Zeeshan Khan

Notes from building AI systems — and on the trust problems that define the next decade.


How do we know a system is doing what it claims to be doing? Most of what I write here comes from asking that question across very different domains, for a long time now.

I'm a product and engineering leader working across AI, supply chains, and cybersecurity. I lead AI product and engineering at Jazzware in hospitality. I run SurroundApps, where we build verification infrastructure for industries where trust used to run on faith — garment supply chains, charitable giving, home healthcare, device security. Earlier work has spanned MIT's AI Lab, DARPA-funded research, physical security systems for public safety and defense at Cisco, DNA sequencing platforms at Illumina, and national-scale identity systems including Bangladesh's biometric SIM verification rollout.

I grew up in Dhaka, came to MIT in the era when AI still meant rule-based systems, and have spent the years since watching the field — and the trust problems it creates — evolve through every major shift. I'm based in Silicon Valley and direct SurroundApps's work in Bangladesh remotely.

Essays

AI Made Generation Cheap. Verification Is the Bottleneck Now.

Generative models pushed the cost of producing plausible content to near zero. The cost of checking whether it's true didn't move. Why verification, not generation, is the constraint that now shapes everything downstream.

~8 min read · May 2026

The Agent Passport

If agents are going to act for us, they need to carry something a counterparty can check: what they are, what they're authorized to do, who answers for them. On what that record must contain — and the one question it can't answer about itself.

~10 min read · May 2026

When You Can't Phone Home

The verification machinery being built for agents assumes a network is always reachable. On what trust looks like at the disconnected edge — carrying the authority, reconciling the record, choosing the failure posture — and the one property, revocation, that no offline system can fully deliver.

~6 min read · June 2026

A Claim Is Not a Credential

A passport's value lies not in what it says but in who signed it. On the difference between a self-signed assertion and an independently issued, revocable credential — and the three things, independent issuance, revocability, and recourse, that only the second has.

~6 min read · July 2026

An Alarm Is Not a Map

A red checkmark tells you something broke. It doesn't tell you what the break touched, who depends on it now, or what to do about it. On the distance between detecting tampering and understanding damage — and why that distance is the entire frontier of integrity tooling.

~11 min read · July 2026

Leading AI Is a Trust Discipline

The tools now produce work that looks trustworthy without being trustworthy — and fool the maker most of all. Why a leader's judgment decays at a distance, and what staying close to the work actually means.

~6 min read · 2026

You Can't Price What You Can't Attribute

If absolute verification is impossible, the frontier moves from preventing failure to containing it. On reversibility, attribution, and why liability — not cryptography — is what makes anyone design for a smaller blast radius.

Coming soon

What I've Watched in AI Since the Eighties

Four decades of watching the field promise, overreach, and retreat. What keeps recurring, what's different this time, and what a long memory says about where agents go next.

Coming soon

Elsewhere

Jazzware·SurroundApps·LinkedIn·Email