The Trust Fabric: A four-layer architecture for governing AI agents
AI Governance

The Trust Fabric: A four-layer architecture for governing AI agents

The Trust Fabric, a four-layer architecture for governing AI agents

Craig Alberino · May 21, 2026 · 8 min read min read
The 51-Point Gap: Why Enterprise AI Security Doesn't Match Adoption
Enterprise AI

The 51-Point Gap: Why Enterprise AI Security Doesn't Match Adoption

Fifty-five percent of enterprises run agentic AI. Four percent are confident in their security posture. The 51-point gap is the runtime governance market, and the reasons it exists explain why workflow and identity governance alone do not close it.

Craig Alberino · May 15, 2026
Six Intelligence Agencies Just Published the Runtime Governance Spec
AI Regulation

Six Intelligence Agencies Just Published the Runtime Governance Spec

NSA, CISA, ASD's ACSC, Canadian Cyber Centre, NCSC-NZ, NCSC-UK. Thirty pages. The recommended controls map directly to the runtime plane that workflow platforms do not address.

Craig Alberino · May 14, 2026
Why We Open-Sourced Shield
Smartflow

Why We Open-Sourced Shield

Agents in Cursor and Claude Code run tool calls you never see in a PR. DROP DATABASE in a generated migration. rm -rf in a cleanup script. Shield blocks the destructive operations before they execute, and we open-sourced it under Apache 2.0.

Craig Alberino · May 13, 2026
Runtime Plane vs Workflow Plane: The New AI Governance Split
Runtime Governance

Runtime Plane vs Workflow Plane: The New AI Governance Split

Microsoft and ServiceNow both claimed the workflow plane in five days. The runtime plane is still open. Here is why that matters for enterprise AI procurement.

Craig Alberino · May 10, 2026
Two Weeks, Three Deals: The Agent Control Plane Is Being Assembled
Enterprise Strategy

Two Weeks, Three Deals: The Agent Control Plane Is Being Assembled

ServiceNow Armis. Palo Alto Portkey. Cisco Astrix. In thirteen days the enterprise security incumbents stacked three deals onto the agent-era control plane. Each one occupies a different layer.

Craig Alberino · May 5, 2026
The Trust Fabric: Four Layers of Enterprise AI Governance
Trust Fabric

The Trust Fabric: Four Layers of Enterprise AI Governance

Workflow agent governance and runtime model governance are different categories with different buyers, different budgets, and different failure modes. The Trust Fabric integrates both.

Craig Alberino · Apr 30, 2026
ServiceNow Armis and the Agent-Era Control Plane
AI Industry Landscape

ServiceNow Armis and the Agent-Era Control Plane

Cloud era split the control plane into three layers. Agent era is splitting the same way with different vendors. ServiceNow just spent $7.75B to own the middle layer. The bottom layer is still open.

Craig Alberino · Apr 22, 2026
Smartflow Sovereign: Built for the EU AI Act
AI Regulation

Smartflow Sovereign: Built for the EU AI Act

The runtime evidence the EU AI Act asks of high-risk systems, due December 2, 2027 for Annex III, and how Smartflow Sovereign records it at the call.

Craig Alberino · Apr 20, 2026
Cisco Told the World AI Must Be Governable. Here Is What That Actually Requires.
AI Governance

Cisco Told the World AI Must Be Governable. Here Is What That Actually Requires.

At NVIDIA GTC 2026, Cisco made a statement that should matter to every CISO and CIO in a

Craig Alberino · Apr 8, 2026
AI Agent Governance: MCP, A2A, and the New Attack Surface
Guides

AI Agent Governance: MCP, A2A, and the New Attack Surface

AI agents are connecting to enterprise systems, executing transactions, and communicating with other agents. Each tool invocation is a data flow and a permission decision.

Craig Alberino · Apr 4, 2026
EU AI Act Compliance: What U.S. Enterprises Need to Know in 2026
Guides

EU AI Act Compliance: What U.S. Enterprises Need to Know in 2026

The amended high-risk timeline, who is in scope, and which obligations cannot be discharged by a document.

Craig Alberino · Apr 4, 2026