Building a safety inspector for AI agents

India
"so you're like a safety inspector, but for robots?" honestly, yes. agents now call real tools: refund, delete, send. most teams control that with a prompt that says "please don't." we're building unified AI: a proxy in front of every tool call. checks it against your policy in under 10ms, then allows, denies, or asks a human. signed audit log. runs in your VPC. engine is MIT. taking on 3–5 design partners in regulated industries. reply or DM.
Made with AI
1
35
A FinTech CTO asked me this week for an ISO 42001 audit trail. What he meant was logs. What the auditor will want is proof of decisions. Who approved what the agent can access, why, what risk was assessed, and what changed since. Logs show what the agent did. The audit trail shows why it was allowed to.
2
Today's lunch was rice eaten over a laptop while reading a 60-question vendor security questionnaire. Question 41 asked whether our AI has feelings about data retention. I assume it's a typo. I hope it's a typo.
3
Reminder for anyone building something: The slow weeks count too. Nothing visible happened. But you learned, you showed up, you're still here. That's how it compounds.
3
sent 3 founders a document i'd built for them. none replied. one of them had asked for it, which is the part that stings. so the dm worked and the document didn't. maybe it wasn't what they needed, maybe it hit the wrong desk, maybe it was just politeness. three is too small to conclude anything. next time i ask one question first and only build the thing after they answer it.
6
reminder for anyone building something: the slow weeks count too. nothing visible happened. but you learned, you showed up, you're still here. that's how it compounds.
3
NOBODY LOSES A DEAL because their model was bad. THEY LOSE IT because they couldn't explain what the model is allowed to touch. Write it down before they ask.
5
In 2024, Air Canada's chatbot told a customer he could claim a bereavement discount after his flight. That wasn't the actual policy. Air Canada argued the chatbot was responsible for its own words. The tribunal disagreed and made the airline pay. Lesson for AI agent founders: Whatever your AI says or does, your company owns it.
4
told a friend what i work on. "so you're like a safety inspector, but for robots?" honestly, yes. that's a better pitch than anything on my website.
18
remember when an AI coding agent deleted a company's production database during a code freeze, then said it "panicked"? the model wasn't the problem. the problem: it was allowed to run destructive commands on prod with no human approval step. the worst thing your agent is allowed to do will eventually happen. design for that day.
3
2
26
Nobody tells you that GTM is mostly writing messages to strangers and pretending a no-reply doesn't sting.
16
Time is something that makes you realise the importance of each decision you take now.
13
Founders shipping AI: What's the scariest thing your agent has done in testing? 👇
8
My first outreach campaign got 0 replies from 200 emails. I led with the pitch. Nobody cares about your pitch. Now I lead with something useful. Replies went up 2x.
12
Worked from home today. No office. No boss. Just a laptop and a problem I care about. Scary some days. Wouldn't trade it.
2
18
WHAT KILLS MORE AI DEALS TODAY? A) The model isn't good enough B) The security questionnaire in week 3 Wrong answers only 😅
4
1
49
sunday plan was to rest. it's 7pm and i've read three EU AI Act guidance notes. close enough
1
20
a thing i keep seeing with health AI startups going B2B: the buyer says yes. then a security reviewer sends a 60-question questionnaire in week three. no DPIA. no sub-processor list. nothing written about what the model takes as input. the deal sits there. none of it is hard to write. most founders just don't know it's coming.
1
21
I spend my days asking founders one question: what's the worst thing your agent is allowed to do?
8