a background in Air Force space operations and cybersecurity. His experience working with complex, mission-critical systems gives him a unique perspective on the challenges of securing increasingly autonomous technology.

In this episode, Justin connects lessons from space systems and cybersecurity with the emerging world of agentic AI, exploring how engineers can build systems that are not only capable, but also constrained, observable, and accountable.

Resources & Links

Episode Transcription


 

Justin Kuiper: [00:00:00] I have a saying that I tell my folks and the devil is in the details, right? But Satan lives in the workflow. That middle layer, that middle space, that ag- that wor- that machine to machine, agentics calling on agentics kind of thing, is the next, that, that orchestration layer, that's the next frontier and that's really what's gonna be the game changer.

Justin Kuiper: The truth is, Per, that you don't want a machine ever making the decision of whether that human is a threat or not. You don't. And because that's when stuff gets starts, or whether that, or who I should save in a crisis, right? Those kind of things. That's the kind of stuff that always needs to be with mankind and I

Justin Kuiper: And that's the part where when I'm speaking about confident misalignment, I'm really speaking about something in our culture that wants to give our job away and just, "Let's go sit on the beach." And the truth is, that's the, that's where we start getting in the dangerous territory. We need to allow for our, ourselves to pull out of the, in a, from an obs- [00:01:00] observability point of view where we're not, we don't have our hands in the dirt quite as much, but we need to have that space where we do understand how things get from point A to Z.

Justin Kuiper: And that's the diffi- that's a difficult balance, Per.

Per Krogslund: Welcome to, to Ship Happens, a podcast by Docker where I sit down with, like, really smart people, people who are more smart than me, to talk about what is the big challenges and what are the big interesting things in the IT industry now that we have AI and we need to think about software development and, well, applications in a whole new way.

Per Krogslund: I have Justin Kuiper with me. He has a super interesting background in aerospace, space and defense, security background, and I'm gonna let you, Justin, introduce yourself a bit more than I can do. So, thank you for being here. 

Justin Kuiper: Yeah, thanks, Per. Yeah, my name is Justin. I currently work as the lead, basically the lead [00:02:00] architect for Future Tech in their out-facing product solution building systems.

Justin Kuiper: We primarily market and supply the federal DIB, the Defense Industry, Industry Bases, uh, the DIB in both the United States and abroad. My background is I spent two decades in the Air Force as a space o- my a- I ended up as a space operations officer. I started as a E3 and then eventually ended up in space operations, which is a fascinating field.

Justin Kuiper: It was, I basically saw the Air Force switch to the Space Force and did some kind of things in that. And also on the other side, my civilian career, I've spent time in most of the, doing cybersecurity, cybersecurity engineering and safe- Agile Scrum practices for some of the major contractors and some of the ma- major space providers.

Justin Kuiper: My last job before this one at Future Tech was I was the director of engineering, uh, cybersecurity engineering for [00:03:00] their, for their Agile Scrum teams. Yeah, this is right in my... When they asked me about this podcast and I knew about it, I said, "Man, that's my, that's my dojo. I can't wait to talk to-" 

Per Krogslund: Oh, perfect.

Per Krogslund: That's great. I'm super happy to have you here. I, I have a lot of questions, especially on space. I don't think I've ever talked about, talked to anyone before who did, especially in the space sector, because again, I don't think there's l- that many of you especially. I think what is... Before we go into talking about AI, like what is, what is different about like securing software for, for space use?

Justin Kuiper: Why don't you take a toaster and then put, make it in the '60s and then try and put some f- flip-flops in there, some processing in there, and then try and secure it from all the bad guys. Space is very different. A lot of the, when you talk specifically, my background's with NASA and some of the DOD stuff.

Justin Kuiper: When you talk specifically about NASA, they have a very interesting philosophy. In, in military and in commercial, you have, you have this job that you've gotta do. You've gotta keep things confidential, you gotta keep things, [00:04:00] you gotta keep things available, and then you gotta keep non-repudiation where people can't pretend to be someone else, right?

Justin Kuiper: And in the case of, in the case of space, their priority is different than the military. The priority in the military is confidentiality, of course. You wanna keep bad guys from knowing your secrets. In the case of NASA, though, the availability is the key, making sure that you can get, make sure that you have integrity of signal and your humans that you have up there are safe.

Justin Kuiper: And that makes a lot of sense, but it, it al- you also see that in the architecture because they, if something's old and trusted with tubes, it, you're, that's what you're gonna do, or you're just gonna use that kind of stuff. So the problem in securing that space in a lot of cases is taking legacy and protecting it from modern type approaches, which is sometimes easier, believe it or not, because there's less of an attack surface, and sometimes it's more difficult because there's just, it just doesn't have any way to kind of stop or authenticate or something like that, right?

Per Krogslund: Yeah. So simpler but old system is often easier than like a large [00:05:00] complex, like modern system. 

Justin Kuiper: It is simpler and harder all at the same time, and I, I mean that in a, in a completely confusing way. I apologize I can't say it any other way. But there's just, it's just a, the OS's are old. They're probably open source.

Justin Kuiper: The, something like Docker is not, was not even considered a possibility back in those days, so yeah. 

Per Krogslund: Yeah. I know that, I think it is, I think it's the B-2 bomber that runs Kubernetes and Docker today, so I think we, we are getting there, but still, the B-2 is like a very modern- 

Justin Kuiper: I can't confirm or deny that, but I'm sure there are things that happen Look, the n- the nat- look, we have got as a, just as a, just in the Western culture in general, we have got to get faster and better at our cyber operations, both in, in vehicular, inside an airplane, and in space, and all those kind of things.

Justin Kuiper: And Docker, those kind of things, the, the new methodologies are the way that you're gonna get there. So yes, there are some things that do that. [00:06:00] I don't, I haven't worked on the B2, but I do know there's definitely an approach to modernization in those spaces. 

Per Krogslund: So given the things you've learned from, you can say, defense and aspa- uh, aerospace and space itself, like what are the, what does that experience teach you about securing AI systems?

Justin Kuiper: It's all about the black box, right? The w- I've been doing a lot of work in that area. When, when the first couple of my executives came to me and said, "Hey, we wanna start using AI." For any cyber guy, there's like this part, there's this muscle inside you that just cramps 'cause you're like, "Oh, I can't see inside that."

Justin Kuiper: But the more you study it, really there's, I think there's three things you have to keep in mind. One is you've got to constrain it properly from a physical boundary. If you remember one of the first Transformer movies, I think it was in the early 2000s. I can't believe we're actually saying that now, the early 2000s like it's a thing.

Justin Kuiper: But there's a part where Megatron's bad forces are trying to take over this TEOC in the middle of the E- in the middle of the Middle East or whatever, and the [00:07:00] colonel runs back to where he grabs an ax and he runs back to the D mark and he starts cranking down at it with the ax because that's the only way that he could stop that kind of hack.

Justin Kuiper: And I look at that example and that's exactly the kind of thing that we have to do nowadays. So we have to do a little bit of trench warfare, right? We have to make sure that we secure the physical boundaries, right? And that there's, it's, and we have complete obs- And then we need to, but we also need to give space for the AI to work agentically and infer properly, right?

Justin Kuiper: So you can't kill the golden goose, right? It does... Agentic AI is a force multiplier. Just in my case alone, I set up just, I did a test. I did a Scrum team on my own. I ran my own Scrum. I was talking to myself the whole time. I had seven personas. Half of them had German names. I don't know why. They just, I just had this thing going.

Justin Kuiper: And I t- I did a velocity test against some feature sets that I was doing, and I was 80% faster than the, than the [00:08:00] Gartner kind of velocity records for what I was doing. Meaningless stat. Meaningless stat. But the point is, is that if you know how to run those kind of things, you can do it. So it's a force multiplier.

Justin Kuiper: But you've got to control three things in it, right? This is the other part. So you got to k- secure your boundary, that's one. The other thing is you have to maintain a different set of information than I'm used to, right? This is the thing I learned first of all, it's semantic context and intent horizon.

Justin Kuiper: That's the third thing. So in other words, how many times do you go up to your AI and you say, "I want this," and it goes, "Okay, I'll give you that." And it- Yeah ... and it gives it something and it's not, the context is off, right? And you go, "No, I'm wa- " And then you end up wasting time going back and forth. So when you build these big prompts and these master prompts, you are heavily focusing on Context, right?

Justin Kuiper: And so that intent horizon, your intent, your curation of what you need in comparison with what the AI can execute is the straight line critical path that you have to maintain. Those are the three things you [00:09:00] have to do. That's the unique part about AI. The rest of it's table stakes. The rest of it's securing underneath and all that kind of stuff.

Justin Kuiper: But if you can do those three things, I think you've got a really good shot of having a pretty decent secure system. 

Per Krogslund: So you're not worried that we might be going in the direction that we are giving software more authority than we might be currently capable of securing? 

Justin Kuiper: If not, I- it's that... Oh, let me tell you, Per, that is absolutely gonna happen.

Justin Kuiper: Like peop- somebody's gonna do it. Somebody's gonna go, "Let's just turn this thing on and see what happens." That's absolutely gonna happen. I'm, I'm less worried that it'll function correctly. I don't think... I've just noticed in the patterns of how we work nowadays and how we code, just in general, just let's talk about coding.

Justin Kuiper: I am constantly with my systems having to reinforce and put touch points between me and Gunther. Gunther is the name of my, my taskmaster. I, again, I don't know why I like it. Good, 

Per Krogslund: good German name. Yeah. 

Justin Kuiper: Thank you. He's, he's, he's [00:10:00] very, he's very strict. But anyway, Gunther and I constantly have to say, "Okay," I have to say, "Now this is what I want.

Justin Kuiper: Now reflect back to me, what do you think you're building me? What, what are you building me?" "I think I'm building you this." Okay. It's kinda like that. And then I have to build up this GitHub structure based on, on issues that have this root issue that show, basically do spec engineering in the root issue.

Justin Kuiper: It shows from, I want it to go from here to here, and it shows the workflow, and then Gunther starts to fill in the cracks, fill in the blanks based on those things. I spend most of the time doing that, and y- I'm thinking to myself, I ha- somebody asked me the same question. They said, "Don't you think AI is gonna replace my jobs, my job?"

Justin Kuiper: And I thought to myself, "If it's gonna replace my job, then why am I working so hard just to get it to do what I want, right?" So I'm not really worried as long as you don't treat it like a Pandora's box, right? So as long as you don't open it, not caring about whatever the consequences are. You, you, you...

Justin Kuiper: It's, it's plutonium [00:11:00] It's powerful, but you have to respect both the, the, the things. The OpenAI, uh, the OpenAI, believe me, it feels like somebody just wanted to see what would happen, honestly. It, the, an AI doesn't have context for boundaries, right? It just has the boundaries you give it. And so that's why that intent horizon and that control and that human governance is so important.

Justin Kuiper: So yes, it could happen, but I'm not that, I'm not as worried about it because I'm used to taking constraint over powerful things, if that makes sense. 

Per Krogslund: Yeah, that makes sense. That makes a lot of sense. So you mentioned both, like, big part of your job is, like, giving guidelines to these agents about how to do things, but you also mentioned human governance.

Per Krogslund: So what's the, what's the technical difference between these two? Because I've seen the industry basically model these two things together, that you have, you give them guidelines, but they can break them, and then you have governance, which is something totally different. 

Justin Kuiper: So I think the governance, uh, so I've wrote a white paper on human governance, and in fact, we at FutureTech are using it to build a [00:12:00] lot of, to architect a lot of pro- our products.

Justin Kuiper: So think of it practically this way, and think about if you, like, how we would work this out is the only thing that you maintain that you should, you should allow an AI to engineer and create, but you are the creative piece, and you are the tether to reality. In a sense, I know this sound a little bit frou-frou or whatever, mystic, but in a sense, it gets all its information of how things work existentially through, through you, right?

Justin Kuiper: So you have to, because you're giving it, the most important thing is context, a semantic context, right? And so the, the point that I'm making is that when you, what, you've got to sit in that role and make sure that whenever you do a project with it and recode, that the s- the system engineering part, the part where you are, where you are defining the specifications and constraints, you have to make those hard set.

Justin Kuiper: So in other words, one of the things that I do, just to say, you just [00:13:00] said it can break the rules. I don't let it If it does, I'm watching. I have a visibility point where it comes over, and I have a break glass option where I could just kill the, the tokens and it can't get over there again. Or I build it across some kind of physical do- domain, like a ethernet something, or I, I physically separate something or something like that.

Justin Kuiper: That's the only way that you can truly control it. So you do... Again, but I don't let it play there. It, it has... As long as it's doing what it's supposed to be doing, it's in the happy space and it can, it has access to all the resources it needs. I just keep the boundary, I, I just keep aro- the hard boundaries around the side.

Justin Kuiper: Does that answer your question? 

Per Krogslund: It does, yeah. And I've, I think for a lot of developers today who are doing the same thing as you are, they're setting up the agents to do work on, they, they, they give them tools, they give them access to tools, they give them credentials, and of course they give them context and so on.

Per Krogslund: But Ryan, how, from your point of view, how would you guide a developer to how do they think about especially like tools and credential use and so on in a more secure way? 

Justin Kuiper: Yeah. [00:14:00] It's a good question. I would think about it as, it's, it's the way you would... Again, it's not such an old question, you just have to think about it from an agentic workflow.

Justin Kuiper: It's always least privilege, least access, always. And it's always least functionality. And so you, you said that it can break rules, you're right. It can promote itself into different things, but it can't necessarily elevate privilege in a system if you don't give it access to do that Right. So that's the one thing.

Justin Kuiper: So you don't all- the lateral pivoting is the way that I would do it. The way that I would do this in a focused way, be very focused, deliberate about this, is that I would go to MITRE ATT&CK or one of the threat modeling kind of standards, and I would say, "Okay, I'm an AI. I'm a bad Gunther." Right? Now how, how do I...

Justin Kuiper: How, how would I elevate myself across one of those boundaries that I just gave you? And then you deny it access to those kind of things. And then you feel you can sleep at night, 'cause you don't feel like you're making Skynet. 

Per Krogslund: Yeah. That's true, and I think it's also interesting that you're bringing up MITRE and, and these other [00:15:00] frameworks, because they have existed for the last 20 years.

Per Krogslund: These are not new. Like, a lot of the security practices that we have today is, is they are, like in the CIA Triad and so on, these are well-known, trusted, and true practices which are not going away just because you're working with AI. No. Actually, they're still true. They're more, more true than ever, actually.

Justin Kuiper: I would say they're even more important, and I would say the human visibility factor is even more important. Because as you... You know this. As you're starting to code in an agentic way, right, you're really a supervisor of a lot of agents rather than just the person hand-jamming, like drinking a lot of Mountain Dew and hand-jamming the code, right?

Justin Kuiper: And that's a good thing, but you also have to keep your eye on the horizon to make sure those things are gone. So you, you must, must... I think it's critical that you not turn a blind eye on this kind of stuff. But it's possible. You just use the same principles. You just don't allow it. You just like you wouldn't allow a new developer to come in your pl- space and start saying, "You know what?

Justin Kuiper: I don't even know what this stuff is." Start... You do the [00:16:00] same thing. You put the same constraints in, and you watch and promote appropriately. 

Per Krogslund: And I think that the last point you mentioned there with the junior developer is a really good point, and I think that's probably still like a mental exercise a lot of developers need to move towards.

Per Krogslund: They've been used to just being accountable for themselves, like, "I know what I'm doing." And but all of a sudden they are basically a manager of a team, and they need to be accountable for the team that they're running. In your case, it's Gunther and all his friends, and you, you are their manager, and you are in essence accountable for their actions.

Justin Kuiper: You are accountable. So one of the th- That's a great point you bring up, Per. One of the things I'm working on personally with Future Tech is the idea of giving agents identities in like a PKI or some kind of identity, a key. And the reason, the way that I would do that is really it would be a derivative key of a, of the, of the person, the human being that actually deployed that.

Justin Kuiper: And there's a, there's an accountability but there that, and a traceability there that is crucial It's just crucial for... We're talking about this for some of the high security stuff, [00:17:00] but in general, I think it's gonna be crucial for everything we do. There's just too many processes that run underneath and above the OS and, and interact with the OS, that if you don't have some way to track it, an AI can be doing anything.

Justin Kuiper: In a sense, it could be a polymorphic virus if you, if it were nefarious in nature, right? And that's what they do. I, I think you're, I think you're right onto something there. You gotta keep, you gotta keep the accountability to the person that's accountable. 

Per Krogslund: Yeah. So I wanted to switch into this thing of, like, agents in production.

Per Krogslund: Now we talked about you have a team, and you really look at it. You, you have, you have the human ac- accountability, but at some point we... That's already happening, right? We deploy agentic services. It's not just an agent that's running on your machine, and you're watching what it's doing. Perfect. But it's gonna be in production, right?

Per Krogslund: And it's gonna, it's gonna act based on input maybe from a user or for an API call or whatever it is, but it's gonna, it's gonna kick off some work autonomously, basically, based on some maybe external input that it gets. So what changes there, in your opinion, again, like looking at it from [00:18:00] a, like a security perspective, risk perspective, what changes once it moves from like your local agent into a production system?

Justin Kuiper: I have a saying that I tell my folks, and the devil is in the details, right? But- Satan lives in the workflow. That middle layer, that middle space, that ag- that w- that machine-to-machine, agentics calling on agentics kind of thing, is the next ... That, that orchestration layer, that's the next frontier, and that's really what's gonna be the game changer.

Justin Kuiper: When you can have, when you can take, like I can take myself and I can extend myself out to seven or eight per- and use that to code, that's great, 8% faster. But think about when you can take an organization or you can take a whole scrum team and you could, you could potentially take your 60 or 70-person scrum team and then have each person spawn those...

Justin Kuiper: Now, now you're starting to e- explode velocity, if you can track it the right way, exponentially. It's a critical thing for us to be able to do and keep up with everybody, [00:19:00] right? So it's absolutely something we need to do, so it's good, right? It's, it's, it's the next space. However, I really think that the way to do that, the consideration is for human beings to move more and more towards the governance role, like we're talking about, and be the spec engineers, the specification engineers that are doing the system engineering on this side, and then make sure that we architect the agents in that...

Justin Kuiper: Sorry, I'm doing all sorts of stuff here. In that middle space here, that we are basically taking the intent horizon, what we intend to do, measuring it to the definition of done, and pushing it through that middle layer, that workflow, to make sure with several different juncture points that the intent is being met the whole way through up until the definition of done.

Justin Kuiper: I think that's, I think the, the architecture has to be built around that kind of thing. Does that, am I hitting the answer to the question there? 

Per Krogslund: Oh, yeah, definitely. Definitely you have some very good points here, and I think this is also related because you, I think [00:20:00] some time ago you wrote about confident misalignment- Yeah

Per Krogslund: uh, which you see as, like, one of the big dangers. Could you dive a little bit more into what you mean about, like, confident misalignment? 

Justin Kuiper: The scary part about this for a lot of the military part in confident misalignment is we've seen movies about it forever, right? The sci-fi genre is big about it. But the truth is, Per, that you don't want a machine ever making the decision of whether that human is a threat or not.

Justin Kuiper: You don't. And because that's when stuff gets, starts, or whether that, or who I should save in a crisis, 

Per Krogslund: right? 

Justin Kuiper: Those kind of things. That's the kind of stuff that always needs to be with mankind, and I... And that's the part where when I'm speaking about confident misalignment, I'm really speaking about something in our culture that wants to give our job away and just, let's go sit on the beach.

Justin Kuiper: And the truth is, that's the, that's where we start getting into dangerous territory. 

Per Krogslund: Yeah. I agree, I agree. I had actually, what you just said reminded me, I had a, I had a conversation some months ago with a, with a guy who works at an AI drone company. I [00:21:00] can't tell you more about that, but the... He said the interesting part is who's accountable if an AI drone does a war crime?

Per Krogslund: Like, if you eventually have to investigate this as an war, war crime, who's actually responsible? Is it the developer who wrote the software? Is it the vendor that sold the drone? Is it the military unit that deployed the drone, and the drone decided to bomb a school instead of whatever it was supposed to bomb?

Per Krogslund: Because it made the, the decision autonomously, and how do we assign accountability for something like that? That is essentially, it's essentially impossible, right? 

Justin Kuiper: It's impossible, but in a sense it's everybody, right? If you think about the real, again, I, I wasn't planning on going here, but the real kind of funny thing was everybody talks about the future and how this is gonna be and the robot taking away our jobs.

Justin Kuiper: I don't think that's gonna happen. I, I really don't. I think really, I think our jobs are gonna change, and they should. They always change, right? 

Per Krogslund: We're not, 

Justin Kuiper: we're not working in the fields and bailing hay these days. We're, we're, I work in air conditioning. I [00:22:00] like air conditioning. The, the goal for us really, and one of the things that I really work on here at Futuric is harnessing- harnessing the future to make things better.

Justin Kuiper: We have a crazy opportunity here. That's why I get so inspired by guys like Elon and those other guys going into space and that kind of thing, because they're trying to, they're trying to do something awesome with technology rather than just trying to make something just faster. They're trying to get somewhere or see something or explore.

Justin Kuiper: That's so exciting, and I think when you lean on that side, if you notice too, with a lot of Elon's stuff, you're always in charge. I have a Tesla outside. I'm always in charge of the thing, you know? 

Per Krogslund: So you mentioned human governance, and I think it's a really good point of saying that humans need to stay in control of our own destiny, and yeah, the, the AI and the robots and so on will, will change the circumstances for our life.

Per Krogslund: But do you feel that we might at some point just get a false sense of security just because we can watch them, but we might lose the control? 

Justin Kuiper: Once again, I, I bring up [00:23:00] all these old stories, but HG Wells and The Time Machine, right? The whole idea is that eventually the people that work on the mechanics of things and then the people that actually control things, the artist or whatever, they separate.

Justin Kuiper: And that's exactly the phenomena you're talking about. I would put it this way, that I think the human governance piece is not human micromanagement, right? Just talking about m- the difference between cruise control, I'm, I'm just trying to make this simple, right, and not get overcomplicate a conversation, and then what my Tesla does now.

Justin Kuiper: If, when I was 20 years old, if I thought that I was, I would have a car one day where I would press a button and it would take me to the store, and I would not even really think about how I got there is, is crazy, right? I just, that's like Dick Tracy stuff. I'm, I'm getting real old here in the 1900s, but that's what it is.

Justin Kuiper: The truth be known though, the, the best, like I said, the, the, the human governance should not be stifling of technology. That's the, that's the, that's the balance [00:24:00] that we walk, right? And that's that, that agentic execution and then the human governance on this side. So we need to all- we need to allow for us- ourselves to pull out of the, in a, from an obs- observability point of view, where we're not, we don't have our hands in the dirt quite as much, but we need to have that space where we do understand how things get from point A to Z And that's the diffi- that's a difficult balance, Per.

Justin Kuiper: It's, 'cause I learned te- I learned by doing. I learned by having, by coding. I learned by building the platform. I built a, I built a platform the other day. I have my own kind of home lab, and then we're building one for future te- I have three different clouds in there. 10 years ago, d- and they're different, they're multimodal.

Justin Kuiper: They're every kind of different cloud. I have Google, I have Oracle, I have AWS, I have some other stuff, and I can, I can s- platform manage that thing so easy. I remember when we first set up the AWS cloud at one of my companies, it took us six [00:25:00] months, and I can do it in 10 minutes. It's insane. So th- that's what I'm saying.

Justin Kuiper: We, but the only way that I could do that is that I had enough knowledge to understand the inner workings, right? Elastic IP. I, I understand the firewall, I understand all that stuff, but I have to step back enough and, because I'm too slow. I'm just too s- I can't do that kind of work that quickly, but I can supervise it 'cause I know enough about it.

Justin Kuiper: So that's, that's the balance. And the problem is the next generation, this is the real, the real truth, the next generation of people like us are not gonna have gone from the rotary dial telephone to the smartphone, right? They're not g- they haven't gone from these things where, you know, you, you had to actually code things.

Justin Kuiper: It's just gonna be, "Hey, do this." And, um, that's the real, that's the challenge for the next generation or the next. That's where we're... I think that's the biggest risk, really practically. Not necessarily that we don't care what happens to ourselves or we just kind of... It's that we don't really know how the thing [00:26:00] works, going back to the original question, Simon.

Per Krogslund: Yeah. And we, like, you have a really good point in saying that we are taking a lot of responsibility away from building the system into the AI. We might not necessarily understand how they were built. We can just, we can monitor them and we can measure them, and we can determine that they're working in the way that they should, but we don't really know what's inside of them.

Justin Kuiper: I, I think the way to do this too, is spec engineering. By putting in those hard, um, constraints in how you s- how you build the system, and not allowing any kind of space where something can, um, trigr- um, transgress a boundary that you can't control, I think that's the way you have to... A- again, it goes back to good practices and cyber, if that makes any sense, right?

Justin Kuiper: The networking cannot traverse from here to there. It cannot go to production except through this link. Okay, I can control that link. Like- 

Per Krogslund: Yeah, makes sense. So given your, like, experience and, and, and time in, in aerospace and space and so on, how far do you think we are from, from, like, putting an AI in space or, like, in [00:27:00] military-grade flights and so on?

Justin Kuiper: Well, I can't talk about any military stuff. You gotta try to get in there, Per. Um, but I can talk about, I'd say we're probably 18 months away Not, maybe not generative. Well, I'm sure there's already physical AIs out there, but, um, just real kind of stuff. I mean, Synack's gonna do it. I know the sys admin put Croc out there on these new, um, version three He's, he's building these new, uh, data centers in space.

Justin Kuiper: I, I suspect we're 18 months away. I, I think that's why he puts... That's why Elon Musk and these other guys are working so hard to put, um, networking bandwidth in there. It's because you have, you know, you have ultimate space up there. I think we're about 18 months away. What is your... I, I'm curious, Per, what is your favorite AI to work with?

Per Krogslund: My favorite AI to work with? That's a really good question. I think my everyday AI to work with is Claude. Like, I use Claude code for pretty much everything. But that, like, it's also, it's a very interesting space to roam around and just [00:28:00] try various, like, local models and just see the difference in behavior and see what they...

Per Krogslund: They're good at different things and seeing, oh, how... And then I think interesting thing is to see how, how small can you go to solve a given task. I think that is, I think for me, and also I think, again, being European, it is, I think, healthy to think about your dependencies in this, like, global world. Um, I think it's important to think about your sovereignty.

Per Krogslund: And what it is, like, the US has done incredibly well in establishing the two leading labs, and Europe has Mistral, which is, like, one thing, and then the rest is, like, Chinese open models, right? So in the grand scheme of things, you need to be aware of, like, what is your dependency and, like, who do you have a hard dependency on?

Per Krogslund: Is there gonna be an export control of the thing that is really driving your entire system in the future? 

Justin Kuiper: It's very interesting that you bring that up because I've been... One of the things, so there are three drivers that we see in the market of future tech. One of them is agentic operations we've kind of talked about.

Justin Kuiper: Emergent compute we haven't talked about, but that's the whole Q Day and quantum and all that kind of [00:29:00] stuff, and that, that's very interesting. But the other thing you're hitting on is tokenomics, because, um, it's this whole economy of being able to use, uh, commercial, uh, commercial and even open weight, um, LLMs, and then what, what happens, what happens to the data?

Justin Kuiper: Like, what, what, how do you control that data in and data out? I can tell you on my side, everything we're talking about is about the data sovereignty. In fact, we're working, Future Tech and I, we're working on something called Praetor. I, I use the, I like using Latin names. Praetor, it's a, um, it's the data, uh, data sovereignty me- a sovereign data mesh is what it is.

Justin Kuiper: So the ability to be able to, um, um, keep the data in the spaces where it needs to be, but also to be able to take parts of that, those requests related to that data and throw them out to, um, Anthropic or something like that. Like, the question you're asking, it's neat to try everything out. Some things are better.

Justin Kuiper: [00:30:00] I use Claude, I use Codex, and then at work I'll use, um, I'll, I'm working with some Nemotron models and that kind of thing. But the goal really is those models are all great, and it's great, it's new, it's fancy. Oh, I love them all. But what's really what you want to know is what gives me back what I want, what I intend In the most efficient way for the best price.

Justin Kuiper: And that is, that's that tokenomics piece, and that's that data sovereignty piece too, 'cause the data still has to be safe. And so that's where I agree with you, that's where everything is going. It has to. 

Per Krogslund: So I think this conversation is a good segue into also just talking about the ecosystem around AI agents and so on.

Per Krogslund: Like, the model vendors is one big piece of this, of course. And then, but then you have all the other things. You have MCP servers, you have APIs, you have tools, you have, like, different dependencies and so on, and other agents as well. We will probably have, like, measures of agents calling each other, and that'll be like a, a big thing to secure.

Per Krogslund: How do you see, like, securing the agent versus the security of the ecosystem around the agent? 

Justin Kuiper: [00:31:00] So the, the only way that you can se- Let's just back out a little bit and use some old school terms here. But the only way that you can... The, the first thing, I know I've talked about this before, but the f- on the first page of my CISSP book, it says, "There is no cybersecurity without physical security," right?

Justin Kuiper: So that's the first thing. You've got to use, you've got to use some old school techniques, number one. But the agents talking to agents, that 

Per Krogslund: highway, 

Justin Kuiper: that I wouldn't even call it a highway, I'd call it an agentic mesh, is what I would call it. It's this whole kind of inference layer. It has to be able to breathe and to, to be able to f- be functional, it has to be able to breathe.

Justin Kuiper: The only way that you can do it though, is by restricting, by again, that least privilege space and, and absolutely being able to know that. There's a product I'm looking at right now that is really good. There's two that I'm looking at working together. Puma Mesh is one of the products we've been working with, where you actually can certify your data down at the network level in between [00:32:00] layer seven and layer one in the OSI model.

Justin Kuiper: So that means that data's tagged all the way through, right? And, and it's invisible if you don't have credentials to that kind of stuff. So that kind of thing, as you're passing, let's just say from system A to system B and then back to system A, that identity comes from a f- all the way through, all the way to the back end, right?

Justin Kuiper: So you can send out a call and you can send out a prompt and say, "Hey, give me some information back. Tag it this way, make sure it's tagged that way." And it's tracked all the way through. And if you don't have access to that piece, if you don't have access to that, if you don't have a key to pull that out, then you're You c- you don't even know it's there, right?

Justin Kuiper: It's those kind of things really. It's about the data. It's not necessarily about the agentic operations. The agentic opera- In cyber you have to pr- you have to protect data at rest, in transit, and in process. It's the process piece. If you can maintain that identity and you can maintain those credentials, the access control table, right?

Justin Kuiper: If you can maintain that by attribute, then you [00:33:00] can, you can make it safe. That is the biggest consideration to me, I think, and that's what I, where everybody wants to do. So Chinese model or whatever, right? As lo- if even in a Chinese model, even if it's processing it, if there's a way that you can make sure that it doesn't necessarily know, or there's obfuscation in there, it doesn't necessarily know what it is, you can still in some cases protect it.

Justin Kuiper: I wouldn't do that, but there are people that might. That there is some safety in that back kind of thing, right? 

Per Krogslund: Yeah. It makes sense. So, so what maybe what you, what you're trying to say, as I hear it at least, is that we will have agentic systems where the flow will be much more unpredictable. Like, it won't be declarative.

Per Krogslund: You can't say, "This is the path it's always 100% securely gonna follow." So the mechanism you're gonna have instead is that you are gonna have way to instill trust in different ways. That, yeah, the flow might be unpredictable. It's not, it's not a way to predict it, but you can still have mechanisms in place that [00:34:00] secure it across those, like, unpredictable ways this da- data might travel.

Justin Kuiper: I think that's the only way you can do it. I don't... Or you just aren't gonna be agentic, right? You, you're either gonna go through and say, "I need to see everything you're doing." Or you're gonna have to lock up the box so tight that only the other person has the key on the other end, and that it's very... It- you can only constrain it.

Justin Kuiper: I don't see any other way to do it. I'm sure there's a mathematician that may have a better idea, but that's where I'm going. 

Per Krogslund: We might create new solutions to the new problems we've just created. 

Justin Kuiper: Mm-hmm. That's the best, the best kinda, best kinda thing. 

Per Krogslund: All right. So, so we talked about agents, we've talked about agents in production, we've talked about the ecosystem, but I also wanna make this a little concrete, like, for...

Per Krogslund: Well, our audience is mostly developers, some security and platform teams and so on, but they, they're coming back to work on Monday, like, what should they do differently? What is the... Like, what's the best advice that we could give them? Thinking about staying agentic. We've, we've been talking about constrained autonomy and so on.

Per Krogslund: Like, what's the, what's the, what's the best things that they could do [00:35:00] starting Monday that they would be able to do that would make a difference? 

Justin Kuiper: Without being too ethereal, I get it. The first thing that I would do is take... I would not allow a... I would make a decision of whether I'm gonna be fully agentic or not.

Justin Kuiper: I would make a decision to organize around that or not, and the reason that I would do that is because you wanna know, you, you... A lot of times the traffic, like I've noticed with a lot of agents and that kind of thing, when you mix the normal kind of chatter of an agile scrum team with agentic things, there's just observability problems.

Justin Kuiper: A lot of times things happen in the background with agentics a lot, and you're not focusing on that 'cause you're used to the old way of doing things, and you're used to getting information a different way. So whoever the person in charge, especially the cyber person, I would say you gotta do one or the other, and you gotta decide, 'cause I gotta set up my operating sys- my monitoring system, my all those kind of things around which way we're gonna go.

Justin Kuiper: 'Cause I have to set up those boundaries. I [00:36:00] can't... It's too hard to see two different ways, right? You just, you can just do it. But that's... I would make that decision. I would say, "We're gonna be all agentic or we're not." And then s- then following that, I would say you gotta make the investment on one or the, way or the other.

Justin Kuiper: And that means with the resources and personnel, and that means training, and that means tools, right? You gotta decide. And the, the third thing I would do is, okay, now that I've decided, let's just say they choose the pro-agentic Part. I would say, okay, now what, now, now how? What's your methodology? And you gotta do the things the same.

Justin Kuiper: You gotta be very deliberate because now you are the tether to reality to your whole agentic kind of process, right? So you are the person that says when stuff gets out of line and when it doesn't. So then you've gotta, you've gotta set your own system to say, "Okay, I know my- I am delivering the right code.

Justin Kuiper: My intent horizon is being met when I check precompilition, check another time before I go to main branch." Whatever your ... [00:37:00] It has to be your rule set, but it has to be very deliberate and very ... And you have to be very disciplined with it. I do this every time. Because if you, if you start getting creative, it'll start getting creative with you, and then nobody will know what it's doing.

Justin Kuiper: And then the fourth thing that I would do is I would write everything down. Everything. I have something, I have a source of truth, and I have something called the black box, where even if I screw it up, it writes it and I, I can't erase it. It's append only. And I would definitely do that. And the final thing that I would do is fail closed with any processes.

Justin Kuiper: Set it to where it has to fail closed because you don't ... And, and make sure those processes actually s- that you do everything to make sure those processes will stop Because that's the stuff where you'll find out three months from now, "Oh, I've been gathering everybody's social security numbers, and I just asked for nine digits," right?

Justin Kuiper: That's kind of thing. That's the kind of... Those are some helpful things. How does that hit you? 

Per Krogslund: That all makes sense. That's really good advice across the board. I also want to go in the other direction, because like all the [00:38:00] advice you've just given, and I know you also interact with a lot of different teams and companies and so on, where do you see people, like, either get it just consistently wrong, or maybe even where they, like, might over-engineer things that are not actually very effective?

Per Krogslund: Like, there's just like, you don't actually need to spend time on this because it doesn't have any effect. It's not useful. Like, that skill file you wrote, it's, it's, it's... Or whatever it is. Like, what, what do you, do you, what do you consistently see getting, like, wrong? 

Justin Kuiper: Grow it deliberately. Grow it, and grow it in, in take the use cases that you know that you can do agentically, test them.

Justin Kuiper: Test them under the right hardware. Get some Blackwell, get some GB10s, get some, get what we're calling our data. We have three levels of the data fabric we're building, sovereign data fabric. One is for the development systems. It's some GB10s, Grace Blackwell processors, and a whole lot of hybrid cloud, and a lot of things that all developers use.

Justin Kuiper: So GitHub, those kind of things. And then build that out and get those, and do the right... You, this is the discipline part you've got to do. Just [00:39:00] because you can do something very fast doesn't mean you do it well and do it right, right? So you build out, and you build out enough of an MVP, and you go, okay.

Justin Kuiper: It's the same thing as always. Then you go and say, okay, now I, now I can go to this prime situation. I can build my AI factory on this because I know it works. I know the 800 will drive me in the right direction, not necessarily up the side of a wall. That's what I would say. That's the biggest mistake is the over-engineering piece is just a pri- just applying forces when really you need a focused use case development spec engineering approach.

Per Krogslund: High speed but no direction is dangerous. 

Justin Kuiper: It's very, always, in every case, it's in all cases That's splat. That's got splat written on it. Bug or the windshield 

Per Krogslund: Yeah, and we also, we saw this when cloud became a thing. Like everyone adopted cloud, and they just bought the biggest AWS instance instead of just going small, because that was actually enough 

Justin Kuiper: Until they got the bill.

Justin Kuiper: Look, deliberate, disciplined approach. I agree. Yeah. Thanks, Per. That's good. I wanna [00:40:00] use that. Can I steal it? 

Per Krogslund: Go, please. Please do. Please do. So the last thing I have is looking back on how you talk about these things, we, we've, we've spent decades with this, all the security practices you mentioned earlier.

Per Krogslund: It's decades old. We've, we've taught developers that they can, they can trust software if we put strong boundaries around it, right? And then what we also have now is we're building software that can make decisions, and they can take action for us. And then the big question is what, what does trust look like when this, the software itself becomes an actor, not just a piece of code that is, has boundaries, but an actual actor itself?

Justin Kuiper: What a, what a brilliant question. So there you have, again, this is another existential question, and also a practical, technical one. I don't trust my agents beyond what I would trust, again, a, a very junior developer who just learned how to type. So I, in general, I don't allow, I just don't allow access beyond what...

Justin Kuiper: That's, that's, it's the cyber guy in me, quite frankly. It's the cyber guy and the dad. I just, I'm not gonna give my toddler the keys to the car. He might [00:41:00] try and take them. That's the first thing. The second thing, though, existentially, is the, the, the trust part I think is really gonna be honestly generational 

Per Krogslund: Very much, yeah.

Per Krogslund: And I think we are also out of time, so this is a perfect conclusion to this, this episode. Again, thank you so much for, for being on the show, Justin. I really appreciate all your insights and your background and all the knowledge you bring to this. And so again, thank you so much for being here. 

Justin Kuiper: Hey, Per, I love your questions.

Justin Kuiper: I love your questions. Thank 

Per Krogslund: you. You're welcome. You're very much welcome. It's my pleasure to talk to you. And so to everyone listening, thank you for listening to another episode of Ship Happens. Maybe this is not just about shipping code, but also shipping autonomy in the future. But again, we will find out in a, in the next episode, where you hopefully come back and listen to us.

Per Krogslund: And this is a show sponsored by Docker, where I can talk to smart people like Justin about everything that's interesting and challenging in the IT and AI industry right now. Thank you for listening.