Studies · Field Notes · Agentic AI · Guardrails

Systems that keep themselves honest, secure, and legal.

Research, architecture, and working notes on agentic AI — local-first, auditable, and built where the rules are real. Written from inside the build, where the failure modes actually live.

Regulated & security-first

Built where the rules are real

Security & compliance →

Local-first by default — MAX3, REEF, and FeedHacker keep data on your own hardware, so there's no third-party egress of PII/PHI, the smallest possible breach surface, and a clean data-residency story. Automation stays approval-gated, reversible, and audited.

HIPAA PCI-DSS HL7 / FHIR Zero-Trust Local-First / Data Residency Auditable & Reversible

Track record

Delivery in high-stakes systems

$3.1B
multi-brand health plan modernized
~50%
operational efficiency gain from system unification
200%
platform performance lift (~$240K/yr saved)
10×
scale delivered at a Series A–C EHR/RCM startup

This site: HTTPS only · no third-party trackers · no analytics cookies · security.txt

Latest

From the field notes

All research →
White paperSecurity & Compliance

The README Is the Payload

When an agent discovers a tool by reading its README, the README becomes the attack. Inside AgentBaiting, the FakeGit campaign, and the gate built to hold the line.

Agentic AISecurity & Compliance
ArticleAgentic AI

Inside MAXs Inside the Loop

Eleven days after the first field guide went to press, most of its “limits today” have shipped. How a local-first mind transplanted its own spine withou…

Agentic AI

Build log

Selected projects

All projects →
ActiveLocal-first AI

MAX3

A local-first, voice-first AI resident built as a single Python process — a DuckDB graph spine for memory, a Forward-Forward learner that predicts, proves and adjusts, and a voice loop to talk to him. The collective's flagship.

PythonVoice-firstFlagship
ActiveNetwork Security

REEF

A local-first network-visibility and gateway-defense tool — a named fleet of sensors fused into one high-confidence card that sees it, explains it in plain language, and acts only on your approval.

PythonOPNsenseSelf-Defending
PublishedReference

The Agentic AI Builder's Playbook

A 25-part published series on production-grade agentic AI architecture: the nine-layer agent stack, MCP and A2A protocols, RAG variants, agent memory, and evaluation & observability.

Writing25 Parts

Founder

About the founder

Full story →

Jason Newell is the founder and principal architect of MAX Research Collective. He brings 25+ years of engineering leadership at the intersection of production agentic AI and regulated healthcare, and is the author of The Agentic AI Builder's Playbook, a 25-part series on production-grade agentic AI architecture. His current research centers on MAX3, a local-first, voice-first AI resident, and the theory behind it.