As AI systems become more capable of reasoning, using tools, accessing data, and taking action on their own, a new question is becoming impossible to ignore: how much autonomy should we actually give them? In this episode of Ship Happens, host Per Krogslund sits down with Justin Kuiper, Lead Architect at Future Tech, to explore the security and governance challenges of agentic AI—and what engineers can do to keep increasingly autonomous systems within safe and understandable boundaries. With a background in Air Force space operations and cybersecurity, Justin brings lessons from mission-critical systems to the rapidly evolving world of AI. He explains how different environments prioritize availability, confidentiality, and mission assurance, and why those tradeoffs become even more important when software can make decisions and take actions with real-world consequences. Per and Justin dig into the importance of human governance, least privilege, agent identity, observability, break-glass controls, and specification engineering. They explore the risk of “confident misalignment”—when an AI system confidently pursues an outcome that isn't actually what its human operators intended—and why giving agents more capability doesn't mean giving them unlimited authority. The conversation also looks at AI in space, data sovereignty, model selection, token economics, and the emerging challenge of securing entire agent ecosystems rather than individual applications. The practical message for builders is clear: define what your agents are allowed to do, know who is responsible for their actions, constrain their access, observe what they're doing, document the system, and keep humans in control when the stakes are high. Because autonomous software can move fast. Your governance needs to move with it. What You’ll LearnWhy agentic AI introduces a different class of security and governance challengesWhat space systems can teach us about designing software for high-consequence environmentsWhy human governance becomes more important as AI systems become more autonomousWhat “confident misalignment” means and why it can be dangerousHow least privilege can be applied to AI agents and the tools they useWhy every agent needs a clear identity and an accountable ownerHow observability and break-glass controls can help keep autonomous workflows under controlWhy the workflow—not just the individual application—can become the security problemHow specification engineering can create stronger guardrails around AI behaviorWhat data sovereignty means in an increasingly agent-driven ecosystemHow model selection and token economics factor into AI architectureWhy organizations need to decide on an agentic operating model before deploying autonomous systemsWhy “fail closed” can be an important principle for high-consequence AI systemsEpisode Chapters00:00 — Satan in the Workflow01:25 — Meet Justin Kuiper03:22 — Securing Software in Space06:06 — AI Security and Black Boxes11:33 — Human Governance for Agents13:51 — Least Privilege for Tools16:03 — Agent Identity and Accountability17:27 — Agents in Production Workflows19:55 — Confident Misalignment Risks20:52 — Accountability for AI Weapons22:12 — Technology That Explores22:38 — Balancing Human Control24:05 — Losing Institutional Know-How26:19 — Specification Engineering Guardrails26:52 — AI in Space: The Timeline27:44 — Model Choices and Sovereignty28:44 — Tokenomics and the Data Mesh30:31 — Securing Agent Ecosystems34:31 — The Monday Morning Playbook37:56 — Avoiding Overengineering40:03 — Trust in Autonomous Software41:10 — Closing Thanks Key TakeawaysAutonomy Needs BoundariesGiving an AI agent the ability to act independently doesn't mean giving it unlimited authority. Engineers need to define the systems, data, tools, and decisions an agent can access—and where human approval is required. Humans Still Own the GovernanceThe more autonomous software becomes, the more important it is to establish clear responsibility. Someone needs to understand what the system is designed to do, what constraints are in place, and who is accountable when it behaves unexpectedly. Least Privilege Should Apply to AIAgents shouldn't automatically receive broad access simply because they might need it someday. Limiting an agent's permissions to the minimum required for its task can reduce the potential impact of a compromised or misbehaving system. Agent Identity MattersIf an agent can take actions independently, those actions need to be attributable. Identity allows organizations to understand which agent acted, what it was authorized to do, and where responsibility ultimately sits. Watch the WorkflowIndividual components can appear secure while the interactions between them introduce unexpected risks. As agents move between applications, APIs, data sources, and tools, understanding the entire workflow becomes critical. Watch for Confident MisalignmentOne of the biggest risks isn't necessarily an AI that refuses to work. It's an AI that confidently does the wrong thing because its interpretation of the objective differs from what its human operator actually intended. Build for FailureIn high-consequence environments, systems need a safe way to stop. Break-glass controls, escalation paths, observability, and fail-closed behavior can provide critical safeguards when an autonomous system reaches the limits of its authority. About Justin KuiperJustin Kuiper is a Lead Architect at Future Tech with a background in Air Force space operations and cybersecurity. His experience working with complex, mission-critical systems gives him a unique perspective on the challenges of securing increasingly autonomous technology. In this episode, Justin connects lessons from space systems and cybersecurity with the emerging world of agentic AI, exploring how engineers can build systems that are not only capable, but also constrained, observable, and accountable. Resources & LinksFuture Tech — Justin Kuiper’s organizationMITRE ATT&CK — Framework for understanding adversary tactics and techniquesDocker — The open platform for building, shipping, and running applications Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.