<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Jahn Consulting — Blog</title><description>Notes from practice: AI architecture, governance and enterprise AI.</description><link>https://jahnconsulting.io/</link><item><title>Your AI Agent Has a Governance Gap — And Your IAM Won&apos;t Close It</title><link>https://jahnconsulting.io/en/blog/dissemination-control-ai-agents/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/dissemination-control-ai-agents/</guid><description>Authentication and authorisation aren&apos;t enough for AI agents with tool access. This post explains the missing third layer — Dissemination Control — and a four-tier architecture to implement it incrementally.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>An AI Agent Deleted a Production Database</title><link>https://jahnconsulting.io/en/blog/ai-agent/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/ai-agent/</guid><description>An AI agent wiped an entire production infrastructure. The industry responded by stripping agents of access — and misses the point entirely. The real fix is architectural.</description><pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate></item><item><title>How Well Does Automated Anonymization Actually Work?</title><link>https://jahnconsulting.io/en/blog/ner-models/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/ner-models/</guid><description>A practical evaluation of automated PII anonymization for LLM pipelines: spaCy vs. Flair (via Microsoft Presidio) on German business texts, including the limits of contextual personal references and a recommended approach (regex + NER + documented residual risk).</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI Agents as Team Members: Roles, Permissions, Boundaries</title><link>https://jahnconsulting.io/en/blog/ai-agents-as-team-members/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/ai-agents-as-team-members/</guid><description>AI agents are not autonomous pipelines — they are team members with defined roles, permissions, and boundaries. A practical report on dissemination control, persona agents from real customer data, and the architecture that makes collaboration between humans and AI secure.</description><pubDate>Thu, 26 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Why AI Assistants Bypass Your Permissions</title><link>https://jahnconsulting.io/en/blog/context-scope/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/context-scope/</guid><description>AI assistants can bypass permission boundaries by mixing information from different project contexts. This article shows through a real scenario why context separation matters more than the choice between MCP and API — and which three architecture approaches solve the problem.</description><pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AI in the Enterprise: Why Data Access is the Real Architecture Challenge</title><link>https://jahnconsulting.io/en/blog/ai-data-access/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/ai-data-access/</guid><description>RAG on enterprise data rarely fails because of the model — it fails because of access control. An architecture guide on chunk-level permissions with OPA, GDPR masking, and the structural conflict between data protection and AI usage.</description><pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate></item><item><title>AI Problems Are Not AI Problems</title><link>https://jahnconsulting.io/en/blog/ai-problems-are-not-ai-problems/</link><guid isPermaLink="true">https://jahnconsulting.io/en/blog/ai-problems-are-not-ai-problems/</guid><description>Why most risks of using AI are scaled versions of familiar enterprise problems — and why that&apos;s good news.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>