Zeeshan Khan

Notes from building AI systems — and on the trust problems that define the next decade.


How do we know a system is doing what it claims to be doing? Most of what I write here comes from asking that question across very different domains, over a long time.

I'm an engineering leader working across AI, supply chains, and security. Twenty-five years of it in places where being wrong is expensive: Cisco, where I was a founding engineer on a physical security and communications platform for defense and public safety — surveillance cameras and push-to-talk endpoints managed as one fleet — and later CTO after it spun out; Illumina, leading the software behind DNA sequencers whose outputs feed clinical decisions; and most recently the full AI mandate at Jazzware, covering AI strategy, product, and the hosting and inference infrastructure underneath it. Five US patents. Earlier, research at MIT's AI Lab and DARPA-funded work, in the era when AI still meant rule-based systems.

I run SurroundApps, where we build verification infrastructure for industries where trust used to run on faith — garment supply chains, charitable giving, home healthcare, device security. A US company with an engineering team in Dhaka. Alongside it I publish open-source work on agent provenance, offline credential verification, and integrity monitoring. Running code, not position papers.

I grew up in Dhaka and I'm based in Silicon Valley. The two series here approach the same question from different altitudes: what makes an answer trustworthy, and what it takes to build one where the customer actually is.

The Verification Series

One argument in seven essays: how trust works when generation is free and verification is the scarce thing.

AI Made Generation Cheap. Verification Is the Bottleneck Now.

Generative models pushed the cost of producing plausible content to near zero. The cost of checking whether it's true didn't move. Why verification, not generation, is the constraint that now shapes everything downstream.

~8 min read · May 2026

The Agent Passport

If agents are going to act for us, they need to carry something a counterparty can check: what they are, what they're authorized to do, who answers for them. On what that record must contain — and the one question it can't answer about itself.

~10 min read · May 2026

When You Can't Phone Home

The verification machinery being built for agents assumes a network is always reachable. On what trust looks like at the disconnected edge — carrying the authority, reconciling the record, choosing the failure posture — and the one property, revocation, that no offline system can fully deliver.

~6 min read · June 2026

A Claim Is Not a Credential

A passport's value lies not in what it says but in who signed it. On the difference between a self-signed assertion and an independently issued, revocable credential — and the three things, independent issuance, revocability, and recourse, that only the second has.

~6 min read · July 2026

An Alarm Is Not a Map

A red checkmark tells you something broke. It doesn't tell you what the break touched, who depends on it now, or what to do about it. On the distance between detecting tampering and understanding damage — and why that distance is the entire frontier of integrity tooling.

~11 min read · July 2026

Leading AI Is a Trust Discipline

The tools now produce work that looks trustworthy without being trustworthy — and fool the maker most of all. Why a leader's judgment decays at a distance, and what staying close to the work actually means.

~6 min read · August 2026

A Maker Cannot Grade Itself

The bold engineer, the self-verifying machine, and the junior you didn't hire are the same problem: a maker can't grade its own work. On a leader's real job — being the grader the work can't fake, and raising the ones who'll do it next.

~7 min read · August 2026

Forward Deployment

The Forward Deployed Engineer Now Works for the Vendor

Closing the distance between generic software and a particular company is a thirty-year-old job with four names. What changed isn't the work but who pays for it — and that decides what happens to whatever gets built in the field.

~5 min read · August 2026

The Handoffs Were the Documentation

Implementation used to be three jobs, and the documents existed because the work changed hands. One person doing all three writes nothing down. That paperwork was how anyone could tell whether the work was good.

~5 min read · August 2026

Why Forward Deployment Has to Be Forward

The specification for systems built on models can't be produced anywhere but the field. It needs the customer's actual data, which doesn't travel, and the customer's expert, who won't.

~5 min read · August 2026

Other Writing

You Can't Price What You Can't Attribute

If absolute verification is impossible, the frontier moves from preventing failure to containing it. On reversibility, attribution, and why liability — not cryptography — is what makes anyone design for a smaller blast radius.

Coming soon

What I've Watched in AI Since the Eighties

Four decades of watching the field promise, overreach, and retreat. What keeps recurring, what's different this time, and what a long memory says about where agents go next.

Coming soon

Elsewhere

SurroundApps·LinkedIn·Email