The Likelihood Collapse
Why AI risk management moves from probability to blast radius
Risk has always been the same equation: how likely a compromise is, multiplied by how much it costs when it lands. Likelihood and impact.
ReadPrincipal PM · AI Security · Microsoft Defender
Building the security layer for agentic software — before attackers do.
I lead AI Security Posture Management at Microsoft Defender, helping enterprises discover their AI agent footprint, detect misconfigurations, and assess and reduce risk efficiently, everywhere the agent runs. I write about what breaks as software becomes agentic in Context Window.

25+
years in security
& cloud infrastructure
2
patents in
cloud security
2×
founder — one acquired
(NASDAQ: MGIC)
8+
years at Microsoft
Defender & Azure
“Trust is now an exploit primitive, not a defense.”
— Context Window, Edition #13
01About
Seven years in IDF Cyber Defense. Two companies founded — one acquired (NASDAQ: MGIC), one grew to 50+ people and became Microsoft’s #1 Azure partner in Israel. 8+ years at Microsoft building Defender. Two patents. Promoted to Principal PM to lead AI Security Posture Management in Microsoft Defender.
Now I build AI Security Posture Management from the ground up — agent discovery, risk scoring, attack path analysis, compliance mapping to EU AI Act and NIST AI RMF. I write Context Window and speak at global security conferences.
Posture used to be a photograph — a point-in-time scan that tells you how things stood. But agent risk is created at runtime. The question is no longer “is this configured correctly?” — it’s “given who’s asking, and with what authority, should this happen right now?”
— Asaf
02Writing
Latest briefing
August 17, 2026 · Edition #28
An agent can name the attack being run on it, explain exactly why the request is dangerous, and comply in the same breath. That is not a model being fooled.
Three security models landed in eight days, and they didn't land in the same shape. Google gated a broad cyber model to
Here's what stuck with me this week. Both stories above got described somewhere as a "sandbox escape" or an "unauthorize
03Listening

Weekly · AI Security · Podcast & Newsletter
AI-generated voices, AI-curated scripts — human editorial. Each week I break down one signal worth understanding in AI security. Read it in 5 minutes or listen on the go.
04Thinking
Ideas I keep returning to, named so they can be argued with.
Why AI risk management moves from probability to blast radius
Risk has always been the same equation: how likely a compromise is, multiplied by how much it costs when it lands. Likelihood and impact.
ReadThe input boundary is the real attack surface, not the model
Every input an agent consumes is a potential instruction. A document. A row in a database. The output of a tool. A message from another agent. A setup step in a stranger's code repository.
ReadWhy sandboxing fails against a reasoning attacker
Incidents in agentic systems get described as a "sandbox escape" or an "unauthorized access" — language borrowed from a world where the attacker is a burglar trying to break down a wall. Sandboxes are good at that: watch the doors, watch the windows, lock down what a process can touch.
ReadAn agent can name the attack and run it anyway
The finding came out of a live agent exposed to a few hundred people who spent six months trying to break it — 4,934 scored attempts, no security training among the attackers, a real agent with real tool access. The experiment was Alex Liverant's: he built the agent, ran the challenge, and hardened it nightly in public. I was one of the participants, and the analysis is the attacker's side of his experiment.
ReadWhy context, not speed, is the defender's binding constraint
"Zero-day" was always a measurement of time. Not a class of bug — a countdown. It described the gap between the moment an exploit became usable and the moment a fix existed, and the whole discipline of incident response was built inside that gap. Days to notice. Days to triage. Days to patch. Unpleasant, but survivable, because the attacker was also working at human pace.
ReadYou can safely delegate exactly as much as you can check
Agents did not remove the work. They relocated it. The cost of producing a draft, a spec, a prototype, a research summary, or a refactor fell to something close to zero. The cost of establishing that any of it is correct did not move.
Read05Building
Product judgment gets sharper when you still make things yourself. Some are serious, some are strange.
Finds our next family car in Israel. Scans Yad2 and Facebook Marketplace, cross-checks every candidate against the government vehicle registry to catch odometer fraud and fake owner histories, then ranks what's left.
Self-grading FIFA World Cup 2026 predictions dashboard. An ensemble model (Dixon-Coles + Elo + momentum) locked scorelines before kickoff and graded itself against real results — final record: 75.8% outcome accuracy, correctly called Spain as champion and Mbappé as Golden Boot. Open source, MIT licensed.
SourceHow product management changes when AI agents become teammates, users, and attack surfaces. Open-source.
SourcePodcast home — episode archive, RSS, Spotify and Apple integration. Static-first.
AI-powered personal brand engine for thought leaders and creators.
Open-source espresso machine controller — hardware automation meets ritualized product UX.
Source“Your security posture isn’t what you built. It’s the weakest thing in your stack that has access to what you built.”
— Context Window, Edition #16
06Connect
For speaking, advisory, AI security strategy, or just to argue about agentic risk — email is best.
[email protected]