All Posts
└─ tech·research·talks·notes
⌘K
2026 15 posts
The Agentic Feedback Loop: From Adaptive Intelligence to Governed Execution
23 min read
Imagine a commercial greenhouse containing a crop worth EUR 500,000.
Temperature is one of the variables that determines whether that crop survives.
Too cold…
Three Pillars for Bringing Agentic AI into Production
13 min read
The current AI transition is often described as a revolution in software development.
Large language models generate code, tests, documentation and…
Demystifying the Temporal Dimension of PIC: From Proof of Possession to Execution Lineage
12 min read
PIC here means Provenance Identity Continuity.
Scope note. This article isolates one part of PIC: its temporal / execution-lineage dimension. PIC is broader…
The AI Agent Economy Cannot Be Trusted: What Agency Theory Teaches, and Where Runtime Authority Needs a Different Instrument
21 min read
Economics offers incentives, monitoring, delegation and control. Runtime software can also make some invalid authority states rejectable at the receiving…
Designing PIC-X: Centralized Token Exchange End to End
16 min read
Designing PIC-X. Centralized Token Exchange End to End. PIC Profile 0.2 defines centralized PIC-X-mediated authority continuity.
This walkthrough follows one…
Designing PIC-X: PIC Token JWT and COSE Artifacts
16 min read
Designing PIC-X. PIC Token JWT and COSE Artifacts. PIC Profile 0.2 defines centralized PIC-X-mediated authority continuity.
The active profile is…
Designing PIC-X: Exposing Configuration through .well-known/pic-x-configuration
8 min read
Designing PIC-X. Exposing Configuration through .well-known/pic-x-configuration. PIC-X exposes discovery at two levels: a server control-plane document and a…
Designing PIC-X: Deriving an Initial PIC Context of Authority
14 min read
Designing PIC-X. Deriving an Initial PIC Context of Authority. PIC-X receives an OAuth access token at the selected realm token endpoint, validates it, and…
Designing PIC-X: From Specification to Architecture to Code
3 min read
Designing PIC-X. From Specification to Architecture to Code. PIC-X stands for Provenance Identity Continuity Exchange.
Verifiable Authority Continuity across…
From Hardy’s Compiler to Hardy’s AI Agent: When the Threat Model Changes, the Confused Deputy Returns
87 min read
From Hardy’s Compiler to Hardy’s AI Agent. The question. This article examines one narrowly defined security property: whether authority propagated across time…
Trusting AI Agents, Who Is Acting?
10 min read
Who Is Acting? AI agent security is usually approached as an identity problem: the question becomes “what is the agent’s identity, and what is it…
TDI2026 - PIC
1 min read
On April 20–21, 2026, the 4th International Workshop on Trends in Digital Identity (TDI 2026) takes place in Verona. The workshop program also includes the talk…
LFDT - From Identity-First to Authority Continuity
1 min read
On March 3, 2026, LF Decentralized Trust hosted the session “From Identity-First to Authority Continuity”, presented by Nicola Gallo.
LFDT - Trusted AI Agents by Design: From Trust Ecosystems to Authority Continuity
1 min read
On March 3, 2026, LF Decentralized Trust hosted the session “Trusted AI Agents by Design: From Trust Ecosystems to Authority Continuity”, presented by Nicola…
ZTAuth* and PIC: From Research to Ground Truth
1 min read
Over the past couple of years I have written several articles touching on ZTAuth* and PIC. Reading them today, some point in different directions, different…
2025 4 posts
A Trust Model for Ambient Mesh, microsegmentation, and async flows
18 min read
Ambient Mesh is redefining the Cloud Native service mesh for Zero Trust, whilst ZTAuth* completes it with Trust Chains built on Trust Elevation, Trust Levels…
Programmable Fiduciary Money and Order Instruments
4 min read
Single-merchant payments are easy; real commerce is not. The moment users ask an AI agent to buy multiple items from different merchants at the best available…
Decentralized Models for Programmable Fiduciary Money
5 min read
AI agents bring new security challenges, but also an opportunity to rethink traditional models.
By looking at payments from a decentralized perspective, we can…
Working on Permguard
1 min read
Kicking things off with something I’ve been building: `Permguard`, an open source project under the Apache 2.0 license.