Regulatory & Runtime Analysis

Notes on governing autonomous agents

Regulatory analysis, enforcement design, and findings from diagnostic engagements. Written for the people accountable for what an agent does in production.

Governance

AI Agent Guardrails Are Not Evidence: What the Economist Enterprise Survey Means for Teams Deploying Agents

A new Economist Enterprise survey finds 98% of large organisations have already experienced a disruptive agent-related incident. The gap is not a lack of guardrails. It is a lack of evidence that those guardrails actually stopped anything.

Read Research Note
Inspection note / latest
policy_surface: autonomous_agent
risk_model: blast_radius
evidence_mode: deterministic
6 min read ยท research archive
Field Notes

Every Agent Has a Blast Radius

An agent's intended job doesn't define its risk. Its permissions do. Six questions, a scoring matrix, and a worked example for measuring what your AI agents could actually reach before you have to explain it.

6 min readRead
Field Notes

Automate the Work. Not the Authority.

Companies aren't automating AI agents just to grow faster, they're automating to survive. Governance isn't the tax on that. It's the condition for scaling it without the first incident undoing it.

5 min readRead
Field Notes

Autonomous Agents Are Entering Lending. Who Is Auditing Their Actions?

A new generation of AI-native financial companies is putting agents directly into underwriting, servicing, and collections. The important control point is before execution, not after.

4 min readRead
Regulation

What Qatar and Saudi Arabia Already Expect from AI Governance

Qatar Central Bank has a binding AI Guideline in force since September 2024. Saudi Arabia governs AI agents through existing cybersecurity frameworks instead. The distinction matters for anyone deploying agents in Gulf financial institutions.

8 min readRead
Governance

One AI agent is manageable. Five vendors change the governance problem.

Regulated fintechs increasingly run AI agents across multiple specialist vendors. Each vendor's controls are built for its own system, not the full customer journey. Here's what an independent governance layer needs to answer.

7 min readRead
Governance

What should an AI agent audit trail actually contain?

A practical checklist for evaluating whether your AI agent records would hold up under regulatory review, chat transcripts and application logs are not the same thing as an audit trail.

9 min readRead
Governance

The AI agent security market is consolidating. The evidence gap isn't.

Check Point, SentinelOne, and WitnessAI are consolidating around detecting AI agent threats. Almost none of them prove an agent's action was actually authorized. That gap is where Gateplex sits.

8 min readRead
Governance

What Zenity's $125M Series C Actually Tells Us About AI Agent Governance

Zenity raised $125 million to work on AI agent governance. The number matters less than what growth-stage investors had to believe was already true before they wrote it.

7 min readRead
Regulation

What Article 12 Actually Requires From Your Logs

Article 12 of the EU AI Act asks for automatic recording of events over the lifetime of a high risk system. Here is what that means in practice, and why most application logs do not satisfy it.

6 min readRead
Governance

When a FLAG Should Stop the Agent

A FLAG verdict records risk without interrupting work. Human approval halts the action until a named reviewer decides. Choosing between them is a risk decision, not a technical one.

5 min readRead
Field Notes

What a 30 Day Shadow Audit Is Built to Catch

A diagnostic engagement observes agent activity without enforcing anything. Here's what the engine is built to catch.

4 min readRead