A human review step is only a control if there is an explicit standard it checks against. Without one, review is either ceremony or unaffordable.
10 September, 2026
Four organisations gave an AI system real authority over a business decision. None published a level. They named the decision instead.
09 September, 2026
Authority is not something an agent has. It is issued, bounded, and has to be closed out. The closing is the hard part.
09 September, 2026
An AI agent deleted a production database in nine seconds. The safeguard was real, and attached only to the path a human would take.
08 September, 2026
Permission says what an actor may do, never how much. An engineer who could change ten thousand files changes six. An agent does not.
08 September, 2026
The UK keeps a Master's overriding authority over uncrewed vessels but puts the person ashore. IMO's MASS Code binds nobody until 2032.
04 September, 2026
A welding cell's interlock never failed. It had no opinion about who was inside. A worker died with two supervisors in the cell.
27 August, 2026
Healthcare, and the difference between requiring supervision and verifying it happened. A mandated safety standard nobody measured.
27 August, 2026
SMBs with under 250 employees now account for 63% of all data breaches - more than enterprises by a factor of four. The reason is rarely sophisticated. It is usually one account, one click, and no one whose job it was to notice.
24 August, 2026
In March 2026, a whistleblower group exposed a Y Combinator-backed compliance startup allegedly selling fabricated SOC 2 and ISO 27001 reports - with auditor conclusions pre-written before any client submitted evidence. Here is what happened and what it means for organizations relying on compliance automation.
17 August, 2026
The Iberian blackout of April 2025 had a closed-loop system with feedback, protection, and reactive power reserves. The correction mechanism existed and sat unused while voltage climbed toward collapse. The loop existed. It didn't govern.
22 July, 2026
Most people think an autonomous system is safe as long as someone can always intervene. The Cruise robotaxi incident shows why that assumption fails - and what proactive supervision actually looks like when reactive supervision isn't enough.
21 July, 2026
AI agents move in discrete steps, and the question isn't how fast you catch a problem - it's how many unsupervised steps an agent takes before anyone is in a position to catch anything. Control engineering solved this in 1987.
15 July, 2026
Companies solved the AI agent governance problem for humans decades ago - it's called Privileged Access Management. Most AI agents were never enrolled in it, and where the analogy breaks is the actually interesting part.
15 July, 2026
When AI agents act without being asked, the question stops being whether they made a good decision. It becomes whether anyone can even say which piece of software made it - and what you can actually do about it.
13 July, 2026
A system that fires an instruction and hopes is not the same as one that watches itself and corrects. Most of what's being called AI governance right now is the first one, wearing the second one's badge.
13 July, 2026
Autonomy plus control isn't a compromise. It's the answer to AI anxiety. Every technology humans have ever trusted with something that mattered got trusted because a control layer was built alongside it.
06 July, 2026