<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Gray Matter — Zero Trust + Agentic AI</title><description>Insights on Zero Trust architecture, Agentic AI governance, Graduated Autonomy, and spec-driven development from Nikola Novoselec.</description><link>https://graymatter.ch/</link><language>en</language><item><title>The Spec Grew Up: What Happened After 542 Lines Became a Product</title><link>https://graymatter.ch/blog/spec-driven-development-part-2/</link><guid isPermaLink="true">https://graymatter.ch/blog/spec-driven-development-part-2/</guid><description>Two months ago I published a 542-line spec and said &apos;the code is a side effect.&apos; The spec is now 4,400 lines. The code is over 100,000 lines. Here&apos;s what happened when the spec stopped being a document and became the product.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>Spec-Driven Development</category><category>Agentic Coding</category><category>Software Engineering</category><author>Nikola Novoselec</author></item><item><title>5 Things About Zero Trust You Only Learn at Scale</title><link>https://graymatter.ch/blog/five-things-about-zero-trust/</link><guid isPermaLink="true">https://graymatter.ch/blog/five-things-about-zero-trust/</guid><description>Zero Trust was never just a security initiative. It was an architectural bet - and the companies that made it early are about to collect.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><category>Zero Trust</category><category>Security Architecture</category><category>Enterprise Security</category><author>Nikola Novoselec</author></item><item><title>The Evaluation Nobody Publishes: What Analyst Reports Won&apos;t Tell You About Zero Trust</title><link>https://graymatter.ch/blog/the-evaluation-nobody-publishes/</link><guid isPermaLink="true">https://graymatter.ch/blog/the-evaluation-nobody-publishes/</guid><description>Everyone saw the architecture. Nobody saw the evaluation behind it. We read every major analyst report. Then built a framework that disagreed with all of them.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>Zero Trust</category><category>Security Architecture</category><category>Enterprise Security</category><author>Nikola Novoselec</author></item><item><title>The Code is a Side Effect: Spec-Driven Development in the Coding Agent Era</title><link>https://graymatter.ch/blog/spec-driven-development/</link><guid isPermaLink="true">https://graymatter.ch/blog/spec-driven-development/</guid><description>Everyone&apos;s talking about AI writing code. Almost nobody&apos;s talking about why most of it ends up in the trash. ~70,000 lines of code later, I accidentally built my favorite development environment.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>Spec-Driven Development</category><category>Agentic Coding</category><category>Software Engineering</category><author>Nikola Novoselec</author></item><item><title>Integration is the Architecture: Zero Trust at National Scale (Part 1)</title><link>https://graymatter.ch/blog/integration-is-architecture/</link><guid isPermaLink="true">https://graymatter.ch/blog/integration-is-architecture/</guid><description>How do you bring Zero Trust to an organization that is older than the concept of a computer? Architecting the transition felt like changing the engines on a plane mid-flight - while that plane was carrying the entire population of a nation.</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate><category>Zero Trust</category><category>Security Architecture</category><category>Enterprise Security</category><author>Nikola Novoselec</author></item><item><title>The Great Decoupling Part II: From Designing the Loop to Running It</title><link>https://graymatter.ch/blog/the-great-decoupling-part-2/</link><guid isPermaLink="true">https://graymatter.ch/blog/the-great-decoupling-part-2/</guid><description>I put a small AI model in charge of my firewall. Then I hired a larger model to watch it. Not just to save time - but because humans are no longer fast enough to stop machine-led attacks.</description><pubDate>Sat, 17 Jan 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>Graduated Autonomy</category><category>AI Governance</category><category>Zero Trust</category><category>Security Architecture</category><author>Nikola Novoselec</author></item><item><title>The Great Decoupling: From Writing Code to Designing the Loop</title><link>https://graymatter.ch/blog/the-great-decoupling/</link><guid isPermaLink="true">https://graymatter.ch/blog/the-great-decoupling/</guid><description>Something is shifting in how we build and protect systems. The center of gravity is moving - from writing logic to managing systems that generate it. What hit development is about to hit security. Are you ready?</description><pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate><category>Agentic AI</category><category>AI Governance</category><category>Graduated Autonomy</category><category>Zero Trust</category><category>Security Architecture</category><author>Nikola Novoselec</author></item><item><title>The Quiet Shift: From Enforcing Rules to Enforcing Baselines</title><link>https://graymatter.ch/blog/the-quiet-shift/</link><guid isPermaLink="true">https://graymatter.ch/blog/the-quiet-shift/</guid><description>The era of the static security rule is ending. As modern organisations roll out new infrastructure on edge platforms, a pattern is emerging that deserves more attention: legacy security components are getting smarter.</description><pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate><category>Zero Trust</category><category>AI Security</category><category>Security Architecture</category><author>Nikola Novoselec</author></item></channel></rss>