governance
19 posts — newest first.
-
A reasoning model just became a platform default. The lock-in isn't where you're looking.
Salesforce made Claude the default model across Agentforce and Slack. Where model dependency actually accrues, and the five exits worth keeping open.
-
Your newest platform user is an agent. Build it a golden path.
Agents are becoming first-class platform citizens. That is an IDP problem: identity, quotas, golden paths, and a portal agents consume as an API.
-
The Model Hardware Standard is the first agent spec where rollback isn't an option
Anthropic's MHS gives agents read/write control of lab and factory hardware. What it guards, what it doesn't, and the controls you have to build yourself.
-
OWASP published an MCP Top 10. Go count your servers before you read it.
OWASP now has a Top 10 dedicated to Model Context Protocol. The list is useful — but the census behind it is the part that should worry your platform team.
-
The 47th approval click is the bug
Human-in-the-loop is a real control until volume turns it into a reflex. How approval fatigue converts oversight into a rubber stamp — and the fix.
-
Why your AI agent should not be allowed to act yet
Reading is reversible. Acting is not. Five things that must exist before an agent gets a write path — and the honest reason advisory-forever is also a failure.
-
MCP has a standards body now. That changes your procurement, not your code.
MCP now lives under the Agentic AI Foundation at the Linux Foundation. What vendor-neutral governance actually buys a platform team.
-
Identity was the easy half. Agent authorization is becoming an audit-trail problem.
NIST, a Senate bill and the MCP roadmap converge on one requirement: prove which agent did what, for whom, under whose grant. Your traces do not.
-
Your agent installs Markdown from the internet and runs it. We spent 20 years learning not to do that.
Agent skills are dependencies with none of the controls. What the 2026 research found, why scanners miss it, and seven fixes for platform teams.
-
Agents are deleting production and nobody is writing the postmortem
Your incident template assumes a deterministic system and a human decision-maker. Agent incidents have neither. Five sections that fix the template.
-
The EU AI Act blinked — your logging requirements didn't
The EU AI Act omnibus moved high-risk deadlines to 2027–28. The logging, oversight, and inventory work is still yours — and reliability needs it anyway.
-
The OWASP Agentic Top 10, translated for platform teams
OWASP's Agentic Top 10 reads like a security doc, but the mitigations are platform controls. Mapping all ten risks to infrastructure you already run.
-
Your agents need identities, not API keys
Every AI agent is a non-human identity — most run on shared, long-lived API keys no IAM review sees. Per-agent identity and your credential blast radius.
-
Autonomy is a budget, not a toggle: error budgets for AI operators
SRE solved runaway release risk with error budgets. The same mechanism governs AI agents: authority per action class, demoted fast, promoted slow.
-
The reliability gap: a framework for trusting autonomous SRE agents
An autonomous airline agent rebooked 1,247 passengers wrong in one weather event. Trusting agents is a reliability problem — here's how to measure it.
-
Agentic AI Patterns: The Maturity Model (Part 3 of 3)
A five-level agentic AI maturity model, from manual to multi-agent mesh — with a self-assessment and where regulated industries should draw the line.
-
The trust gap: bounded autonomy for AI SRE agents
SREs face 50+ alerts a day at 60% false positives while vendors promise autonomous resolution. The autonomy ladder: what an AI agent should never do alone.
-
Agent sprawl is your next production incident
Teams shipping AI agents are recreating 2015's microservices sprawl with worse observability. The governance surface that contains it before it pages you.
-
No anonymous inference endpoints — the MCP security principle you're probably violating
The NSA and NIST put MCP on notice: agents are a funnel for prompt injection and privilege abuse. Why 'no anonymous inference endpoints' — and how to comply.