Honest writing on AI runtime governance, compliance, and the security challenges that come with deploying AI agents in regulated industries.
Every AI governance mistake was already made with cloud. Shadow IT, shared credentials, missing audit trails. The playbook exists.
Read article
8 dimensions, scored 0-4. A practical framework to measure where your organization stands on AI agent governance.
Read article
Enforcement starts August 2027. Here is a quarter-by-quarter timeline with specific actions for each phase.
Read article
Most teams retrofit auditability. Here are five design principles for agents that generate compliance evidence as a byproduct.
Read article
Shared API keys mean you can't tell agents apart. Here is what real agent identity looks like.
Read article
Three scenarios. Three cost calculations. The math is clearer than you think.
Read article
DORA treats AI agents as ICT assets. Operational resilience testing, incident reporting, third-party risk.
Read article
Least privilege for humans is well understood. For AI agents, it barely exists.
Read article
The real risk is not making the model say bad things. It's making the agent do bad things.
Read article
Ethics is about what you should build. Governance is about what you can prove you controlled.
Read article
Kernel sandboxes lock down the process. Policy governs what the agent is allowed to do.
Read article
Everyone knows they need "human oversight." Almost nobody agrees on what that means.
Read article
Your teams are deploying AI agents without telling security. You need a governed path that's faster than going around you.
Read article
Most teams log prompts and token counts. When the auditor asks what happened, the answer is incomplete.
Read article
The threat model is fundamentally different from securing a language model.
Read article
AI agents are deploying faster than governance can keep up. Here's what needs to change.
Read article