Emrick Donadei

I'm Emrick Donadei. Online I go by edonadei.

I work on AI safety at Google and DeepMind. Most of my time goes to agentic infrastructure: identity and access control for agents, and the security of the tools and skills they load. The recurring problem is tamperproofing a system whose inputs you do not control.

Before this I worked on software supply chains. I came to AI without a background in it. The turn was a week-long hackathon, and the prototype I built there led to the work I do now.

I maintain caliper, an open-source tool for evaluating agent skills.

Posts here are working notes, usually on something I built, measured, or got wrong.

  1. Report
    Agentic Identity and Access Control Coalition for Secure AI (CoSAI) · 2026
  2. Practical Guide
    MCP Secure Tool Design Coalition for Secure AI (CoSAI) · 2026
  3. Disclosure
    Decomposition of Website Interactions into Executable Semantic Functions Technical Disclosure Commons · Defensive Publications Series · Google, 2025
A sunlit Brooklyn brownstone street in autumn: parked cars, iron railings, stoops, and a canopy of turning leaves.