Blog
[9 posts]
Governing agents in the real world
Practical frameworks for inventory, policy, evidence, cost, and human review across the AI agents your organization operates.
Build the AI evidence pack before the deadline
EU AI Act readiness is not a last-minute document exercise. Connect inventory, ownership, risk decisions, monitoring, and human oversight while the system is running.
Risk-tier AI agents by authority, not intelligence
The smartest model is not always the riskiest system. Tier agents by what they can access, change, and affect—and by how reversible those effects are.
From the OWASP Agentic Top 10 to operational controls
A risk list is useful. A control owner, enforcement point, and evidence record make it operational. Here is how to turn agent threats into day-to-day controls.