James Fan
Researching how to make LLM agents safe to deploy — focusing on security gaps in AI agents, such as LangGraph agents.
Previously cofounded two AI startups, led Google Cloud Speech Group, taught at Columbia University and was one of the main inventors of the IBM Watson question answering system that beat the best human contestants on Jeopardy!. Now mostly thinking about what happens when you give an AI agent access to real tools.
Individual security controls applied to an insecure architecture produce whack-a-mole defense. Seven architectural patterns — perimeter nodes, privilege separation, immutable audit trails, minimal context windows, isolated subgraphs, dead man's switches, and canary nodes — compose into a structure where a compromise at any single point has a bounded blast radius.
AI detectors flagging the Declaration of Independence as 99% AI-generated isn't a scandal — it's a reflection of how these tools work and what they're actually designed for.