top of page
Insights
Practitioner thinking, from the people doing the work.
We publish what we learn, the same instinct that leads us to ship our source code. No gated downloads, no thought leadership theatre. Writing on agentic AI governance, the EU AI Act and identity as the control plane.
Search for Midships Knowledge Base
! No Results found
Mythos, Fear, and What Good Security Architecture Already Tells You
The reaction to Mythos is understandable. There however appears to be a lot of misunderstanding (at least from my conversations). Mythos is a frontier AI model that can identify software vulnerabilities at a level previously reserved for highly skilled human operators changes the economics of cyber risk (think about a seriously good hacker on steroids!). It fundamentally changes the economics of cyber risk. It compresses the time between vulnerability discovery and exploitati

Ajit Gupta
Apr 282 min read
Human in the Loop is Necessary. It Cannot Be the Destination.
Professor Paul Morrissey C.Eng, FIET, FBCS, FRSA published a piece this week on the Agentic Digital Workforce that deserves serious attention. His central warning is right: human oversight designed as theatre, nominal checkpoints with no real authority or context, is not governance. It is liability without accountability. I agree completely. Where I think the argument needs to go further is what happens at scale. Enterprises deploying AI agents across real-time, high-volume w

Ajit Gupta
Apr 272 min read


Why Red Hat Keycloak Is Not What You Think "Open Source" Means
There is a conversation I keep having with CISOs across Southeast Asia and beyond. It goes something like this: we recommend Keycloak for their identity platform, and the room gets uncomfortable. "We looked at it," someone says. "It's open source." The tone tells you everything. In that sentence, open source means unsupported, unvetted, and unsuitable for production workloads that carry regulatory weight. And if we were talking about community Keycloak downloaded from GitHub

Ajit Gupta
Apr 164 min read


Your Permissions Model Was Not Built for AI Agents
The EU AI Act is not the only regulation your enterprise needs to think about. But it is the clearest signal that the governance gap most organisations have quietly tolerated is about to become a measurable compliance liability. This is not a policy problem. It is an architectural one. The Governance Gap Nobody Talks About Most enterprises deploying AI agents rely on the same access control infrastructure they have used for a decade. RBAC. ABAC. API gateways. Firewall rules.

Ajit Gupta
Mar 314 min read


McKinsey's AI Got Hacked in Two Hours. Here's What That Actually Means.
Earlier this month, a security firm called CodeWall pointed an autonomous AI agent at McKinsey's internal AI platform, Lilli. No credentials. No insider knowledge. Just a domain name. Two hours later, the agent had full read and write access to the entire production database. 46.5 million chat messages. 728,000 confidential files. 57,000 user accounts. And — most critically — 95 system prompts that controlled how Lilli thought, responded, and behaved. All writable. Silently.

Ajit Gupta
Mar 274 min read


McKinsey's AI Got Hacked in Two Hours. Here's What That Actually Means.
Earlier this month, a security firm called CodeWall pointed an autonomous AI agent at McKinsey's internal AI platform, Lilli. No credentials. No insider knowledge. Just a domain name. Two hours later, the agent had full read and write access to the entire production database. 46.5 million chat messages. 728,000 confidential files. 57,000 user accounts. And — most critically — 95 system prompts that controlled how Lilli thought, responded, and behaved. All writable. Silently.

Ajit Gupta
Mar 274 min read


Accelerating Ping Deployment with Midships Accelerator
How One of the UK’s Largest Banks Fast-Tracked Their Ping Identity Deployment with the Midships Accelerator One of the UK’s largest banks—ranked among the top 25 globally with over 30 million customers—set out to deploy the Ping Identity platform on Google Cloud Platform (GCP). The bank required a production-grade deployment capable of meeting stringent enterprise standards across security, scalability, operational control, and multi-region resilience . Key requirements incl

Juan Redondo
Jan 53 min read


Have You Checked Your Ping EOS Dates - Midships Helps You Prepare, Upgrade, and Protect Your IAM
Understanding Ping Product Support Status Ping Identity has formalised its product lifecycle — and for many organisations, the deadlines are approaching faster than expected. The new Support Status model finally gives clarity, but it also exposes a hidden risk: many enterprises are already running versions that are nearing End of Maintenance or End of Support. The shift to STS (Short-Term Support) and LTS (Long-Term Support) finally brings predictability to upgrade planning

Ajit Gupta
Dec 15, 20254 min read


Scaling with Focus: Why Midships Chose Ping and Keycloak
Ajit Gupta presenting during a Midships strategy workshop — discussing focus, growth, and risk As a bootstrap founder, we have to constantly balance growth and risk. Over the past year, we’ve gone through significant internal change (for the better), and it gave me an opportunity to tackle a risk that has kept me up many nights. I thought it might be helpful to share this experience and would love any feedback. Each year, I try to mitigate one major risk that could lead to a

Ajit Gupta
Nov 2, 20254 min read
Common Questions
Insights – FAQs
What does Midships publish?
Practitioner writing on agentic AI governance, the EU AI Act and identity as the control plane, from the people doing the work.
Are the insights gated?
No. There are no gated downloads and no thought leadership theatre.
bottom of page



















