AI Governance
Governance stops being a document the moment AI reaches production. What a model was permitted to do, what it did, and whether anyone can prove the difference later are runtime questions, answered at the point of the call or not at all. These posts work through that in the open. Start with the APERION AI governance overview, the Trust Fabric architecture, or the agent governance approach.
Governing Google, ServiceNow, OpenAI, Anthropic and LangChain Agents
Hosted agent platforms keep model calls inside the vendor. Developer SDKs run in your code. How to govern both kinds across Google, ServiceNow, OpenAI, Anthropic and LangChain.
Microsoft Copilot Agent Governance: Copilot Studio, Foundry and Agent 365
Agent 365, Entra Agent ID, Purview and Defender each cover part of governing Microsoft agents. How they fit together, and the gaps to close, in seven steps.
Amazon Bedrock AgentCore Governance: How to Govern AI Agents on AWS
AgentCore Policy evaluates the calls that pass through AgentCore Gateway. How to route the calls that matter through it and govern AI agents on AWS in seven steps.
Glean Agents Governance: Permissions, Tools and Audit
Glean agents read what each user can read and act in connected apps. How to govern them in seven steps, from source permissions to one audit record.
How to Govern AI Agents Across Platforms: Microsoft, Salesforce, AWS, Google and More
Every agent platform ships its own controls. How to apply one inventory, one identity model, one policy and one audit record across all of them, with a map of the control points on each platform.
OpenAI, Hugging Face, and the Deployment Flag
The attacking models ran with cyber refusals reduced for an eval. The responders ran with guardrails at full strength and got refused. The variable that decided who got capability was a deployment flag. OpenAI's fix concedes the missing layer and raises the harder question of who should own it.
The Assembly and the Assembler
The biggest names in AI and private capital just stood up services firms to make enterprise AI work. The ratio behind the move is one to six. There are two ways to sell that layer: as hours, or as a machine.
The WOPR Brief: your monitoring stack is now an attack surface
Loops Moved the Work Up a Level. The Risk Moved Down One.
The field moved from prompting agents to designing the loops that run them. The developer conversation has the right cautions. Inside a regulated enterprise, the loop's connectors reach actions that do not reverse, and what the agent sends to the model is a disclosure on its own.
Mythos, Daybreak, and the System Around the Model
A restricted frontier model leaked into a proxy this week before its evaluation finished. It raises the question two cyber systems already posed: is the capability the model, or the system around it? On offense, mostly the system. On defense, that answer is where the moat sits.
The CISO's Guide to Runtime Governance for AI Agents
The Trust Fabric: A four-layer architecture for governing AI agents
The Trust Fabric, a four-layer architecture for governing AI agents