Petrov's Loop · CyberCon 2026 companion

Before you sign.

The working artifacts from the talk, in one place: the three questions that open the work, the four that sign it off, and the matrix that decides how much autonomy a system has earned.

Three questions that open the work

Ask these before anyone asks "how".

  • What are we actually building for?
  • What does success look like?
  • Would we even do this if it weren't for AI?

Four questions that sign it off

Before you put your name on an AI-assisted security system. If you can answer all four, you can sign. If you can't, what you're being asked to approve isn't ready — no matter how good the demo was.

  1. Where is the return to the question — and who is the named human who signs?

    Not 'the system decided.' A person — in the incident log, in the governance record — with the information, the time, and the authority to genuinely decide differently. If removing their judgment wouldn't change the outcome, that's not oversight; it's a liability sponge.

  2. Can we audit the process, not just the output?

    Right output through a wrong process is a deferred failure wearing a green tick. Can the system show what it retrieved, how it reasoned, and what confidence it assigned — traceable to a source you trust?

  3. Can three of our own engineers map how it decides in a week?

    Every consequential decision point, every input, every action it can take, every failure condition. If your best people can't produce that map, you can't govern it, audit it, or explain it after an incident. Benchmarks say it's impressive. The map says whether it's governable.

  4. When it fails — and it will — what can we say, to whom, and how fast?

    The question the regulator will ask. Containment, notification, recovery — decided before go-live, not drafted during the incident.

The autonomy matrix

Match the degree of autonomy to two things: how confident the signal is, and how big the blast radius is.

Low blast radius
High blast radius
High confidence
Full automation. Get the human out of the way — you're wasting time you don't have.
Pre-stage everything. One human clicks go. Target 60 seconds.
Low confidence
Automate and monitor. Review the patterns, not the instances.
Petrov's chair. The loop is non-negotiable. This is where the named human lives.

Automate the reversible. Human-gate the irreversible. And reversible means cheap to reverse and harmless if reversed wrongly — a credential you can restore in ten minutes, revoked in the middle of your payment batch, was never reversible.

Ran these against a system and got stuck?

Tell me — that conversation is exactly why I gave the talk. Find me on LinkedIn.