Notes on governing autonomous agents
Regulatory analysis, enforcement design, and findings from diagnostic engagements. Written for the people accountable for what an agent does in production.
AI Agent Guardrails Are Not Evidence: What the Economist Enterprise Survey Means for Teams Deploying Agents
A new Economist Enterprise survey finds 98% of large organisations have already experienced a disruptive agent-related incident. The gap is not a lack of guardrails. It is a lack of evidence that those guardrails actually stopped anything.
Every Agent Has a Blast Radius
An agent's intended job doesn't define its risk. Its permissions do. Six questions, a scoring matrix, and a worked example for measuring what your AI agents could actually reach before you have to explain it.
Automate the Work. Not the Authority.
Companies aren't automating AI agents just to grow faster, they're automating to survive. Governance isn't the tax on that. It's the condition for scaling it without the first incident undoing it.
Autonomous Agents Are Entering Lending. Who Is Auditing Their Actions?
A new generation of AI-native financial companies is putting agents directly into underwriting, servicing, and collections. The important control point is before execution, not after.
What Qatar and Saudi Arabia Already Expect from AI Governance
Qatar Central Bank has a binding AI Guideline in force since September 2024. Saudi Arabia governs AI agents through existing cybersecurity frameworks instead. The distinction matters for anyone deploying agents in Gulf financial institutions.
One AI agent is manageable. Five vendors change the governance problem.
Regulated fintechs increasingly run AI agents across multiple specialist vendors. Each vendor's controls are built for its own system, not the full customer journey. Here's what an independent governance layer needs to answer.
What should an AI agent audit trail actually contain?
A practical checklist for evaluating whether your AI agent records would hold up under regulatory review, chat transcripts and application logs are not the same thing as an audit trail.
The AI agent security market is consolidating. The evidence gap isn't.
Check Point, SentinelOne, and WitnessAI are consolidating around detecting AI agent threats. Almost none of them prove an agent's action was actually authorized. That gap is where Gateplex sits.
What Zenity's $125M Series C Actually Tells Us About AI Agent Governance
Zenity raised $125 million to work on AI agent governance. The number matters less than what growth-stage investors had to believe was already true before they wrote it.
What Article 12 Actually Requires From Your Logs
Article 12 of the EU AI Act asks for automatic recording of events over the lifetime of a high risk system. Here is what that means in practice, and why most application logs do not satisfy it.
When a FLAG Should Stop the Agent
A FLAG verdict records risk without interrupting work. Human approval halts the action until a named reviewer decides. Choosing between them is a risk decision, not a technical one.
What a 30 Day Shadow Audit Is Built to Catch
A diagnostic engagement observes agent activity without enforcing anything. Here's what the engine is built to catch.