Volume 58
Volume 58 | May 8, 2026
News
🎙 Secured Podcast
Episode 14 | Your Features Are Becoming Bugs
Verkada dropped the kind of release that makes every feature-by-feature roadmap look old. Lee breaks down why the next decade belongs to companies building across the full stack, not just announcing one new thing at a time.
Listen now
West to East series | This week we are featuring:
Chris Carlson, Rick Focke, and Fredrik Nilsson
✍🏻 Articles
Arturo Falck | The AI Agent I Actually Wanted Started Working When I Treated It Like a Coworker
The real promise of AI agents isn’t the flashy demo. It’s the boring, critical follow-through: remembering the task, the relationship, and what needs to happen next.
Read below
Tim Miller | “State of the Security Film Industry” The Ostrich Syndrome
If school doors are being “secured” with methods that are likely to fail, that is not a small technical issue. It is a safety gap hiding in plain sight.
Read below
Ryan Schonfeld | If convergence is still on your 2027 roadmap, you're already behind
Convergence is not coming. It is already here. The real question is whether security leaders are doing the political, operational, and data work required to keep up.
Read below
🚨 Breaking News
Breaking: Verkada just announced a platform-wide update covering cameras, access control, AI alerts, and healthcare visitor management.
Scroll down to go deeper ↓
![]()
Podcast | Secured: Episode 14
In this episode, Lee looks at why Verkada’s latest platform-wide release should make the industry pay attention, from access control and AI alerts to healthcare workflows and compliance. He also shares takeaways from The Security Event in Birmingham and a local manufacturer’s rep event that reinforced why local relationships, labor, and the old school vs. new school tension still matter. The episode closes with a bigger industry question: when someone asks what we do, why is security still so bad at answering in a way people actually care about? Listen here.

From West to East, the conversation doesn’t stop at the show floor. This podcast series brings together 45 voices from across the industry to share what’s actually top of mind right now. You can stream right from the Secured Youtube channel.
Chris’ episode: here
Rick’s episode: here
Fredrik’s episode: here

I have been building an AI agent. Not a chatbot, not a better search box, and not a clever way to summarize my inbox. I wanted something more practical, more boring, and more useful: an agent that could help me carry work forward.
By “carry work forward,” I mean the work that usually lives in the gaps between meetings, emails, introductions, promises, and follow-ups. Who did I meet with? Who introduced whom? What did I promise? What still needs to happen? Who is waiting on me? When should something come back onto my radar?
For example, after a good meeting with Steve, I do not want an AI tool to simply summarize the call and disappear. I want something closer to this:
“Great meeting with Steve. Don’t forget to send him a note about the call. I’ll remind you tomorrow. You should also thank Dan again for the introduction. Steve mentioned that he wanted to schedule a deeper dive with Clarence, so I’ll make sure that does not fall through. Also, Clarence is going to be an important contact.”
That is the agent I actually wanted. Not one that talks more. One that remembers the work, the relationship, and what needs to happen next.
Assistance vs. agency
One of the problems with the current AI conversation is that we use the same words for very different things. AI assistance helps you do the work. AI agency helps carry the work forward.
That distinction matters.
If I ask an AI tool to help me write an email, summarize a meeting, brainstorm ideas, research a topic, edit a draft, or help me write code, that is assistance. Very valuable. Very real. But still assistance.
Agency starts when the system takes some responsibility for continuity. It remembers that something is unfinished. It knows when to come back. It checks whether the outside world has changed. It can take the next step, or at least prepare the next step, without waiting for me to start from zero again.
In my case, I used Claude Code as AI assistance to help me build Mike, an AI agent. Claude Code helped me write and modify the instructions, tools, skills, and workflows. Mike is the agent. He runs in his own Claude Cowork instance on a dedicated Mac, where he can interact with the tools that matter to me: email, calendar, scheduling links, task memory, and a growing set of operating rules.
That sounds more advanced than it is.
What I have built is still simple. It is not a fully autonomous digital employee. It is not a magic chief of staff. It still makes mistakes, still needs guardrails, and still needs supervision.
But it is enough to show the shape of what an agent can become. More importantly, it has taught me that the hard part of AI agents is not intelligence.
The hard part is follow-through.
Three attempts
This is my third attempt.
The first attempt was OpenClaw. I liked the ambition. It gave me a language for thinking about agents, memory, tools, and recurring work. But for what I needed, it had too much friction. When I used the stronger model, it became expensive. When I tried to make it cheaper, it became too limited.
The second attempt was using Claude more directly. That helped me think and design, but I was still trying to force a general assistant into a persistent operating role it was not really built for.
The third attempt is the one that is starting to work. The difference is not that the model suddenly became magical. The difference is that the work finally had somewhere to live.
Mike has a workspace. He has instructions. He has tools. He has tasks. He has a way to improve after mistakes. He has a growing memory of what good work is supposed to look like.
That changed the whole feel of the project.
A chatbot replies. An automation executes. An agent remembers the work, the relationship, and what needs to happen next.
That is the distinction I have been learning in practice.
The almost useful failure
The clearest example came from a scheduling flow with someone named Juan.
Scheduling sounds like a small thing. It is not the glamorous version of AI. Nobody is going to put “AI scheduled a meeting” in a keynote. But scheduling is exactly the kind of work where the difference between a chatbot, an automation, and an agent shows up.
Mike sent Juan some scheduling options. Juan replied with availability. Then Mike made the mistake.
Instead of doing the assistant work, he pointed Juan back to my public Calendly link.
That was not completely wrong. Juan could have clicked the link and found a time. The meeting might still have happened. But it missed the point.
Juan had already replied with availability. He had already done his part. A good assistant should not make him start over with a generic link.
Mike had replied, but he had not handled it.
That was the moment. It was an almost useful failure. The AI did something. It produced a reasonable-sounding response. It moved the conversation forward a little bit. But it did not carry the work.
And that is where a lot of AI agent demos break down. They look impressive until the real workflow shows up.
The correction loop
So we corrected Mike.
The new instruction was simple: if someone replies with availability, do not punt them back to the public Calendly link unless you have to. First, propose specific booking links. Make it easy for the other person. Use the public link as a fallback, not the default.
That sounds obvious, because it is obvious. But this is exactly the kind of detail that turns a general AI tool into something more useful.
You do not build an agent by writing one perfect prompt. You build it by watching where it fails, turning that failure into a rule, and testing whether the next version behaves better.
That is much closer to managing a junior coworker than operating a software feature. A coworker learns the work by doing the work, getting corrected, and developing better habits.
Mike needed the same thing. The point was not simply to make him send a better scheduling link. The point was to teach him to understand the state of the work before taking the next step.
Checking in is not the same as carrying forward
At first, Mike worked mostly by checking in on a schedule. Every so often, he would wake up, scan for changes, and decide what to do.
That is useful. It is also limited. A scheduled check-in is a good safety net, but it is not the same as agency.
The next step is for Mike to think when something happens and create a reminder for himself. If Juan replies with availability, Mike should not only respond. He should also decide whether a future check is needed. If no one responds, he should know when to come back. If a meeting happens, he should remember the follow-up, the introduction, the next person, and the relationship context.
That is the agentic leap. It is not about giving the AI unlimited freedom. It is about giving it enough work memory to know what is still open.
The relationship layer
This is where the agent I wanted becomes different from a task manager.
A task manager can remind me to follow up with Steve. A good agent should understand why Steve matters.
The relationship context is what makes the task matter.
That is the layer of work that usually lives in someone’s head. Founders, salespeople, integrators, project managers, and security leaders all carry this invisible relationship map around with them.
They remember who trusts whom, who opened the door, who needs to be kept informed, who will feel ignored if skipped, who is the real decision-maker, who is the emerging champion, who is waiting, and who needs to be thanked.
Most software does not understand that. Most automation does not even try.
But if AI agents are going to become useful in real business workflows, they need to understand more than tasks. They need relationship-aware work memory.
Where this connects to security
I work in the security industry, so I could not help seeing the parallel.
Security runs on follow-through. A visitor is expected. A technician needs access. A door is malfunctioning. A camera is offline. A vendor promised an update. A customer is waiting for a fix. A shift handoff depends on context.
In each case, the important work happens after the first signal.
Someone has to notice. Someone has to understand who is involved. Someone has to know what already happened. Someone has to decide what comes next. And someone has to make sure it does not fall through the cracks.
I am not suggesting that every security workflow should suddenly be handed to an AI agent. That would be the wrong lesson.
But I do think this is where agents may become useful: not in the flashy demo, but in the unresolved work between the signal and the outcome.
An agent that can remember what is unresolved, understand who is involved, check whether conditions changed, and act within guardrails could be genuinely useful. Not because it is impressive. Because it reduces dropped balls.
What building Mike taught me
The biggest surprise was how ordinary the work became.
Once I stopped thinking about Mike as a futuristic AI system and started thinking about him as a coworker, the requirements became clearer. He needed a defined job, access to the right tools, a place to keep track of unfinished work, instructions for when to act, when to wait, and when to ask, and feedback when he got something almost right but not quite right enough.
That is what I started building. Not a perfect agent. A simple one.
The rest of the build became a practical primer in what an agent needs to become useful: triggers, tools, durable memory, a work queue, guardrails, tests, fallbacks, and correction loops.
That is the part I did not appreciate at the beginning. The intelligence is only one layer. The work system matters just as much.
The real lesson
I still do not have the agent I ultimately want. Mike is early, simple, and imperfect. But the project has already changed how I think about AI agents.
The goal is not to build something that talks like a person. The goal is to build something that can carry work forward with enough context, humility, and state awareness to be trusted.
That trust will not come from a better demo. It will come from the boring moments: checking before nudging, remembering who made the introduction, not asking someone to repeat availability they already gave, knowing that a meeting was booked, coming back tomorrow because today is too soon, and understanding that the relationship matters as much as the task.
That is where agency starts to feel real.
A chatbot replies. An automation executes. An agent remembers the work, the relationship, and what needs to happen next.
That is the agent I actually wanted.
Not one that talks more. One that helps carry the work forward.

If you are not familiar with the Ostrich Syndrome, the "Ostrich Syndrome," also known as the "Ostrich Effect," is a cognitive bias in which individuals tend to avoid or ignore negative information, especially financial information, to avoid discomfort or potential negative consequences.
This is often framed as "burying their heads in the sand" to avoid facing the problem.
The problem here is that 95%+ of school doors that have security film applied in Texas and throughout the country are NOT anchored properly and WILL FAIL to keep an intruder out.
The current so-called industry standard of using silicone as an anchoring system for security-filmed doors doesn't even meet the specifications set by the manufacturers of security film. All the specifications state that the silicone bead must be a minimum of 3/8" on film and frame. Most commercial doors utilize a glazing stop and compression gasket.
All testing done by the manufacturers is done on windows NOT DOORS.
This method has a very high failure rate!!!
Several large window film companies train the above method, and one manufacturer knows it will fail. The people in charge of ensuring things are done correctly have “The Ostrich Syndrome” or are not properly trained.
If you are a parent, teacher, student, or administrator, you should be furious. I have been warning people of this deficiency since 2018, long before any state mandates.
The Ostrich Syndrome runs deep.
All the way to the top.

I just wrapped a panel called Beyond compliance: Driving business value through integrated security operations alongside other leaders in the industry. The conversation was varied and most of the room nodded along to the right ideas about where security operations need to go.
But here's what's been sitting with me since: almost none of what we discussed is aspirational anymore. It's overdue.
My hot take: The convergence conversation isn't new. The industry is still treating it like it is.
I've been part of the convergence conversation for years. I've helped build fusion centers. I've watched plenty of organizations announce a strategic initiative, hire a head of converged security, publish the press release, and then quietly do nothing for 18 months.
It's never the technology. The technology is the easiest part of this. APIs in our industry are still bad (we'll come back to that) but the integration problem is solvable. What's not solvable with software: egos. Politics. Empire building. Two senior leaders who'd rather protect their headcount than share a common operating picture.
That's where convergence dies. Not in the architecture diagram. In the conference room.
The organizations pulling ahead already know this. They've had the hard conversations about who owns what data, who escalates what, where decision rights live. They've accepted that converged security means somebody loses some autonomy. They did the political work first, which is the only reason their technical work matters now.
The organizations that haven't started those conversations aren't running a few quarters behind. They're in a different category entirely. And the gap is widening, not because the leaders are sprinting, but because they're already on their second and third generation of integrated programs while everyone else is still arguing about reporting lines.
If “we should look at convergence” is still on your strategic roadmap, your strategic roadmap is wrong. It should be on your operating plan. It should have been there two years ago.
My hot take: If you're not actively evaluating and using AI, you don't have an AI strategy. You have an excuse.
Let me be clear about what I'm not saying. I'm not saying buy more tools. I'm not saying AI is a silver bullet. The “AI will solve it” pitch is mostly noise.
What I am saying: if your security organization isn't actively evaluating AI right now, if your team isn't being guided through what actually works, where the privacy and compliance landmines are, and how it fits into the program you already run, you're not being cautious. You're being slow. Those aren't the same thing.
The larger enterprises pulling ahead are standing up dedicated AI compliance functions for a reason. They're working through global privacy laws, regional data restrictions, scalability across markets, and the question of what data is actually getting fed into these models. They're treating AI evaluation as a discipline, not a vendor demo cycle. That's the bar. If your team isn't operating at that level, the gap to whoever is your toughest competitor is growing every quarter.
Empowerment is the other half. Evaluation without empowerment is theater. There's no point training your operators on AI capabilities if they're not trusted to apply those capabilities to real business problems, including triaging alerts faster, pulling insights out of video that nobody's reviewed, connecting signals across HR, IT, physical, and operations into a picture no human could assemble manually. AI's most genuinely useful capability is taking messy data and surfacing outcomes. It can only do that if your people are allowed to actually deploy it against the work that matters.
If your team isn't being trained on AI, given guardrails, and empowered to apply it to the business problems you're trying to solve, you don't have a conservative AI strategy. You don't have one at all. Reset it.
And while we're being honest: garbage in, garbage out is a cliché because it's true. If your data is locked in five different systems that don't talk to each other because the manufacturers never bothered to give you real APIs and you never bothered to push them for some, AI is going to underperform for you no matter how much you spend. The data layer is the work. There's no shortcut.
Here’s the hard part.
The hard part of this isn't the technology. It rarely is. The hard part is admitting that the way most organizations have run security operations for the past two decades doesn't work for the risks they're facing now, and that every additional quarter spent debating it is a quarter someone else uses to widen the lead.
Convergence isn't coming. It's already here.
The question is whether you're in it, or watching from the sidelines while someone else writes the case study.
đź‘€ As Seen in the PhySec Community this Week:
#ai
-
Brian Karas shared
178 AI tools that have shut down or been acquired and folded into other products.
#deal-activity

The ALOA Convention & Security Expo is coming up fast. From technical training to meaningful connections, ALOA 2026 is where the people behind physical security come together to learn, connect, and move the industry forward. This is where the industry gets back to the fundamentals, real skills, real conversations, and the people who actually make security work every day. Learn more and register here.

ACS26, The Access Control Summit, is heading to New Zealand in 2026, hosted in collaboration with our city-host, Gallagher Security. Join us October 7–8, and sign up here to be notified first when registration goes live.