Notes on governing autonomous agents
Regulatory analysis, enforcement design, and findings from diagnostic engagements. Written for the people accountable for what an agent does in production.
The AI agent security market is consolidating. The evidence gap isn't.
Check Point, SentinelOne, and WitnessAI are consolidating around detecting AI agent threats. Almost none of them prove an agent's action was actually authorized. That gap is where Gateplex sits.
What Zenity's $125M Series C Actually Tells Us About AI Agent Governance
Zenity raised $125 million to work on AI agent governance. The number matters less than what growth-stage investors had to believe was already true before they wrote it.
What Article 12 Actually Requires From Your Logs
Article 12 of the EU AI Act asks for automatic recording of events over the lifetime of a high risk system. Here is what that means in practice, and why most application logs do not satisfy it.
When a FLAG Should Stop the Agent
A FLAG verdict records risk without interrupting work. Human approval halts the action until a named reviewer decides. Choosing between them is a risk decision, not a technical one.
What a 30 Day Shadow Audit Is Built to Catch
A diagnostic engagement observes agent activity without enforcing anything. Here's what the engine is built to catch.