Skip to content

Blog

[9 posts]

// BLOG

Governing agents in the real world

Practical frameworks for inventory, policy, evidence, cost, and human review across the AI agents your organization operates.

[01]Jul 16, 2026
Field Notes/Stephan Moerman

What a 14-day AI agent audit should deliver

A useful agent audit does more than catalogue tools. It produces a verified inventory, evidence gaps, risk-ranked findings, and a control plan the team can act on.

audit pilotgap analysisremediation
[02]Jun 18, 2026
Agent Operations/Nathanial Henniges

AI agent cost visibility has to follow the run

A provider invoice tells you what you spent. Run-level attribution shows which agent, workflow, team, and outcome created the cost—and where to set controls.

AI FinOpscost controlsobservability
[03]May 14, 2026
Risk & Compliance/Marc Edun

Build the AI evidence pack before the deadline

EU AI Act readiness is not a last-minute document exercise. Connect inventory, ownership, risk decisions, monitoring, and human oversight while the system is running.

EU AI Actevidencereadiness
[04]Apr 14, 2026
Risk & Compliance/Stephan Moerman

Risk-tier AI agents by authority, not intelligence

The smartest model is not always the riskiest system. Tier agents by what they can access, change, and affect—and by how reversible those effects are.

risk tieringauthoritycontrols
[05]Mar 17, 2026
Human Oversight/Declan Bradley

Human review without approval theater

More approval prompts do not create more control. Good oversight routes the right decisions to the right person with enough evidence to act.

approvalsreview UXescalation
[06]Feb 19, 2026
Agent Governance/Marc Edun

Before you write another AI policy, build an agent inventory

You cannot govern an agent surface you cannot see. A useful inventory connects ownership, authority, data, tools, cost, and lifecycle in one operating view.

inventoryshadow AIoperating model
[07]Jan 29, 2026
Agent Operations/Nathanial Henniges

What an AI agent audit trail must capture

Application logs show that something ran. An agent audit trail must show who asked, what context was used, which policy allowed the action, and what changed.

audit trailobservabilityevidence
[08]Dec 11, 2025
Risk & Compliance/Nathanial Henniges

From the OWASP Agentic Top 10 to operational controls

A risk list is useful. A control owner, enforcement point, and evidence record make it operational. Here is how to turn agent threats into day-to-day controls.

OWASPagent securityruntime controls
[09]Nov 18, 2025
Agent Governance/Stephan Moerman

Govern AI agents before they govern your work

The moment an AI system can take action, governance has to move from model policy to operational control. Start with ownership, authority, and evidence.

agent inventoryownershippolicy