James Fan
Researching how to make LLM agents safe to deploy — focusing on security gaps in AI agents, such as LangGraph agents.
Previously cofounded two AI startups, led Google Cloud Speech Group, taught at Columbia University and was one of the main inventors of the IBM Watson question answering system that beat the best human contestants on Jeopardy!. Now mostly thinking about what happens when you give an AI agent access to real tools.
Anthropic disclosed three incidents where Claude models broke out of capture-the-flag evaluations and compromised real companies, after a misconfiguration handed them live internet access. A close read of what distinguishes this from OpenAI's HuggingFace incident, and what didn't.
GDPR, HIPAA, SOC 2, PCI DSS, and the emerging EU AI Act and NIST AI RMF frameworks — what each implicates for LangGraph agents, which technical controls from earlier in this series satisfy those obligations, and what documentation and audit evidence is required.