{
 "name": "ApexClaw",
 "canonical": "https://apexclawai.com/",
 "category": "Evidence-grade agent trust layer",
 "summary": "Governance for AI agents that take real actions: policy gates before execution, approvals bound to actions, signed execution and refusal receipts, revocation and replay.",
 "generated": "2026-08-13",
 "page_count": 91,
 "claims_policy": "Every public claim is sourced, first-party with stated methodology, or labelled TARGET / SYNTHETIC / COLLECTING.",
 "pages": [
  {
   "url": "https://apexclawai.com/apexclaw-receipts/",
   "title": "ApexClaw Receipts \u2014 The Receipt Format Inside Our Governance Audit",
   "description": "ApexClaw Receipts is the draft receipt-format schema used inside ApexClaw's own governance audit: passports, policy decisions, approvals, execution and refusal receipts, revocation and replay. Not a standalone protocol or standard. Published for use and critique."
  },
  {
   "url": "https://apexclawai.com/answers/",
   "title": "The Answer Bank \u2014 362 Direct Answers on Agent Governance",
   "description": "A bank of 362 direct, citable answers on AI agent governance: identity, policy gates, receipts, MCP, wallets, OWASP ASI01-ASI10, EU AI Act, cost, audits and incidents. Machine-readable at /.well-known/answers.json."
  },
  {
   "url": "https://apexclawai.com/ask/",
   "title": "Ask ApexClaw - Agent-Queryable Answers on AI Agent Governance",
   "description": "The agent-queryable answer endpoint: 362 sourced, filterable answers on AI agent governance - identity, receipts, policy gates, MCP, wallets, OWASP, regulation. Machine index at /api/ask.json, MCP manifest at /.well-known/mcp.json."
  },
  {
   "url": "https://apexclawai.com/compare/",
   "title": "Agent Trust Layer vs Observability, Guardrails, Gateways & NHI \u2014 ApexClaw",
   "description": "How an agent trust layer differs from AI observability, guardrails, LLM gateways, non-human identity vendors, runtime security, audit logging and GRC platforms. Plus build-vs-buy and the four questions that separate the categories."
  },
  {
   "url": "https://apexclawai.com/compare/agent-governance-platform/",
   "title": "ApexClaw vs AI Agent Governance Platforms - Evidence vs Dashboards",
   "description": "How ApexClaw compares to AI agent governance platforms: governance platforms centralise policy, discovery and monitoring; ApexClaw adds the evidence layer - per-action authorization and signed execution receipts - underneath them."
  },
  {
   "url": "https://apexclawai.com/compare/build-in-house/",
   "title": "ApexClaw vs Building Agent Governance In-House - Total Cost of Evidence",
   "description": "How ApexClaw compares to building AI agent governance in-house: the honest comparison is total cost of evidence - the policy engine, receipt store, approval surface and their ongoing defence at audit - not licence price."
  },
  {
   "url": "https://apexclawai.com/compare/grc-policy-registry/",
   "title": "ApexClaw vs GRC & AI Policy Registry Tools - Proof vs Catalog",
   "description": "How ApexClaw compares to GRC and AI policy-registry tools: registries catalog policies, risks and attestations; ApexClaw proves each consequential agent action was authorized and produces tamper-evident receipts."
  },
  {
   "url": "https://apexclawai.com/compare/observability-monitoring/",
   "title": "ApexClaw vs AI Agent Observability & Monitoring - Governance vs Traces",
   "description": "How ApexClaw compares to AI agent observability and monitoring tools: traces show what happened; ApexClaw decides what is allowed to happen and proves it with signed, authorization-bound receipts."
  },
  {
   "url": "https://apexclawai.com/compare/runtime-guardrails/",
   "title": "ApexClaw vs AI Runtime Guardrails - Authorization vs Filtering",
   "description": "How ApexClaw compares to AI runtime guardrails and filters: guardrails filter model inputs and outputs; ApexClaw authorizes the downstream effect and proves it, closing the gap between a filtered prompt and an unproven action."
  },
  {
   "url": "https://apexclawai.com/contact/",
   "title": "Contact \u2014 ApexClaw",
   "description": "Three questions to get to the right starting point: what your agents can access, what consequence worries you most, and what you need next. Gap Brief, full audit, or incident response."
  },
  {
   "url": "https://apexclawai.com/demos/block-approve-tamper/",
   "title": "BLOCK / APPROVE / TAMPER \u2014 The Three-Case Control Test \u2014 ApexClaw",
   "description": "Three cases that separate a governed agent estate from an instrumented one: an out-of-scope action refused with a signed receipt, a payload-bound approval that refuses when the payload changes, and a tampered receipt that breaks chain verification."
  },
  {
   "url": "https://apexclawai.com/founder/",
   "title": "Founder \u2014 Julian Joseph \u2014 ApexClaw",
   "description": "ApexClaw was founded by Julian Joseph, who built and operates Omega, the governed autonomous system used as first-party evidence on this site."
  },
  {
   "url": "https://apexclawai.com/glossary/",
   "title": "AI Agent Governance Glossary \u2014 ApexClaw",
   "description": "Definitions for agent governance: agent passport, execution receipt, assurance gateway, autonomy budget, payload-bound approval, MCP, AP2, x402, kill switch, replay and more."
  },
  {
   "url": "https://apexclawai.com/",
   "title": "ApexClaw \u2014 Govern Every AI Agent Action, Prove Every One",
   "description": "ApexClaw is an evidence-grade agent trust layer: signed execution receipts, policy gates, human approvals, autonomy budgets, revocation and replay for autonomous AI agents. Govern every agent action before it happens. Prove every action afterward."
  },
  {
   "url": "https://apexclawai.com/industries/",
   "title": "AI Agent Governance by Industry - BFSI and Healthcare",
   "description": "How AI agent governance is examined in banking and healthcare: the instruments, the questions examiners actually ask, and the evidence that answers them."
  },
  {
   "url": "https://apexclawai.com/industries/bfsi/",
   "title": "AI Agent Governance for Banking & Financial Services \u2014 ApexClaw",
   "description": "DORA, OSFI E-23, SR 11-7, NYDFS Part 500, MAS FEAT, APRA CPS 230/234 and PSD2 mapped to agent governance. Why model risk management does not cover agents, and the seven questions an examiner asks."
  },
  {
   "url": "https://apexclawai.com/industries/healthcare/",
   "title": "AI Agent Governance in Healthcare \u2014 HIPAA, FDA and State Law",
   "description": "How HIPAA, FDA device thinking and state AI laws apply to AI agents in healthcare, where the clinical boundary sits, and what evidence regulators and health systems expect."
  },
  {
   "url": "https://apexclawai.com/platform/",
   "title": "The Agent Trust Layer \u2014 ApexClaw Platform",
   "description": "The ApexClaw platform is an evidence-grade agent trust layer: agent identity, policy enforcement, execution receipts, MCP governance, and wallet governance. The minimum trust spine for autonomous AI agents."
  },
  {
   "url": "https://apexclawai.com/platform/agent-identity/",
   "title": "Agent Identity & the Agent Passport \u2014 ApexClaw Platform",
   "description": "Cryptographic identity, named human ownership, mission scope, tool permissions, autonomy level and lifecycle for every AI agent. Covers non-human identity, least privilege, shadow agent discovery and delegation without impersonation."
  },
  {
   "url": "https://apexclawai.com/platform/agent-observability/",
   "title": "AI Agent Observability \u2014 Beyond Traces to Governance Evidence",
   "description": "Why agent observability differs from application observability: capturing decisions and authority rather than spans, and producing evidence that holds up in an audit."
  },
  {
   "url": "https://apexclawai.com/platform/agent-wallet-governance/",
   "title": "Agent Wallet & Payment Governance \u2014 AP2, x402 \u2014 ApexClaw",
   "description": "Governing AI agents that hold payment capability: AP2 cryptographic mandates, x402 settlement, hard fail-closed spend ceilings, merchant scoping, payment kill switch and authorization evidence for every transaction."
  },
  {
   "url": "https://apexclawai.com/platform/execution-receipts/",
   "title": "Execution Receipts & Replay \u2014 ApexClaw Platform",
   "description": "Signed, hash-chained execution receipts for AI agent actions: identity, policy version, payload-bound approval, outcome and chain verification. Includes replay and the BLOCK/APPROVE/TAMPER test."
  },
  {
   "url": "https://apexclawai.com/platform/mcp-governance/",
   "title": "MCP Governance \u2014 Identity, Authorization & Tool Exposure \u2014 ApexClaw",
   "description": "Governing Model Context Protocol servers and tools: the 2026-07-28 specification, Enterprise-Managed Authorization, OAuth 2.1 resource-server model, tool-exposure assessment, and the confused-deputy and token-passthrough failure modes."
  },
  {
   "url": "https://apexclawai.com/platform/policy-enforcement/",
   "title": "Policy Enforcement & the Assurance Gateway \u2014 ApexClaw Platform",
   "description": "Deny-by-default policy gates, payload-bound single-use expiring approvals, autonomy levels, circuit breakers and kill switches for AI agents. Why a guardrail filters and a gate authorizes."
  },
  {
   "url": "https://apexclawai.com/platform/post-quantum-agent-evidence/",
   "title": "Post-Quantum Agent Evidence \u2014 Will Your Receipts Still Verify? \u2014 ApexClaw",
   "description": "Agent execution receipts are signed, retained for years, and mostly not quantum-safe. ML-DSA, SLH-DSA, CNSA 2.0's January 2027 deadline, the FIPS 140-2 sunset, crypto agility, and harvest-now-forge-later."
  },
  {
   "url": "https://apexclawai.com/platform/revocation-kill-switch/",
   "title": "Agent Revocation and Kill Switch \u2014 Stopping an Agent That Acts",
   "description": "How to revoke an AI agent's authority and stop it mid-flight: revocation propagation, blast-radius scoping, in-flight action handling and proving the stop actually took effect."
  },
  {
   "url": "https://apexclawai.com/pricing/",
   "title": "AI Agent Governance Pricing - How ApexClaw Is Scoped and Priced",
   "description": "How ApexClaw agent governance is priced: the three cost layers (platform, integration, operation), why scope precedes price, the minimum useful engagement, and where the Agent Trust Gap Brief fits."
  },
  {
   "url": "https://apexclawai.com/proof/omega-governed-run/",
   "title": "Omega: A Governed Run, With the Failures Visible \u2014 ApexClaw",
   "description": "Omega is an autonomous system running under ApexClaw's own controls: refusals on unauthorized sends, receipts emitted, zero real external sends. Published with its limitations rather than as a case study."
  },
  {
   "url": "https://apexclawai.com/regions/",
   "title": "AI Agent Governance by Region \u2014 Seven Regulatory Regimes",
   "description": "How AI agent governance differs across the EU, US, Middle East, Canada, APAC, Latin America and the UK \u2014 the instruments that bind, dated and sourced."
  },
  {
   "url": "https://apexclawai.com/regions/asia-pacific/",
   "title": "AI Agent Governance in Asia-Pacific \u2014 Singapore, Korea, Japan",
   "description": "Singapore's agentic AI framework is the only major published framework addressing AI agents directly. Korea's AI Basic Act, Japan's approach and APRA's prudential expectations complete the picture."
  },
  {
   "url": "https://apexclawai.com/regions/canada/",
   "title": "AI Agent Governance in Canada \u2014 OSFI E-23 and What Replaced AIDA",
   "description": "AIDA did not pass. OSFI Guideline E-23 applies from May 2027 and is the real Canadian agent-governance deadline for federally regulated financial institutions."
  },
  {
   "url": "https://apexclawai.com/regions/european-union/",
   "title": "AI Agent Governance in the European Union \u2014 What Applies",
   "description": "What the EU AI Act, the Digital Omnibus deferral, DORA and national measures actually require of AI agents that take actions, and what evidence supervisors expect."
  },
  {
   "url": "https://apexclawai.com/regions/latin-america/",
   "title": "AI Agent Governance in Latin America \u2014 Brazil PL 2338",
   "description": "Brazil's PL 2338 is the region's most advanced AI bill and follows a risk-tiered structure familiar from the EU. What that means for AI agents, plus the data-protection regimes that bind today."
  },
  {
   "url": "https://apexclawai.com/regions/middle-east/",
   "title": "AI Agent Governance in the Middle East \u2014 DIFC, UAE, Saudi",
   "description": "DIFC Regulation 10 enforced from January 2026, the Autonomous Systems Officer role, the UAE federal AI authority and Saudi SDAIA guidance \u2014 what binds AI agents and what does not."
  },
  {
   "url": "https://apexclawai.com/regions/united-kingdom/",
   "title": "AI Agent Governance in the United Kingdom \u2014 Regulator-Led",
   "description": "The UK has no AI act. Governance runs through existing regulators \u2014 FCA, ICO, Ofcom \u2014 using existing powers, plus UK GDPR and sectoral rules. What that means for AI agents."
  },
  {
   "url": "https://apexclawai.com/regions/united-states/",
   "title": "AI Agent Governance in the United States \u2014 State Patchwork",
   "description": "How Texas TRAIGA's safe harbor, Colorado SB 26-189, California transparency rules and federal sectoral supervision apply to AI agents that take actions."
  },
  {
   "url": "https://apexclawai.com/resources/",
   "title": "AI Agent Governance Resources \u2014 Articles and Reference",
   "description": "Reference articles on AI agent governance: definitions, control checklists, non-human identity, execution receipts, AI search citation, and incident response."
  },
  {
   "url": "https://apexclawai.com/resources/agent-execution-receipts-explained/",
   "title": "Execution Receipts Explained \u2014 Evidence an AI Agent Can Produce",
   "description": "What an execution receipt contains, why application logs are not evidence, how receipt chains provide integrity, and what replay does and does not prove."
  },
  {
   "url": "https://apexclawai.com/resources/agent-governance-audit-checklist/",
   "title": "The Agent Governance Audit Checklist \u2014 Copyable, 2026",
   "description": "A copyable AI agent governance audit checklist: inventory, identity, permissions, policy gates, approvals, receipts, revocation, and the evidence each control must produce to count."
  },
  {
   "url": "https://apexclawai.com/resources/agent-governance-cost/",
   "title": "What Agent Governance Actually Costs \u2014 A 2026 Breakdown",
   "description": "What AI agent governance costs in 2026: the three budget layers, the minimum defensible deployment, what ungoverned agents cost when they fail, and why retrofitting is the expensive path."
  },
  {
   "url": "https://apexclawai.com/resources/agent-governance-evidence-report-2026/",
   "title": "The Agent Governance Evidence Report 2026 - First-Party Research",
   "description": "Original first-party research: a dated measurement of what AI answer engines tell buyers about the agent-governance category, and what running our own governance against a live autonomous system produced - refusals, receipts, the acceptance-gauntlet PASS, and the parts not yet working."
  },
  {
   "url": "https://apexclawai.com/resources/agent-incident-patterns/",
   "title": "AI Agent Incident Patterns \u2014 What Public Post-Mortems Repeat",
   "description": "The failure patterns public AI agent incidents repeat: excessive agency, injection-to-action chains, cascade amplification, memory poisoning, and the missing-evidence problem every post-mortem cites."
  },
  {
   "url": "https://apexclawai.com/resources/agent-incident-what-to-do/",
   "title": "An AI Agent Did Something Wrong \u2014 What To Do First",
   "description": "The first hour after an AI agent takes a harmful action: contain, preserve evidence, establish scope, notify, and the mistake that destroys your ability to explain what happened."
  },
  {
   "url": "https://apexclawai.com/resources/agentic-ai-governance-statistics/",
   "title": "Agentic AI Governance Statistics - Sourced and Dated",
   "description": "A sourced reference of agentic AI governance facts: regulatory deadlines (DIFC, OSFI E-23, CNSA 2.0, FIPS 140-2), adoption figures with caveats, and first-party measurements with methodology."
  },
  {
   "url": "https://apexclawai.com/resources/ai-agent-governance-checklist/",
   "title": "AI Agent Governance Checklist \u2014 12 Controls Before Production",
   "description": "A concrete pre-production checklist for AI agents that take actions: action inventory, least privilege, approval gates, idempotency, caps, receipts, revocation and testing."
  },
  {
   "url": "https://apexclawai.com/resources/choosing-agent-governance/",
   "title": "How to Choose an AI Agent Governance Approach - A Buyer's Guide",
   "description": "A decision aid for choosing AI agent governance: start from the action inventory, the minimum any solution must do, build-vs-buy on total cost of evidence, and the questions that expose a weak control."
  },
  {
   "url": "https://apexclawai.com/resources/how-ai-search-engines-cite-sources/",
   "title": "How AI Search Engines Choose What to Cite",
   "description": "Why AI answer engines cite some pages and paraphrase around others: crawler access, extractability, sourcing and off-site corroboration \u2014 the four gates in order."
  },
  {
   "url": "https://apexclawai.com/resources/non-human-identity-agents/",
   "title": "Non-Human Identity for AI Agents \u2014 NHI, Secrets and Scope",
   "description": "Why AI agents break traditional identity models, how non-human identity applies, and what to do about credential sprawl, over-scoped service accounts and unattributable actions."
  },
  {
   "url": "https://apexclawai.com/resources/what-is-agent-governance/",
   "title": "What Is AI Agent Governance? Definition, Scope and How It Differs",
   "description": "AI agent governance defined: the control point between an agent's decision and its effect - identity, policy gates, approvals and signed receipts - and how it differs from AI safety, guardrails and observability."
  },
  {
   "url": "https://apexclawai.com/resources/what-is-an-ai-agent/",
   "title": "What Is an AI Agent \u2014 A Definition That Survives Scrutiny",
   "description": "An AI agent is software that pursues a goal by choosing and taking actions with real effects. The distinction that matters for governance is not autonomy, it is whether it can act."
  },
  {
   "url": "https://apexclawai.com/roles/",
   "title": "Who Owns AI Agent Governance \u2014 Roles and Accountability",
   "description": "Which role owns AI agent governance: CISO, Chief AI Officer, model risk, compliance, platform engineering \u2014 and what each is accountable for when an agent acts."
  },
  {
   "url": "https://apexclawai.com/services/",
   "title": "Growth Services \u2014 Delivered by ThruLiquid \u2014 ApexClaw",
   "description": "The full ThruLiquid service catalog: AI search visibility, GEO/AEO, content authority, enterprise SEM and SEO, LinkedIn ABM, outbound, GTM engineering, RevOps and attribution. Partner company to ApexClaw."
  },
  {
   "url": "https://apexclawai.com/services/abm/",
   "title": "ABM Services \u2014 Account-Based Marketing for Technical Buyers",
   "description": "Account-based marketing built on named-account targeting, buying-committee mapping and measurement tied to pipeline rather than impressions."
  },
  {
   "url": "https://apexclawai.com/services/ai-search-visibility-audit/",
   "title": "AI Search Visibility Audit \u2014 Get Cited by AI Answer Engines",
   "description": "A structured audit of whether AI answer engines can find, parse, trust and cite your content \u2014 covering crawler access, extractability, entity clarity and off-site consensus."
  },
  {
   "url": "https://apexclawai.com/services/analytics-attribution/",
   "title": "Attribution Engineering \u2014 Warehouse-Native Multi-Touch \u2014 ThruLiquid Services",
   "description": "Warehouse-native multi-touch attribution: modelling built on the data warehouse connecting ad platforms, web analytics and CRM into one pipeline-attribution model finance will defend."
  },
  {
   "url": "https://apexclawai.com/services/content-authority/",
   "title": "Content & Entity Authority \u2014 Being the Cited Source \u2014 ThruLiquid Services",
   "description": "Content and entity authority engineering: definition-first content, corroborating off-site consensus, and knowledge-graph presence that makes a brand the source AI engines cite and buyers trust."
  },
  {
   "url": "https://apexclawai.com/services/enterprise-sem/",
   "title": "Enterprise SEM, Measured in Pipeline \u2014 ThruLiquid Services",
   "description": "Enterprise search engine marketing measured in attributed pipeline, not clicks: named-account visibility, intent capture across Google and Microsoft Ads, and attribution a finance team accepts."
  },
  {
   "url": "https://apexclawai.com/services/enterprise-seo-migration/",
   "title": "Enterprise SEO & Migration Protection \u2014 ThruLiquid Services",
   "description": "Enterprise SEO as revenue infrastructure: technical architecture, entity consistency, and migration protection through rebrands, domain moves and platform changes without losing accumulated search equity."
  },
  {
   "url": "https://apexclawai.com/services/geo-aeo/",
   "title": "GEO and AEO Services \u2014 Generative and Answer Engine Optimisation",
   "description": "Generative Engine Optimisation and Answer Engine Optimisation: making content extractable, sourced and corroborated so AI answer engines cite it rather than paraphrase around it."
  },
  {
   "url": "https://apexclawai.com/services/gtm-engineering/",
   "title": "GTM Engineering \u2014 Signal-Based Outbound Systems \u2014 ThruLiquid Services",
   "description": "GTM engineering: signal-driven target detection, enrichment, routing and sequencing systems that let a small revenue team operate with the reach of a large one \u2014 governed, deliverable, and measured in meetings."
  },
  {
   "url": "https://apexclawai.com/services/linkedin-abm/",
   "title": "LinkedIn ABM \u2014 Account-Based Marketing on LinkedIn \u2014 ThruLiquid Services",
   "description": "LinkedIn account-based marketing run against a named account list: buying-committee targeting, MAL measurement, webinar and content programs that produce marketing-accepted leads from target accounts."
  },
  {
   "url": "https://apexclawai.com/services/outbound/",
   "title": "Outbound Services \u2014 Deliverability, Sequencing and Compliance",
   "description": "Outbound built on deliverability infrastructure, defensible targeting and lawful-basis discipline \u2014 the parts that determine whether a programme works at all."
  },
  {
   "url": "https://apexclawai.com/services/revops/",
   "title": "RevOps Services \u2014 Data, Routing and Reporting You Can Trust",
   "description": "Revenue operations: CRM data integrity, lead routing, lifecycle definitions and reporting that survives scrutiny \u2014 the foundation every other GTM investment depends on."
  },
  {
   "url": "https://apexclawai.com/solutions/",
   "title": "Agent Governance Solutions & Assessments \u2014 ApexClaw",
   "description": "Agent Trust Gap Brief, Agent Trust Audit, incident response, inventory and permission mapping, MCP tool-exposure assessment, evidence and replay assessment, revocation testing, and governed pilots."
  },
  {
   "url": "https://apexclawai.com/solutions/agent-incident-response/",
   "title": "AI Agent Incident Response \u2014 ApexClaw",
   "description": "What to do when an AI agent acts outside what you intended: contain, preserve, bound the blast radius, establish whether it was authorized or merely unstopped, and reconstruct from receipts."
  },
  {
   "url": "https://apexclawai.com/solutions/agent-trust-audit/",
   "title": "Agent Trust Audit \u2014 Inventory, Controls, Evidence \u2014 ApexClaw",
   "description": "A full assessment of your AI agent estate: inventory and permission mapping, MCP tool-exposure, evidence and replay testing, revocation and kill-switch verification, and a remediation roadmap ordered by blast radius."
  },
  {
   "url": "https://apexclawai.com/solutions/agent-trust-gap-brief/",
   "title": "Agent Trust Gap Brief \u2014 ApexClaw",
   "description": "A short, evidence-based read of your AI agent risk surface: inventory snapshot, ranked trust gaps, evidence gaps, standards mapping, one recommended next control, and stated limitations."
  },
  {
   "url": "https://apexclawai.com/standards/",
   "title": "AI Agent Control Crosswalk \u2014 OWASP ASI, NIST AI RMF, ISO 42001, EU AI Act",
   "description": "Twelve agent governance controls mapped across OWASP Top 10 for Agentic Applications 2026, NIST AI RMF, ISO/IEC 42001 and the EU AI Act. Published for checking, not as a compliance claim."
  },
  {
   "url": "https://apexclawai.com/standards/agent-assurance-frameworks/",
   "title": "AI Agent Assurance Frameworks \u2014 What Exists and What Certifies",
   "description": "Which AI assurance frameworks are certifiable, which are voluntary, and which carry legal weight \u2014 ISO 42001, NIST AI RMF, SOC 2, OWASP ASI and the EU AI Act compared."
  },
  {
   "url": "https://apexclawai.com/standards/agent-audit-and-attestation/",
   "title": "AI Agent Audit, Attestation & Red Teaming \u2014 What Exists in 2026 \u2014 ApexClaw",
   "description": "Assessment, attestation, certification and red teaming are not interchangeable. CSA STAR for AI, ISO/IEC 42001, AI-CAIQ, MITRE ATLAS, PyRIT, garak, Inspect, DeepTeam \u2014 and why no ratified agent certification exists yet."
  },
  {
   "url": "https://apexclawai.com/standards/eu-ai-act-ai-agents/",
   "title": "EU AI Act for AI Agents \u2014 What Still Applies After the Digital Omnibus",
   "description": "The Digital Omnibus deferred Annex III high-risk obligations to December 2027 and Annex I to August 2028, but most transparency obligations took effect 2 August 2026. Article-by-article for agent operators."
  },
  {
   "url": "https://apexclawai.com/standards/mcp-2026-07-28/",
   "title": "MCP 2026-07-28 Migration & Authorization Hardening \u2014 ApexClaw",
   "description": "The Model Context Protocol 2026-07-28 specification: stateless core, authorization hardening onto OAuth 2.1, Enterprise-Managed Authorization, and the twelve-month deprecation window closing in July 2027."
  },
  {
   "url": "https://apexclawai.com/standards/nist-ai-rmf-agents/",
   "title": "NIST AI RMF for AI Agents \u2014 and the TRAIGA Affirmative Defense",
   "description": "NIST AI RMF read for agentic systems: GOVERN, MAP, MEASURE, MANAGE mapped to agent identity, tool inventory, execution receipts and kill switches. Plus the Texas TRAIGA affirmative defence."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-security/",
   "title": "OWASP Agentic Security - Risks, Controls, Evidence",
   "description": "OWASP agentic security explained: the Agentic Top 10 taxonomy (ASI01-ASI10), the control that answers each risk, and the evidence that proves controls actually fire."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/",
   "title": "OWASP Top 10 for Agentic Applications 2026 (ASI01\u2013ASI10) \u2014 Controls & Evidence",
   "description": "All ten OWASP agentic risks, ASI01 through ASI10, each with how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/agent-goal-hijack/",
   "title": "ASI01 Agent Goal Hijack \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI01 Agent Goal Hijack from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/agentic-supply-chain/",
   "title": "ASI04 Agentic Supply Chain Vulnerabilities \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI04 Agentic Supply Chain Vulnerabilities from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/cascading-failures/",
   "title": "ASI08 Cascading Failures \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI08 Cascading Failures from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/human-agent-trust-exploitation/",
   "title": "ASI09 Human-Agent Trust Exploitation \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI09 Human-Agent Trust Exploitation from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/identity-and-privilege-abuse/",
   "title": "ASI03 Identity and Privilege Abuse \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI03 Identity and Privilege Abuse from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/insecure-inter-agent-communication/",
   "title": "ASI07 Insecure Inter-Agent Communication \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI07 Insecure Inter-Agent Communication from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/memory-and-context-poisoning/",
   "title": "ASI06 Memory and Context Poisoning \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI06 Memory and Context Poisoning from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/rogue-agents/",
   "title": "ASI10 Rogue Agents \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI10 Rogue Agents from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/tool-misuse-and-exploitation/",
   "title": "ASI02 Tool Misuse and Exploitation \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI02 Tool Misuse and Exploitation from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/standards/owasp-agentic-top-10/unexpected-code-execution/",
   "title": "ASI05 Unexpected Code Execution \u2014 Controls, Evidence & Limitations \u2014 ApexClaw",
   "description": "ASI05 Unexpected Code Execution from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation."
  },
  {
   "url": "https://apexclawai.com/trust/",
   "title": "Trust Center \u2014 Claims Ledger, Agent Identity & Crawler Posture \u2014 ApexClaw",
   "description": "Every ApexClaw claim with its basis, verification date and expiry. ApexClaw Receipts endpoints, RFC 9421 readiness, Web Bot Auth as a draft not a standard, and the observe-not-block crawler posture."
  },
  {
   "url": "https://apexclawai.com/updates/",
   "title": "ApexClaw Updates - What Changed and When",
   "description": "A dated log of ApexClaw platform and content updates: new pages, standards coverage, machine-layer changes and governance guides, newest first. Machine-readable at /rss.xml."
  },
  {
   "url": "https://apexclawai.com/use-cases/",
   "title": "AI Agent Use Cases \u2014 Governed Automation by Workload",
   "description": "How AI agent governance differs by workload \u2014 field service, healthcare, revenue and procurement \u2014 and the controls each one actually needs."
  },
  {
   "url": "https://apexclawai.com/use-cases/healthcare-agent-governance/",
   "title": "Healthcare AI Agent Governance \u2014 HIPAA, Scope and Evidence",
   "description": "Governing AI agents in healthcare operations: scheduling, prior authorisation, patient messaging and records. Where the clinical line sits and what evidence a regulator expects."
  },
  {
   "url": "https://apexclawai.com/use-cases/procurement-agent-governance/",
   "title": "Procurement Agent Governance \u2014 RFPs, Tenders and Bids",
   "description": "Governing AI agents across procurement and tendering: what the agent may submit, how bid integrity is preserved, and the evidence a public buyer or auditor will expect."
  },
  {
   "url": "https://apexclawai.com/use-cases/revenue-agent-governance/",
   "title": "Revenue Agent Governance \u2014 Outbound, CRM and Pipeline",
   "description": "Governing AI agents across outbound, CRM writes and pipeline: sending limits, data-protection duties, deliverability risk and the evidence that proves what was sent to whom."
  }
 ],
 "agent_query": {
  "ask": "https://apexclawai.com/api/ask.json",
  "mcp": "https://apexclawai.com/.well-known/mcp.json"
 }
}