Runtime Governance

Governance that runs after the fact describes what happened. Governance that runs at the call decides what happens. The difference is architectural, and it determines whether an examiner is handed a policy document or an evidence trail. This is the category APERION builds in, worked through post by post. See the Trust Fabric, policy as code, and tamper-evident audit logs.

The missing verb
Runtime Governance

The missing verb

Agents act on a person's authority at machine speed. When one goes past what the person authorized, where does the action go?

Craig Alberino · Sep 17, 2026
OpenAI, Hugging Face, and the Deployment Flag
AI Governance

OpenAI, Hugging Face, and the Deployment Flag

The attacking models ran with cyber refusals reduced for an eval. The responders ran with guardrails at full strength and got refused. The variable that decided who got capability was a deployment flag. OpenAI's fix concedes the missing layer and raises the harder question of who should own it.

Craig Alberino · Jul 22, 2026
The Assembly and the Assembler
AI Governance

The Assembly and the Assembler

The biggest names in AI and private capital just stood up services firms to make enterprise AI work. The ratio behind the move is one to six. There are two ways to sell that layer: as hours, or as a machine.

Craig Alberino · Jul 16, 2026
The Routing Layer Gets Named From Three Directions
WOPR

The Routing Layer Gets Named From Three Directions

Three constituencies named the routing layer between May 4 and July 12: capital, the channel, and the developer mainstream. All three agree on the position. None includes identity, inline policy, or evidence.

Craig Alberino · Jul 15, 2026
Mythos, Daybreak, and the System Around the Model
AI Governance

Mythos, Daybreak, and the System Around the Model

A restricted frontier model leaked into a proxy this week before its evaluation finished. It raises the question two cyber systems already posed: is the capability the model, or the system around it? On offense, mostly the system. On defense, that answer is where the moat sits.

Craig Alberino · Jun 7, 2026
Agent of an Agent
AI Agents

Agent of an Agent

When an agent spawns another agent, the authority chain gets longer and the audit trail gets thinner. The runtime layer is the only place that can prove what actually happened at the end of the chain.

Craig Alberino · May 25, 2026
The 51-Point Gap: Why Enterprise AI Security Doesn't Match Adoption
Enterprise AI

The 51-Point Gap: Why Enterprise AI Security Doesn't Match Adoption

Fifty-five percent of enterprises run agentic AI. Four percent are confident in their security posture. The 51-point gap is the runtime governance market, and the reasons it exists explain why workflow and identity governance alone do not close it.

Craig Alberino · May 15, 2026
Six Intelligence Agencies Just Published the Runtime Governance Spec
AI Regulation

Six Intelligence Agencies Just Published the Runtime Governance Spec

NSA, CISA, ASD's ACSC, Canadian Cyber Centre, NCSC-NZ, NCSC-UK. Thirty pages. The recommended controls map directly to the runtime plane that workflow platforms do not address.

Craig Alberino · May 14, 2026
Runtime Plane vs Workflow Plane: The New AI Governance Split
Runtime Governance

Runtime Plane vs Workflow Plane: The New AI Governance Split

Microsoft and ServiceNow both claimed the workflow plane in five days. The runtime plane is still open. Here is why that matters for enterprise AI procurement.

Craig Alberino · May 10, 2026
The Trust Fabric: Four Layers of Enterprise AI Governance
Trust Fabric

The Trust Fabric: Four Layers of Enterprise AI Governance

Workflow agent governance and runtime model governance are different categories with different buyers, different budgets, and different failure modes. The Trust Fabric integrates both.

Craig Alberino · Apr 30, 2026
ServiceNow Armis and the Agent-Era Control Plane
AI Industry Landscape

ServiceNow Armis and the Agent-Era Control Plane

Cloud era split the control plane into three layers. Agent era is splitting the same way with different vendors. ServiceNow just spent $7.75B to own the middle layer. The bottom layer is still open.

Craig Alberino · Apr 22, 2026