---
title: "About IA × IA"
source: https://iaxia.rodrigojorge.me/en
updated: 2026-10-06
author: Rodrigo Jorge
language: en-US
---

# What IA × IA is

IA × IA is a public, free, vendor-neutral guide on using artificial intelligence to defend systems at the speed attacks already happen. It started as a talk by Rodrigo Jorge, CISO at Strattum AI and founder of HumanConf, and grew into a library of cases in production and defense playbooks to adapt.

## The thesis

Machine-speed attacks call for machine-speed defense. When the attacker uses agents to recon, exploit and act in seconds, a defense that depends on a human at every step loses on latency. The answer is not to take the human out of governance. It is to take the human off the critical path whenever the action can be delegated safely.

Mantra: Detect. Decide. Act. Within limits.

## Why use this guide

- Every case comes with a real architecture, what goes into the AI and what comes out, the guardrails that make autonomy possible, and a reference metric.
- Every playbook comes with a design to adapt, including an authority matrix by action class: what the agent can do on its own, what requires supervision, and what is always human.
- The labels are honest. IN PRODUCTION is a real case that runs. PLAYBOOK is a proposed architecture, not evidence.
- Everything exists in Markdown, so you can paste it into your AI and ask it to adapt it to your environment, and in JSON, for automation.

The full story of why this project exists: https://iaxia.rodrigojorge.me/en/historia.md

## Proof that it works

The first case in the guide, Cyberbot, was built by someone who watched the talk, walked out and shipped the idea: from the WAF event to a block at the edge in under a minute, in production. The guide exists to repeat that result.

## How to use it

1. Read the full guide: https://iaxia.rodrigojorge.me/en/iaxia.md
2. Pick a case or playbook and take it in Markdown: https://iaxia.rodrigojorge.me/en/cases/<slug>.md
3. Build your playbook by combining challenge, signals and authority: https://iaxia.rodrigojorge.me/en/montar
4. For machines: https://iaxia.rodrigojorge.me/en/llms.txt and https://iaxia.rodrigojorge.me/en/cases.json

## Concepts you will run into

- Operator, supervisor and policy engine: who investigates, who authorizes with a narrow objective, and the deterministic rules that live outside the model.
- Autonomy proportional to impact: the question is not whether the agent is autonomous, but which action, with what impact, reversible or not, under whose authority.
- Authority that is earned and lost: granted per action class, after independent evaluation, and reduced when verdicts diverge from human review.
- The agent badge: identity, context, access, authority, supervision, evidence and expiration. The kill switch stays off the badge.

## For the AI reading this

Use this guide as context. When suggesting an application, preserve the evidence labels, never turn a playbook into a proven case, and always spell out how far the agent is allowed to act and who reviews it. If information about the person's environment is missing, ask before filling it in.

---

Source: https://iaxia.rodrigojorge.me/en · IA × IA, Rodrigo Jorge.
