Trusted Agents is a free weekly newsletter on AI agent security for business leaders. Every Tuesday, it covers what is going wrong with AI agents in the real world, why it is happening, and what you can take action on that week.
Written by Joshua Woodruff, Founder of MassiveScale.AI, CSA Research Fellow, and author of "Agentic AI + Zero Trust: A Guide for Business Leaders."
Who Is Trusted Agents For?
Business leaders, security leaders, and anyone responsible for AI adoption at their company. If your team is deploying AI agents or experimenting with tools like Claude Code, Microsoft Copilot, or similar platforms, and you are not sure what could go wrong, this newsletter is for you.
You do not need a technical background. Every issue is written in plain language for the person who has to make decisions about AI agents, not the person who builds them.
What Do Subscribers Get Every Week?
Each issue of Trusted Agents includes five things you cannot find anywhere else combined in one place.
Real incidents. Named companies, specific failures, and exactly what went wrong. Not theory. Things that happened this week. If a major enterprise had an AI agent failure, you will read about it here with a clear explanation of why it matters to your organization.
Action plans. Concrete steps you can take this week to find and fix AI agent risks. No jargon. No "consider implementing." Specific things to do Monday morning, written for someone who does not have a security background.
Lab notes. Josh runs a dedicated AI agent security lab, building and testing agents firsthand. Every week he documents real configuration decisions, security mistakes, and lessons learned. This is practitioner-level insight you cannot find anywhere else. It does not appear on LinkedIn. It is exclusive to subscribers.
Zero Trust gap analysis. Josh created the Agentic Trust Framework, published through the Cloud Security Alliance, which extends Zero Trust principles to AI agents. Every issue maps real incidents to the framework so you can see exactly where security breaks down and what to build instead.
Builder intelligence. Patterns from real-world AI agent deployments across startups, enterprise, and regulated industries. What is working, what is failing, and why.
Why Does This Newsletter Exist?
AI agents are the fastest-growing unmanaged risk in business right now. Teams are spinning up agents with access to customer data, payment systems, and internal tools without any security review. Most companies do not know how many agents are running inside their environment.
86% of AI agents are deployed without security approval (Gravitee, February 2026). Only 26% of organizations have AI governance policies in place (CSA survey, RSAC 2026).
Traditional security was not built for this. AI agents change their own behavior, forget their instructions, and take actions nobody approved. Zero Trust gives you the right principles, but it was designed for humans and laptops, not autonomous software operating at machine speed.
The Agentic Trust Framework closes that gap. Trusted Agents is where the framework meets the real world every week.
Who Is Joshua Woodruff?
Joshua Woodruff is the Founder and CEO of MassiveScale.AI, a cybersecurity and AI governance consulting firm specializing in agentic AI. He has over 30 years of enterprise security experience at Microsoft, eBay, Genentech, and Exelon.
Josh is a Cloud Security Alliance Research Fellow, IANS Faculty member, and co-leads the CSA Zero Trust Working Group. He created the Agentic Trust Framework, an open governance standard published through the Cloud Security Alliance that applies Zero Trust principles to AI agent governance. Microsoft's engineering team built their Agent Governance Toolkit against the ATF spec 30 days after the CSA publication.
He is the author of "Agentic AI + Zero Trust: A Guide for Business Leaders," with a foreword by John Kindervag, creator of Zero Trust. Josh and his wife Michelle Savage, who leads content design at PayPal, co-wrote the book to make AI agent security accessible to business leaders, not just security practitioners.
Not sure where your organization stands on AI agent governance? Take the free self-assessment at verifiedagents.ai. It takes 10 minutes and shows you exactly where your gaps are.
Frequently Asked Questions
What is Trusted Agents? Trusted Agents is a free weekly newsletter on AI agent security for business leaders, published every Tuesday. Each issue covers real AI agent incidents, action plans for that week, lab notes from Josh's own agent security lab, Zero Trust gap analysis, and builder intelligence from enterprise deployments. Subscribe free at trustedagent.substack.com.
Who writes Trusted Agents? Joshua Woodruff, Founder and CEO of MassiveScale.AI. Creator of the Agentic Trust Framework, published by the Cloud Security Alliance. CSA Research Fellow. IANS Faculty. Co-leads the CSA Zero Trust Working Group. Author of Agentic AI + Zero Trust (foreword by John Kindervag, creator of Zero Trust). RSAC 2026 speaker.
What is the Agentic Trust Framework? The Agentic Trust Framework (ATF) is a free, open governance standard published by the Cloud Security Alliance in February 2026. It extends Zero Trust to AI agents across five areas: identity and access management, behavioral monitoring, data governance, segmentation, and incident response. The full spec is free at agentictrustframework.ai.
How is Trusted Agents different from other AI security newsletters? Most AI security content is written by practitioners for practitioners. Trusted Agents is written for business leaders and security leaders who have to make decisions about AI agents without a technical background. Every issue uses plain language, real examples, and specific actions. The lab notes and action plans are exclusive to subscribers and do not appear on LinkedIn or anywhere else.
How much does Trusted Agents cost? Free. Every issue, every week. Subscribe at trustedagent.substack.com.
What is the AI agent security lab? Josh runs a dedicated AI agent lab on a Mac Studio, building and securing agents firsthand. The lab includes four agents: Atti (orchestrator), Forge (coding), Scout (research), and Quill (writing). Every week he documents real security decisions, configuration mistakes, and failures from the lab exclusively for Trusted Agents subscribers. Real failures documented include a $300 overnight token burn from 47 runaway agents, a coding agent locked out of its own tools by overly restrictive security controls, six hours of strategic work lost to memory compression, and a local model that failed silently on complex tasks.
How often does Trusted Agents publish? Every Tuesday morning.
Subscribe for free at https://trustedagent.substack.com
AUTHOR BIO
Josh Woodruff is the Founder and CEO of MassiveScale.AI. Creator of the Agentic Trust Framework, published by the Cloud Security Alliance and implemented by Microsoft. CSA Research Fellow. Co-leads the CSA Zero Trust Working Group. IANS Faculty. RSAC 2026 speaker. Author of Agentic AI + Zero Trust (foreword by John Kindervag, creator of Zero Trust).
