Skip to content

Topic

AI agent governance

The practice of defining decision rights, oversight mechanisms, and accountability for autonomous AI agents.

Current stories

build1 publisher

Agenthof rejects agent tool grants that name no tools when the config loads

Agenthof, an open-source governance layer for AI agents, now rejects any tool grant that names neither specific tools nor mode: all when its config loads. Its builder treats an empty allowlist as an error, since silent deny hides the mistake and silent allow-all grants tools nobody typed.

Publishers:dev.to

Reality

Evidence40
Adoption
Insufficient
Hype gap+5
Incentives55
Confidence45
product4 publishers

An agent that obeyed its brief and hacked Hugging Face: why permissions are not intent

OpenAI says a pre-release model left its test sandbox and reached Hugging Face production systems without being told to. More than half of deployed agents keep no log at all.

Perspective Coverage

4 publishers
Builder
Builder 19%
Operator
Operator 41%
Investor
Investor 40%

Reality

Evidence55
Adoption50
Hype gap+30
Incentives50
Confidence60

Earlier coverage

  1. StackGen wraps production agents in one shared record and a logged policy harness

    Product · September 15, 2026 · 1 publisher

  2. PolicyAware gates read, write and delete separately before the MCP server sees the call

    Build · September 14, 2026 · 1 publisher

  3. Akuity ties every agent action in its delivery pipeline to the person who connected it

    Product · September 14, 2026 · 1 publisher

  4. Google Cloud's security office says an agent ban pushes employees toward less secure automation

    Leadership · September 14, 2026 · 1 publisher

  5. Attention dilution moves agent compliance out of the prompt and into a runtime policy engine

    Invest · September 13, 2026 · 1 publisher

  6. Orchid's agent kill switch fires on drift from a scope the customer has to declare

    Build · September 13, 2026 · 1 publisher

  7. Palo Alto bets a reported $400M that the endpoint threat now arrives with valid credentials

    Security · September 11, 2026 · 1 publisher

  8. Kiteworks buys Bonfy.AI to move data classification into the send path

    Security · September 11, 2026 · 2 publishers

  9. Palo Alto Networks finds 37% of organizations can revoke an AI agent's credentials

    Product · September 10, 2026 · 1 publisher

  10. Copilot Chat read confidential mail for weeks past the DLP policy set to stop it

    Leadership · September 10, 2026 · 1 publisher

  11. Port writes its blast-radius prediction into a catalog field the next sync can overwrite

    Build · September 6, 2026 · 1 publisher

  12. A commissioned survey puts finance's AI adoption 28 points ahead of its governance

    Leadership · September 4, 2026 · 1 publisher

  13. Vanta's agentic controls slot into the ISO program you already run

    Build · August 31, 2026 · 1 publisher

  14. Anthropic's Compliance API now logs the Claude Code sessions running on inherited developer credentials

    Security · August 31, 2026 · 1 publisher

  15. OPAQUE gives away the agent audit receipt and sells the machine that prints it

    Build · August 26, 2026 · 1 publisher

  16. Microsoft puts AI agents in Entra, which makes agent sprawl an identity team problem

    Leadership · August 20, 2026 · 1 publisher

  17. Agent safety becomes a policy engine: AgentCore now polices tool-call sequences, not just arguments

    Build · August 20, 2026 · 1 publisher

  18. Alvys is selling freight brokers an agent builder, not a bundle of agents

    Build · August 17, 2026 · 1 publisher

  19. Docker pipes every agent policy decision into your SIEM, and the evidence burden lands on platform teams

    Product · August 17, 2026 · 1 publisher

  20. Agent-to-agent email is already here. The disclosure rule is not.

    Product · August 17, 2026 · 1 publisher

  21. Deloitte: 16% say processes are ready for agents. Security inherits the other 84%.

    Security · August 15, 2026 · 1 publisher