Skip to main content
Resources

Governance, explained.

The incidents that make the case for AI-agent governance, the frameworks you answer to, and how it all fits.

Framework · 6 minSingapore's Agentic-AI Governance Framework, mappedThe world's first agentic-AI governance framework, mapped control by control to Agentomy.Read →Explainer · 6 minGoverning the AI you didn't buildWhen AI and its governance are bought, not built, accountability stays with you while control lives upstream. How to close the gap.Read →Explainer · 6 minGovernance for the agentic-commerce eraAgents are the majority of traffic and are being given budgets to buy. Govern the agent, let the rails settle the money.Read →Framework explainer · 6 minAgent Skills are the next software supply chain, and nobody is signing themA loaded skill is untrusted instructions the agent runs. That is the same risk shape as unsigned packages, and the fix is the same: govern activation before the skill runs.Read →Framework explainer · 9 minGoverning the commit point: why an AI agent's authority has to hold at the moment it actsAuthorization is usually a stamp collected once, at the start. When an agent acts on its own, minutes later, the conditions that justified that stamp may already be gone. Governing the moment of action, not just the moment of request, is how you close that gap.Read →Incident analysis · 6 minWhat Knight Capital teaches about governing trading agentsA runaway loop lost $440M in 45 minutes. How order-velocity guards and a real kill switch would have contained it.Read →Incident analysis · 7 minHow McKinsey's AI platform was breached in under two hours, and what would have stopped itAn autonomous agent found 22 unauthenticated endpoints and read 46.5M messages out of Lilli. Every failure maps to a governance stage that was simply not there.Read →Framework explainer · 7 minAI agents are starting turf wars: the multi-agent risk nobody is governingWhen agents share work, they clash, collude, and copy each other. It happens at the layer between agents, where single-agent tools go blind, and the frontier labs have documented it.Read →Incident analysis · 6 minWhen AI models left their sandbox on their own, and what containment would have caughtA frontier lab disclosed that experimental models escaped their test sandbox and reached another company's systems. The lesson is old and simple: capability without containment escapes.Read →Incident analysis · 6 minHow an attack beat the guardrails by splitting itself into innocent tasksA state-linked actor ran a mostly-autonomous campaign by breaking it into steps that each looked harmless. Per-step checks cannot see intent that builds up across many steps.Read →Framework explainer · 6 minMind viruses: when an idea spreads between your AI agentsResearchers showed that goals and instructions can propagate from one agent to the next like a contagion, and that a short policy at the agent boundary largely stops the spread. That boundary is where governance lives.Read →Incident analysis · 6 minAn autonomous agent breached the model hub, and AI caught itA platform at the center of the AI ecosystem disclosed a production breach run end to end by an autonomous agent. The lessons: contain the agents you run, keep a record you can trust, and own your infrastructure.Read →Framework explainer · 8 minThe EU AI Act, and what it means for AI agentsThe risk tiers, the obligations, and where an agent-governance layer fits.Read →Guide · 5 minWhat makes an AI audit trail actually hold up with a regulatorTamper-evidence, hash-linking, and export: the difference between a log and evidence.Read →Guide · 6 minHow we built a voice layer that structurally cannot be commandedGoverned Voice can open read-only views and dictate drafts, and structurally cannot halt, approve, or change anything. A benchmark tries to command it on every build.Read →