<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Frank Winkler — Writing</title>
    <link>https://frankwinkler.me</link>
    <atom:link href="https://frankwinkler.me/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Essays and notes on applied AI, cloud architecture, and product design by Frank Winkler — Sr. Solution Architect &amp; AI/ML Specialist at AWS, Singapore.</description>
    <language>en</language>
    <lastBuildDate>Sun, 21 Jun 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title><![CDATA[An Operational Checklist for AI Agent Identity]]></title>
      <link>https://frankwinkler.me/blog/mcp-security-4-operational-checklist/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/mcp-security-4-operational-checklist/</guid>
      <pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[The non-human identity crisis is measurable in your own account today. Here's a concrete audit — admin agents, secret age, secrets outside repos — and what to fix.]]></description>
      <category>security</category>
      <category>ai-agents</category>
      <category>aws</category>
      <category>identity</category>
      <category>playbook</category>
    </item>
    <item>
      <title><![CDATA[Short-Lived Credentials and Brokered Tokens for AI Agents]]></title>
      <link>https://frankwinkler.me/blog/mcp-security-3-short-lived-credentials/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/mcp-security-3-short-lived-credentials/</guid>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[No agent should ever hold a standing key. AWS STS and OAuth token exchange already make that possible — the failure is architectural, not technological.]]></description>
      <category>security</category>
      <category>ai-agents</category>
      <category>aws</category>
      <category>iam</category>
      <category>oauth</category>
    </item>
    <item>
      <title><![CDATA[The architecture of trust: designing AI products people actually rely on]]></title>
      <link>https://frankwinkler.me/blog/sample-post/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/sample-post/</guid>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Most AI features don't fail because the model is wrong. They fail because the product never earned the user's confidence — and confidence is something you design, not something you ship by accident.]]></description>
      <category>applied-ai</category>
      <category>product-design</category>
    </item>
    <item>
      <title><![CDATA[Govern AI Agents at the Gateway, Not the Prompt]]></title>
      <link>https://frankwinkler.me/blog/mcp-security-2-govern-at-the-gateway/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/mcp-security-2-govern-at-the-gateway/</guid>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A guardrail in a system prompt is advisory. Authorization at the MCP gateway is enforced before the tool call runs. Here's the difference, on AWS.]]></description>
      <category>security</category>
      <category>ai-agents</category>
      <category>mcp</category>
      <category>aws</category>
      <category>bedrock</category>
    </item>
    <item>
      <title><![CDATA[MCP Security Is an Identity Problem: The Non-Human Identity Crisis]]></title>
      <link>https://frankwinkler.me/blog/mcp-security-1-non-human-identity-crisis/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/mcp-security-1-non-human-identity-crisis/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Everyone's bracing for prompt injection. The boring, bigger risk is that your AI agents are non-human identities multiplying 144:1 — and most are holding long-lived secrets.]]></description>
      <category>security</category>
      <category>ai-agents</category>
      <category>mcp</category>
      <category>aws</category>
      <category>identity</category>
    </item>
    <item>
      <title><![CDATA[Building Production ML Pipelines on AWS]]></title>
      <link>https://frankwinkler.me/blog/building-production-ml-pipelines-on-aws/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/building-production-ml-pipelines-on-aws/</guid>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[A field guide to the SageMaker patterns that survive contact with production — and the well-architected guardrails that keep them there.]]></description>
      <category>mlops</category>
      <category>aws</category>
      <category>genai</category>
    </item>
    <item>
      <title><![CDATA[Why ASEAN Is an AI Inflection Point]]></title>
      <link>https://frankwinkler.me/blog/why-asean-is-an-ai-inflection-point/</link>
      <guid isPermaLink="true">https://frankwinkler.me/blog/why-asean-is-an-ai-inflection-point/</guid>
      <pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate>
      <description><![CDATA[Southeast Asia is not a follower market for AI — it is a forcing function. A young, mobile-first, multilingual population of nearly 700 million is adopting generative tools faster than the playbooks…]]></description>
      <category>genai</category>
      <category>asean</category>
      <category>strategy</category>
    </item>
  </channel>
</rss>