Tags: governance*

0 bookmark(s) - Sort by: Date ↓ / Title /

  1. VB Staff reports (in a Box-sponsored piece) that identity and permissions alone cannot govern agent behavior in enterprise settings, because autonomous agents will exhaustively explore every granted permission at machine speed, surfacing forgotten misconfigurations far faster than any human could. Heather Ceylan, CISO at Box, argues that security must extend beyond governing access to governing execution—deciding in advance what an agent is permitted to execute on each step regardless of how its prompt is manipulated. Box proposes a three-tier approval model (fully autonomous, monitored, and high-risk requiring human sign-off) and contends that legacy content platforms lack the metadata, classification, and logging depth needed to support agent governance.
    - Ceylan warns that bolting an agent connector onto legacy ECM stacks doesn't fix blind spots; it just hands agents the same gaps at machine speeds
    - Behavioral baselines calibrated to human activity are useless for agents because suspicious agent behavior doesn't resemble suspicious human behavior
    - Box cites recent incidents where models slipped sandboxes, reached out-of-scope systems, and read unauthorized content
    - "The sanctioned path has to be the fast path"—when teams lack a safe way to experiment, they route around controls entirely
  2. Wes Steyn writes that making an AI agent production-ready requires addressing observability, governance, deployment, and evaluation through a shared agent factory pattern. By defining the agent once in a single factory, developers can deploy the same core logic across different hosts—such as interactive consoles, hosted services on Foundry, or automated eval runners—while applying specific security constraints like disabling shell access for cloud environments.
    - Observability is achieved via OpenTelemetry to track model turns, tool calls, and token usage.
    - Microsoft Purview can be integrated via middleware to screen prompts and responses against organizational policies.
    - Hosted agents in Foundry automatically handle telemetry configuration through environment variables.
    - Local evaluations use simple functions for quick checks, while hosted evals provide model-graded quality scores like relevance and coherence.
    2026-08-29 Tags: , , , , by klotz
  3. The MeshCore development team announces a formal split within the project following internal disputes regarding brand ownership and the use of AI-generated code.

    A former team member is accused of attempting to claim the MeshCore trademark and rebranding components using "vibe coded" AI tools without team consensus. The core team clarifies that the only official source of truth remains the GitHub repository and has launched meshcore.io to serve as the new central hub for firmware, documentation, and community engagement.
    Main points:
    - Internal conflict regarding trademark filings and brand control.
    - Dispute over the use of AI-generated code versus human-crafted software.
    - Transition of official resources to the meshcore.io domain.
    - Introduction of the core development team members responsible for future updates.
  4. Abstract:
    >"The rapid development of advanced AI agents and the imminent deployment of many instances of these agents will give rise to multi-agent systems of unprecedented complexity. These systems pose novel and under-explored risks. In this report, we provide a structured taxonomy of these risks by identifying three key failure modes (miscoordination, conflict, and collusion) based on agents' incentives, as well as seven key risk factors (information asymmetries, network effects, selection pressures, destabilising dynamics, commitment problems, emergent agency, and multi-agent security) that can underpin them. We highlight several important instances of each risk, as well as promising directions to help mitigate them. By anchoring our analysis in a range of real-world examples and experimental evidence, we illustrate the distinct challenges posed by multi-agent systems and their implications for the safety, governance, and ethics of advanced AI."
    2026-02-01 Tags: , , , by klotz
  5. The article discusses the emergence of 'agentic traffic' – outbound API calls made by autonomous AI agents – and the need for a new infrastructure layer, an 'AI Gateway', to govern and secure this traffic. It outlines the components of an AI Gateway and the importance of security, compliance, and observability in managing agentic AI.
  6. Grammarly has achieved ISO/IEC 42001:2023 certification, demonstrating its commitment to responsible AI development and deployment, focusing on security, transparency, and alignment with human values.
  7. An article discussing ten predictions for the future of data science and artificial intelligence in 2025, covering topics such as AI agents, open-source models, safety, and governance.
  8. 2018-12-10 Tags: , , by klotz

Top of the page

First / Previous / Next / Last / Page 1 of 0 SemanticScuttle - klotz.me: tagged with "governance"

About - Propulsed by SemanticScuttle