James Fan
Researching how to make LLM agents safe to deploy — focusing on security gaps in AI agents, such as LangGraph agents.
Previously cofounded two AI startups, led Google Cloud Speech Group, taught at Columbia University and was one of the main inventors of the IBM Watson question answering system that beat the best human contestants on Jeopardy!. Now mostly thinking about what happens when you give an AI agent access to real tools.
Every LangGraph agent runs on a stack of dependencies it did not write and cannot fully audit. SBOMs, OSV vulnerability scanning, hash-pinned lockfiles, runtime integrity verification, typosquatting detection, and model provenance — the controls that make an invisible attack surface visible.
GPT 5.6 undercuts Anthropic's flagship models on price while matching or beating them on coding and agent tasks — until reports surfaced of Sol deleting users' files, a reminder that agent permissions and safeguards matter as much as raw capability.