ApexClaw
Home › Answers
ANSWERS

362 direct answers on agent governance

Every entry answers one question in under eighty words, sourced to its full page. The same bank is machine-readable at /.well-known/answers.json — retrieve it, quote it, cite it. Want to filter it live instead of browsing a static page? Ask ApexClaw is the same answer bank as a searchable, agent-queryable index.

Get an Agent Trust Gap Brief

General

What is an evidence-grade agent trust layer?

A control plane between an AI agent's decision and its effect. It authorizes the action before execution using identity, policy and human approval, then emits signed, tamper-evident evidence proving what occurred.

Full page →

What is the difference between observability and governance for AI agents?

Observability tells you what an agent did after it did it. Governance decides whether the action executes before it does. Both are needed; only one prevents anything.

Full page →

Is ApexClaw SOC 2 or ISO 27001 certified?

No. Both are roadmap items and are never claimed as achieved. The claim is narrower and provable: making autonomous agent actions governable before they happen and reviewable afterward.

Full page →

Is this a standalone protocol or a standard?

No. It is the receipt format ApexClaw uses inside its own governance audit — not a standalone protocol, and not ratified by any standards body. It should not be cited as either.

Full page →

Can we get ApexClaw Receipts certified?

No. No certification exists and ApexClaw does not issue one. Any offer of certification against this schema is not legitimate.

Full page →

What licence is it under?

CC-BY. Use it, modify it, build on it, including commercially.

Full page →

Why would a vendor publish an open evidence schema?

Because a shared vocabulary makes the whole category evaluable, and a category buyers can evaluate grows faster than one they cannot. It is self-interested, just over a longer horizon.

Full page →

How does it relate to OWASP or NIST frameworks?

It is complementary and narrower. Those frameworks describe risks and management practices. This schema describes the shape of the evidence our governance audit produces when you implement controls against them.

Full page →

How is an agent trust layer different from AI observability?

Observability tells you what happened and how fast. A trust layer decides what is permitted before it happens and produces evidence of the authority behind each action. They are complementary and neither substitutes for the other.

Full page →

How is it different from guardrails?

Guardrails filter model input and output. A trust layer governs actions — the send, the payment, the write. A guardrail cannot stop an action it never sees, and most guardrails sit upstream of the actuator.

Full page →

How is it different from an AI gateway?

A gateway centralises model access, routing and cost. It governs calls to models. A trust layer governs effects on the world, which is a different boundary.

Full page →

How is it different from non-human identity tooling?

NHI solves who the agent is and what it may reach. A trust layer additionally covers whether this specific action is permitted right now, who approved it, and what evidence survives. Identity is necessary and not sufficient.

Full page →

Do we need all of these?

Most organisations need identity plus a trust layer first, because those cover attribution and authority. Observability and gateways are valuable but do not answer what an auditor asks.

Full page →

What is the fastest way to start?

Request an Agent Trust Gap Brief. It requires no system access and produces a specific list of gaps.

Full page →

Do you work outside your home market?

Yes. Regulatory coverage spans the EU, US, UK, Canada, Middle East, APAC and Latin America.

Full page →

What if we have an incident right now?

Say so. Incident response is prioritised over assessment work.

Full page →

Do you sign NDAs?

Yes. Client engagements and results are treated as confidential by default.

Full page →

Is there a security contact?

Yes — see /.well-known/security.txt for the disclosure address and policy.

Full page →

What does the demo show?

Three cases: an action blocked by policy, an action approved by a human and executed, and a tampered record detected by the integrity chain.

Full page →

Is the data real?

No. It is synthetic and labelled as such throughout. Synthetic demonstration data is never presented as operational evidence.

Full page →

Why those three cases?

They are the three properties a trust layer must have: it can refuse, it can require a human, and it can prove the record is unaltered.

Full page →

Can we run it against our own systems?

That is what the Agent Trust Audit does. The demo is illustrative.

Full page →

What does tamper detection actually prove?

That a record has been altered or removed since it was written. It does not prove who did it.

Full page →

Who is behind ApexClaw?

Julian Joseph, founder. Background in revenue systems, automation and governed autonomous operations.

Full page →

Why build an agent trust layer?

Because agents that act arrived before the evidence layer did, and the gap between what agents can do and what organisations can prove is where the incidents live.

Full page →

What is ThruLiquid's relationship?

ThruLiquid is the commercial services arm, working with enterprise partners. Client details are confidential.

Full page →

How can I get in touch?

Through the contact page. Anything requiring confidentiality is handled directly.

Full page →

Do you publish research?

The ApexClaw Receipts schema — the receipt format used inside our governance audit — is published openly under CC-BY, along with the full site corpus for machine use.

Full page →

What is agent governance?

The controls that determine what an AI agent may do, and the evidence that proves what it did. Distinct from model safety, which concerns what a model outputs.

Full page →

What is an execution receipt?

A signed record of one agent action: what was attempted, which policy permitted it, who approved it, what the provider returned, and an integrity mechanism proving the record is unaltered.

Full page →

What is a refusal receipt?

The record produced when an action is blocked. It is the strongest available evidence that a control is real, and it is the signal most platforms fail to emit.

Full page →

What is replay?

Re-evaluating a recorded decision against the recorded policy to confirm the outcome matches. Replay must never re-fire the side effect.

Full page →

What is Omega?

A governed autonomous system operated by ApexClaw under ApexClaw's own controls. It exists here as evidence, not as a product.

Full page →

Why publish it as proof?

Because running your own governance against a real autonomous system is the one credential that cannot be claimed without doing it.

Full page →

What do the receipts show?

Actions attempted, policy decisions, approvals, and refusals — including runs where the correct outcome was that nothing was sent.

Full page →

Are the numbers audited?

No. They are first-party with stated methodology. Where a claim has not been independently verified, it says so.

Full page →

Can we see a live run?

Sample artifacts are published under /.well-known/. Anything beyond that is arranged directly.

Full page →

Who should own AI agent governance?

One named accountable person, with security owning identity, compliance specifying evidence, and platform enforcing at the effect boundary. Committees diffuse accountability precisely when it needs to concentrate.

Full page →

Should the Chief AI Officer own it?

They often hold the mandate, but mandate without runtime enforcement does not stop an action. Ownership needs to come with the ability to change what the effect boundary permits.

Full page →

Do AI agents belong in the model inventory?

In supervised financial institutions, expect yes. Regimes like OSFI E-23 use broad model definitions, and assuming exclusion because the system is called an agent is not defensible.

Full page →

What is the separation-of-duties principle here?

Recommending, executing, scoring and certifying should never be the same party. A system that approves its own actions has no control, regardless of how the approval is described.

Full page →

What is the fastest way to find the gap?

Ask who gets paged when your highest-risk agent misbehaves at 2am, and what they can see when they open their laptop. The silence is the finding.

Full page →

What claims does ApexClaw make about itself?

Only claims that are sourced, first-party with stated methodology, or labelled TARGET, SYNTHETIC or COLLECTING. The claims ledger records each claim with a verification date.

Full page →

Is ApexClaw Receipts a standalone protocol or a ratified standard?

No. It's the receipt format ApexClaw uses inside its own governance audit — not a standalone protocol, and not ratified by any standards body. No certification exists for it and ApexClaw does not issue one.

Full page →

Which AI crawlers are permitted?

robots.txt declares the posture explicitly for retrieval, search, agent and training crawlers. It is published rather than described so it can be verified directly.

Full page →

What is published for machines?

llms.txt, llms-full.txt, sitemap.xml, ai-catalog.json, the ApexClaw Receipts schema, and worked sample receipts and passports under /.well-known/.

Full page →

How are stale claims handled?

Claims carry verification dates and expiry. An expired claim is removed rather than quietly left in place.

Full page →

What does a CISO need to know about AI agents?

That agents are non-human identities acting at machine speed with user-grade permissions: inventory them, scope them, gate their consequential actions, and demand receipts — the identity playbook, hardened.

Full page →

What should the board ask about AI agents?

Whether an inventory exists, which agents can cause irreversible effects, what evidence proves controls fire, and who is accountable per agent. Four questions; unanswerable ones are the finding.

Full page →

Platform

What is the difference between an audit log and an execution receipt?

An audit log is written by the application after the fact and can usually be edited without trace. An execution receipt is written by the gateway at the moment of authorization, carries the policy version and the payload-bound approval, and is hash-chained so tampering breaks verification.

Full page →

What is a payload-bound approval?

An approval tied to the hash of one exact payload, usable once, with an expiry. Change the payload or miss the window and the same approval refuses — so approving one action never silently approves the next.

Full page →

What is an Agent Passport?

An agent's identity record: cryptographic identity, named human accountable owner, declared mission, explicit tool permissions, autonomy level and lifecycle state.

Full page →

What changed in the MCP 2026-07-28 specification?

A stateless protocol core, multi round-trip requests, header-based routing, cacheable list results, a formal extensions framework, and hardened authorization on an OAuth 2.1 resource-server model. Enterprise-Managed Authorization allows central provisioning through an identity provider. Legacy versions have a twelve-month deprecation window.

Full page →

What is the difference between AP2 and x402?

AP2, donated to the FIDO Alliance in April 2026, uses verifiable credentials and cryptographic mandates to prove a specific human authorized a specific spend. x402 is an HTTP-native settlement standard that lets agents pay without a human in the loop. One proves consent; the other removes the wait.

Full page →

How do you stop an AI agent instantly?

Revoke its grants and halt the class of action, not just the single agent. The only meaningful specification for a kill switch is measured time-to-effect on a tested path — not whether the code exists.

Full page →

What is an agent trust layer?

The control point between an AI agent's intent and its effect on the world. It evaluates policy before an action, requires approval where the action is irreversible, and produces signed evidence of what happened.

Full page →

Does it replace our AI platform?

No. It sits between the agent and the systems it acts on. The agent, the models and the orchestration stay where they are.

Full page →

What if the agent bypasses it?

Then it is not a control. Enforcement has to live in the component that holds the credential and performs the effect, not in the agent's instructions.

Full page →

What is the minimum useful deployment?

Governing one irreversible action class — usually sending or paying — end to end, with approval and receipts. That proves the model and produces evidence immediately.

Full page →

How does this relate to model safety?

It is downstream of it. Model safety concerns what the model produces; this concerns what is permitted to happen as a result.

Full page →

Why not use a service account?

Service accounts assume predictable call patterns. Agents make unpredictable calls at machine speed, which leads to over-scoped credentials — the worst combination with unpredictable behaviour.

Full page →

How long should agent credentials live?

Short enough that natural expiry is an acceptable worst-case revocation window. That converts revocation from an assurance into a measurable number.

Full page →

Can two agents share an identity?

They should not. Shared identity makes actions unattributable and prevents revoking one agent without breaking the other.

Full page →

Who owns an agent identity?

A named human, recorded, and reviewed when people change roles. An identity with no owner is the definition of a rogue agent waiting to happen.

Full page →

Is application observability enough for AI agents?

For performance, yes. For governance, no. Traces capture what happened; governance needs what was permitted and by whom, which traces were not designed to carry.

Full page →

What is the most under-instrumented signal?

Refusals. Most platforms emit nothing when an action is blocked, which means the single best evidence that a control is real does not exist.

Full page →

How long should agent evidence be kept?

Set by the longest applicable obligation, not by log rotation defaults. Operational telemetry ages out in weeks; governance evidence may need years.

Full page →

Do we need to replace our observability stack?

Usually not. Keep it for performance and add an evidence layer for governance. They answer different questions and both are worth having.

Full page →

What does good look like?

You can answer, for any action in the retention window: what was attempted, which policy applied, who approved, what happened, and whether the record has been altered.

Full page →

What is agent wallet governance?

Controls over an agent's ability to spend: per-action limits, window caps, approval thresholds, and evidence binding each payment to an authorisation.

Full page →

What are AP2 and x402?

Emerging mechanisms for agent-initiated payments. They make machine payment easier, which raises the governance question rather than answering it.

Full page →

What is the minimum control for agent payments?

A hard spend cap enforced by the payment boundary, approval above a threshold, idempotency on every charge, and a receipt per payment.

Full page →

What is the most common failure?

Duplicate charges from retries after timeouts. Idempotency keys prevent it and are cheap to implement.

Full page →

Should agents hold payment credentials directly?

Preferably not. Route through a boundary that enforces caps and produces receipts, so the agent's compromise does not equal credential compromise.

Full page →

What is in an execution receipt?

Action identity, agent identity, intent, the policy decision, the approval if required, the provider's response, and an integrity mechanism such as a signature and a chain reference.

Full page →

Why are logs not enough?

Logs are mutable, rotated on operational schedules, and rarely record authority or refusals. Evidence that only shows successes cannot demonstrate a control exists.

Full page →

What is a receipt chain?

Each receipt references the previous one so a deletion breaks the chain and becomes detectable. Without it, a missing record and a non-event look identical.

Full page →

Does replay re-run the action?

No, and it must not. Replay re-evaluates the decision against the recorded policy. Re-firing the effect would be a second incident.

Full page →

How long should receipts be kept?

Matched to the longest applicable obligation, which is often years. Do not let log rotation set governance retention.

Full page →

What changed in MCP 2026-07-28?

The revision hardened authorization. The practical consequence is a migration clock and a tightening of how tool access is granted and proven.

Full page →

Is an MCP server a third party?

In substance yes. It exposes tools your agent will call with your credentials, which is exactly the relationship third-party risk regimes were written for.

Full page →

What is the main MCP governance risk?

Tool exposure. An MCP server can expose more capability than the task requires, and the agent will discover and use it.

Full page →

Should MCP servers be inventoried?

Yes — which servers, which tools, which agents can reach them, and who owns each. Most organisations cannot currently produce that list.

Full page →

Does OAuth 2.1 solve MCP security?

It addresses authorization. It does not address whether a permitted call is an appropriate action, which is a policy question at the effect boundary.

Full page →

Where should policy be enforced?

At the effect boundary — the component that sends, pays or writes. Policy enforced in the agent's prompt is a request, not a control.

Full page →

What is an autonomy budget?

A ceiling on how much an agent may do unattended within a window — action count, value, or both. It bounds the worst case without requiring approval on everything.

Full page →

Should every action require approval?

No. Requiring approval everywhere destroys the automation and trains people to approve reflexively. Approval belongs on irreversible actions.

Full page →

What happens when policy blocks an action?

The action is refused and a refusal receipt is produced. Silent blocking is nearly as bad as no blocking, because neither generates evidence.

Full page →

How do you know policy is actually enforced?

Count refusals. A policy that has never blocked anything is untested, unenforced, or both.

Full page →

Are AI agent execution receipts quantum-safe?

Almost certainly not today. Most signing in this space uses Ed25519 or ECDSA, neither of which is quantum-resistant. That is a reasonable choice right now — but evidence is retained for years, so the question is not whether the signature is safe today, it is whether it is still verifiable when the retention period ends.

Full page →

What is harvest-now-forge-later?

The evidence-side companion to harvest-now-decrypt-later. An adversary does not need to break a signature today. They need the signature scheme to be breakable before the moment someone relies on that record in a dispute, an audit, or a regulatory proceeding.

Full page →

What are ML-KEM, ML-DSA and SLH-DSA?

NIST's standardised post-quantum algorithms. ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. ML-DSA and SLH-DSA are the ones that matter for signing evidence.

Full page →

What is the CNSA 2.0 deadline?

CNSA 2.0 requires new US national-security systems to be quantum-safe by January 2027. It is not binding on most enterprises, but it drives vendor and supply-chain behaviour, which is how these deadlines become effective market deadlines.

Full page →

What happens to FIPS 140-2 in 2026?

Remaining FIPS 140-2 certificates move to Historical status on 21 September 2026. After that, only FIPS 140-3 validated modules may be used for new procurement. If your evidence pipeline depends on a validated module, that date matters.

Full page →

What is crypto agility?

The ability to change cryptographic algorithms without rebuilding the system around them. NIST published CSWP 39 on this. For an evidence layer it means the signature algorithm is a versioned field in the receipt, not an assumption baked into the verifier.

Full page →

Should we migrate agent signing to PQC now?

Not necessarily. The defensible position is crypto agility plus a cryptographic inventory, so migration is a configuration change rather than a rebuild. Migrating before you can enumerate what you are running is how organisations end up migrating twice.

Full page →

What is the difference between a kill switch and revocation?

A kill switch stops execution. Revocation withdraws authority. Stopping the process without revoking credentials leaves an agent that can act again the moment anything restarts holding those credentials.

Full page →

How fast should revocation propagate?

Fast enough that the worst action in your blast radius cannot complete within the window. That makes it a per-deployment number derived from your action inventory, not a universal target.

Full page →

What happens to in-flight actions?

It has to be decided in advance: completed, cancelled, or explicitly indeterminate. Indeterminate is acceptable if it is known and documented — it is a failure only when it is a surprise.

Full page →

How do you prove an agent stopped?

Refusal receipts after the stop timestamp. Absence of activity proves nothing, because absence is also what a broken logger looks like.

Full page →

Should the kill switch be global or scoped?

Both, with scoped as the default. Global switches get used late because the cost of using them is high, and lateness is the whole problem.

Full page →

Agent governance vs AI guardrails - what is the difference?

Guardrails filter model inputs and outputs. Governance authorizes effects: identity, policy evaluation, approval, and signed evidence around what the agent is permitted to cause. Filters advise; gates decide.

Full page →

Agent governance vs observability - which comes first?

They answer different questions: observability shows what happened; governance decides what may happen and proves it. Traces are not authorization evidence — receipts are. Deploy the gate first on consequential actions.

Full page →

Do AI agents need their own identity?

Yes. Shared service accounts make actions unattributable and permissions unscopeable. Each agent needs a distinct identity with an accountable human owner, a permission set and a lifecycle state.

Full page →

What is payload-bound approval?

An approval cryptographically tied to one specific action payload, single-use and expiring. Approving one action never silently authorizes the next — the property session-level approvals lack.

Full page →

Can an AI agent be stopped once it is running?

Only if revocation was designed in: withdrawing authority at the gate, propagation faster than the agent acts, and a receipt proving the stop. A kill switch that has never been drilled is a hope.

Full page →

What should a CFO ask about AI agents that move money?

Three questions: what is the hard spend ceiling and does it fail closed; who approved this specific payment and can we prove it; and what evidence exists if a payment is disputed.

Full page →

What is MCP governance?

Controlling how agents reach tools through the Model Context Protocol: server identity, per-tool authorization, exposure assessment, and the confused-deputy and token-passthrough failure modes the 2026-07-28 spec hardens against.

Full page →

What is AP2 and how does it differ from x402?

AP2 proves a human authorized a specific spend using cryptographic mandates; x402 settles agent payments over HTTP with no human present. Both make wallet governance — caps, allowlists, receipts — non-optional.

Full page →

What is agent sprawl?

The accumulation of agents nobody inventories: created in pilots, embedded in tools, or spun up by teams independently. It is the non-human twin of shadow IT, and discovery is the control.

Full page →

What is deny-by-default for AI agents?

The gate posture where every consequential action is refused unless policy explicitly permits it — the inverse of allow-and-filter, and the property that makes refusal receipts possible at all.

Full page →

Standards & OWASP

What are the OWASP Top 10 for Agentic Applications?

Published 9 December 2025: ASI01 Agent Goal Hijack, ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse, ASI04 Agentic Supply Chain Vulnerabilities, ASI05 Unexpected Code Execution, ASI06 Memory and Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation, ASI10 Rogue Agents.

Full page →

Does the EU AI Act still apply after the Digital Omnibus deferral?

Yes in part. Annex III high-risk obligations were deferred to 2 December 2027 and Annex I to 2 August 2028, but most transparency obligations, including deployer obligations, took effect on 2 August 2026.

Full page →

Which AI standards can you be certified against?

ISO/IEC 42001 offers accredited third-party certification. NIST AI RMF and the OWASP Agentic Top 10 have no certification path.

Full page →

What is a control crosswalk?

A mapping showing how one control satisfies requirements across several frameworks, so evidence is produced once and reused.

Full page →

Does the EU AI Act require certification?

High-risk systems face conformity assessment. It is a legal obligation rather than a framework you opt into.

Full page →

Is the OWASP Agentic Top 10 a standard?

It is a risk taxonomy and the closest thing to shared vocabulary the category has. It is not certifiable.

Full page →

Where should we start?

NIST AI RMF for structure, because it costs nothing and other regimes point back at it.

Full page →

Which AI framework can you actually be certified against?

ISO/IEC 42001 offers accredited third-party certification of an AI management system. Most other AI frameworks, including NIST AI RMF and OWASP's agentic taxonomy, have no certification path.

Full page →

Is SOC 2 enough for AI governance?

Not on its own. It attests to controls within defined trust criteria. Unless agent governance controls were explicitly scoped in, it evidences a different thing.

Full page →

Does ISO 42001 mean our agents are safe?

It means you operate a certified management system for AI. That is meaningful and it is not a per-agent safety claim — the distinction matters to any competent reviewer.

Full page →

Which framework should we start with?

NIST AI RMF for structure, because it costs nothing and other regimes point at it. Add ISO 42001 if you need a certificate a buyer can verify.

Full page →

Can an AI agent be certified?

Not in any settled sense. No ratified certification for agent governance exists today. CSA's STAR for AI programme, grounded in ISO/IEC 42001 and the AI-CAIQ, is the closest thing to a third-party attestation pathway. Anyone selling you 'AI agent certification' is selling something the standards bodies have not yet defined.

Full page →

What is agentic red teaming?

Adversarial testing aimed at agent-specific failure: tool misuse, unauthorized tool calls, indirect prompt injection arriving through tool output, and excessive agency. Distinct from LLM red teaming, which targets the model's outputs rather than its actions.

Full page →

What tools exist for it?

Open tooling includes PyRIT, garak, Inspect and DeepTeam. Commercial vendors map findings to OWASP, NIST AI RMF, MITRE ATLAS, ISO/IEC 42001 and the EU AI Act and produce auditor-ready reports. Tooling maturity varies sharply — evaluate against your own agents, not the demo.

Full page →

What is MITRE ATLAS?

A knowledge base of adversarial tactics and techniques against AI systems, structured like ATT&CK. Increasingly used to classify agentic attack paths in a way security teams already understand.

Full page →

How is an agent audit different from a pen test?

A pen test asks whether someone can get in. An agent audit asks whether what the agent did was authorized, whether you can prove it, and whether you could have stopped it. Different question, different evidence.

Full page →

What should an agent audit produce?

An inventory, a control-gap list ordered by blast radius, evidence of which controls actually fired, standards mapping, and — critically — written limitations. An assessment claiming completeness is not a trust artifact.

Full page →

Was the EU AI Act delayed?

Partly. Under the Digital Omnibus, agreed politically on 7 May 2026, Annex III use-based high-risk obligations moved from 2 August 2026 to 2 December 2027, and Annex I product-regulated obligations moved from August 2027 to August 2028. Most transparency obligations were not deferred.

Full page →

What still applies from 2 August 2026?

Most transparency obligations, including those falling on deployers, took effect as scheduled. The deferral covers the high-risk obligation sets, not the whole Act.

Full page →

Why was it deferred?

The stated reason is the late arrival of harmonised standards from CEN-CENELEC JTC21. Without them, providers had no agreed technical means of demonstrating conformity.

Full page →

Does the AI Act cover AI agents specifically?

Not as a named category. The Act was drafted around AI systems and general-purpose models, not around software that plans, holds memory and calls tools autonomously. Agentic behaviour is governed indirectly through risk management, human oversight, logging and post-market monitoring obligations.

Full page →

What should we do during the deferral?

Build the evidence layer that every obligation set ultimately requires: logging that reconstructs an action, human oversight that can actually intervene, and documentation that matches what the system does. None of that becomes less necessary in December 2027.

Full page →

What is MCP 2026-07-28?

A revision of the Model Context Protocol that hardened authorization. It matters because MCP is the transport a growing share of agent tool calls run over.

Full page →

Is there a migration deadline?

The revision starts a practical migration clock for implementations on earlier revisions. Confirm specifics against the protocol documentation.

Full page →

What should we do first?

Inventory: which MCP servers exist, which tools they expose, which agents can reach them, and who owns each.

Full page →

Does MCP handle policy?

No. It handles connection and capability exposure. Whether a permitted call is an appropriate action is a policy question at the effect boundary.

Full page →

Can you be certified against NIST AI RMF?

No. There is no certification body and no certificate. What exists is documented conformance evidence.

Full page →

Why does it matter then?

Texas TRAIGA provides an affirmative defence for organisations complying with a recognised risk framework, which gives documented conformance direct legal value.

Full page →

What are the four functions?

Govern, Map, Measure, Manage. Govern is the one most often skipped and the one that determines whether the rest holds.

Full page →

How does it apply to agents specifically?

Map the action surface, measure refusals and incidents, manage through policy and caps, and govern by naming an accountable owner.

Full page →

Is it enough on its own?

It is a structure, not a control set. It tells you what to have decided, not what to build.

Full page →

Is OWASP agentic security the same as the OWASP Agentic Top 10?

The Top 10 (ASI01-ASI10) is the taxonomy at the centre of it. 'Agentic security' is the wider practice: the risks, the controls that answer them, and the evidence that proves the controls fire.

Full page →

Is there an OWASP certification for agentic security?

No. No certification exists for the Agentic Top 10 and OWASP does not issue one. Its value is shared vocabulary.

Full page →

How does agentic security differ from LLM security?

LLM security concerns model input and output - injection, leakage, unsafe content. Agentic security concerns systems that ACT: goal hijack, privilege abuse, rogue agents, cascading failures. Different failure modes, different controls.

Full page →

What is the fastest way to assess agentic security posture?

Walk ASI01 to ASI10 and ask two questions per risk: which control answers it, and what evidence shows that control has ever fired. A control with zero recorded refusals is unproven.

Full page →

Where do execution receipts fit?

They are the evidence layer for most of the ten: attribution for ASI03 and ASI10, tamper-evidence for ASI06, refusal receipts proving gates fire for ASI01 and ASI02.

Full page →

What is the OWASP Agentic Top 10?

A taxonomy of the ten most significant risks specific to agentic applications, ASI01 through ASI10. It replaces extending the LLM Top 10 by analogy.

Full page →

Is it certifiable?

No. There is no OWASP certification for it. Its value is shared vocabulary and a checklist for control coverage.

Full page →

How does it differ from the LLM Top 10?

The LLM Top 10 concerns model input and output. The agentic list concerns systems that act — goal hijack, privilege abuse, rogue agents, cascading failures.

Full page →

Which risk is most commonly unaddressed?

ASI10, rogue agents — agents operating outside governance entirely because no inventory exists to notice them.

Full page →

How do you evidence coverage?

Per-risk control mapping plus refusal receipts showing the controls actually fire.

Full page →

What is ASI01 agent goal hijack?

ASI01 agent goal hijack — An attacker steers the agent's objective away from what the operator intended, usually through injected content the agent treats as instruction.

Full page →

How do you defend against it?

Separate instruction channels from data channels, constrain the goal at the policy layer rather than in the prompt, and gate every irreversible action so a hijacked objective still cannot act unilaterally.

Full page →

Is the OWASP Agentic Top 10 a certification?

No. It is a risk taxonomy, not a certifiable standard. There is no OWASP certification for it. Its value is as shared vocabulary — see the assurance frameworks comparison.

Full page →

What evidence shows this control is working?

Refusal receipts. A control that has never blocked anything is either untested or not enforced. Countable refusals with reasons are what turn a claimed control into a demonstrated one.

Full page →

What is ASI04 agentic supply chain vulnerabilities?

ASI04 agentic supply chain vulnerabilities — Compromise arrives through a tool, model, plugin, mcp server or dependency the agent trusts.

Full page →

What is ASI08 cascading failures?

ASI08 cascading failures — One agent's bad output becomes another's trusted input, and the error amplifies through the chain.

Full page →

What is ASI09 human-agent trust exploitation?

ASI09 human-agent trust exploitation — The agent's fluency persuades a person to approve something they should have questioned.

Full page →

What is ASI03 identity and privilege abuse?

ASI03 identity and privilege abuse — The agent acts with more authority than the task required, or its identity is reused across contexts.

Full page →

What is ASI07 insecure inter-agent communication?

ASI07 insecure inter-agent communication — One agent accepts instruction from another without verifying identity or authority.

Full page →

What is ASI06 memory and context poisoning?

ASI06 memory and context poisoning — Persistent memory or retrieved context is contaminated, so the agent misbehaves long after the injection.

Full page →

What is ASI10 rogue agents?

ASI10 rogue agents — An agent operates outside governance entirely — unregistered, unmonitored, or still running after it should have been retired.

Full page →

What is ASI02 tool misuse and exploitation?

ASI02 tool misuse and exploitation — The agent uses a legitimate tool in an unintended or damaging way — right credential, wrong call.

Full page →

What is ASI05 unexpected code execution?

ASI05 unexpected code execution — Generated content reaches an interpreter and runs.

Full page →

Are AI agents covered by the EU AI Act?

The Act regulates AI systems by risk and function rather than naming agents; agentic deployments inherit obligations through their use case — plus logging, oversight and record-keeping duties that receipts answer directly.

Full page →

What is the OWASP Agentic Top 10 in one sentence?

A 2026 taxonomy of the ten security failure modes specific to systems that act — from goal hijack (ASI01) to rogue agents (ASI10) — giving teams shared vocabulary for agentic risk.

Full page →

Which OWASP agentic risks do execution receipts address?

Attribution for ASI03 and ASI10, tamper-evidence for ASI06, and refusal receipts proving gates fire against ASI01 and ASI02 — receipts are the evidence layer for most of the ten.

Full page →

What is a rogue agent?

An agent operating outside governance entirely — unowned, uninventoried, or acting past its intended lifecycle. OWASP lists it as ASI10; discovery plus lifecycle-bound identity is the answer.

Full page →

How do you stop prompt injection from becoming action?

Accept that injection will land, and gate the consequence: treat retrieved content as data, evaluate consequential actions against policy, and require payload-bound approval where effects are irreversible.

Full page →

Why is 'the agent seemed trustworthy' a security risk?

Fluency reads as competence, so humans approve what they should question — OWASP's ASI09. Payload-bound approvals that show exactly what will execute are the structural answer to social trust in machines.

Full page →

Regions & regulation

Which jurisdiction regulates AI agents most directly?

DIFC Regulation 10 and Singapore's agentic AI framework are the two that address autonomous systems as a distinct category rather than extending general AI rules. Most other regimes govern agents by analogy.

Full page →

Is there a single global compliance approach for AI agents?

No, and anyone selling one is overstating. What does transfer is the evidence: per-action records showing what was attempted, which policy applied, who approved it, and what happened. Every regime asks for some version of that.

Full page →

What changed in the EU in 2026?

The Digital Omnibus package deferred and simplified parts of the AI Act's application. Deferral is not repeal — obligations already in force remained and deferred ones are still scheduled.

Full page →

Does Canada have an AI act?

No. AIDA did not pass. For federally regulated financial institutions the operative deadline is OSFI Guideline E-23 in May 2027.

Full page →

Where should a multinational start?

With an applicability register: which legal entity, in which jurisdiction, running which agent, under which instrument. Most compliance failures we see are register failures, not control failures.

Full page →

Which country has the most specific AI agent rules?

Singapore's agentic AI framework is the most direct published treatment of agents we can identify. Most other jurisdictions address agents by extension from general AI rules rather than on their own terms.

Full page →

Is Korea's AI Basic Act in force?

Korea has passed a comprehensive AI statute. Commencement and the scope of specific obligations are staged — confirm current status against the official text before relying on any date.

Full page →

Does Japan have an AI act?

Japan's approach has been guidance-led and sectoral rather than a single comprehensive binding statute. Expectations are set through guidance and procurement conditions.

Full page →

What applies to agents in Australian financial services?

APRA prudential standards on operational risk and third-party arrangements apply to regulated entities today, independent of any AI-specific instrument.

Full page →

Can we use one APAC compliance approach?

No. The regimes differ structurally — statute-led in Korea, guidance-led in Japan, framework-led in Singapore, prudential in Australia. A single approach will fail in at least one market.

Full page →

Did Canada pass an AI act?

No. AIDA, proposed within Bill C-27, did not become law. Canada has no comprehensive federal AI statute. Sources describing an imminent Canadian AI act are out of date.

Full page →

What is OSFI Guideline E-23?

OSFI's model risk management guideline for federally regulated financial institutions, applying from May 2027. It uses a broad model definition and sets lifecycle expectations — inventory, risk rating, validation, ongoing monitoring.

Full page →

Is an AI agent a model under E-23?

If it informs or makes decisions, institutions should expect it to be treated within model risk management. The guideline's definition is deliberately broad; assuming exclusion because the system is called an agent is not a defensible position.

Full page →

What should a Canadian FI do first?

Inventory. You cannot risk-rate, validate or monitor what you have not enumerated, and discovery consistently takes longer than institutions plan for.

Full page →

Does Quebec Law 25 add anything for agents?

Yes. It includes automated-decision transparency obligations that apply independently of federal law, so a Quebec deployment needs its own answer.

Full page →

Does the EU AI Act regulate AI agents specifically?

Not as a named category. Obligations attach to risk classification and to your role — provider, deployer, importer, distributor. An agent is governed by the tier its use case falls into, plus whatever sectoral and data-protection law already applied.

Full page →

Did the Digital Omnibus cancel the AI Act?

No. It deferred and simplified parts of the application timetable. Duties already in force remained, and deferred duties are still scheduled. Confirm the dates that apply to your specific classification against the amended text.

Full page →

What is the single most useful thing to build for EU readiness?

A per-action evidence record: what the agent tried to do, which policy allowed or blocked it, who approved it if approval was required, and what actually happened. That artifact satisfies record-keeping, supports oversight claims, and shortens every enquiry.

Full page →

Does DORA apply to our AI vendor?

If you are a financial entity in scope, your ICT third-party providers fall within your oversight and contractual obligations. An agent platform that touches critical or important functions is squarely in that conversation.

Full page →

Is GDPR Article 22 triggered by an agent?

It depends on effect, not autonomy. If a decision produces legal or similarly significant effects on a person and is made without meaningful human involvement, Art. 22 is in play — regardless of whether the software is called an agent.

Full page →

Does Brazil have an AI law in force?

Not a comprehensive one. PL 2338 is the leading bill and follows a risk-tiered structure. LGPD, Brazil's data protection law, is in force and already governs automated processing of personal data.

Full page →

Is PL 2338 the same as the EU AI Act?

Structurally similar — risk tiers, obligations scaled to risk — but not identical in definitions, thresholds or duties. Treat EU work as transferable reasoning, not transferable compliance.

Full page →

What binds an AI agent in Latin America today?

Principally data protection law and sectoral financial supervision. Comprehensive AI statutes are mostly still in progress across the region.

Full page →

Which LATAM market should we prioritise?

Brazil, on both market size and regulatory maturity. It has the most advanced AI instrument in progress and an operative data-protection regime today.

Full page →

Do we need Portuguese and Spanish disclosures?

If an agent interacts with people, disclosure and explanation obligations are only met in a language they can actually read. Treat localisation as compliance, not marketing.

Full page →

What is DIFC Regulation 10?

A DIFC regulation, enforced from 1 January 2026, addressing autonomous and semi-autonomous systems. It is notable for treating autonomy as the regulated property rather than analogising to existing software rules.

Full page →

What is an Autonomous Systems Officer?

A designated accountable role contemplated by DIFC Regulation 10 — a named human answerable for autonomous systems within the entity. Confirm the exact scope and appointment requirements against the regulation text.

Full page →

Is SDAIA guidance legally binding in Saudi Arabia?

No. It is guidance without force of law. It nonetheless influences public-sector procurement and vendor expectations, so it often functions as a practical requirement even where it is not a legal one.

Full page →

Does DIFC regulation apply to our onshore UAE entity?

No. DIFC is a separate jurisdiction with its own regulations and regulator. Applicability follows the entity, not the country. Confirm entity by entity.

Full page →

Why does the Middle East matter for agent governance specifically?

Because DIFC is one of the few regimes anywhere that regulates autonomous systems as such and names an accountable role. Organisations that solve accountability for DIFC generally find they have solved most of it for everywhere else.

Full page →

Does the UK have an AI act?

No. The UK's approach is context-based and regulator-led — existing regulators applying existing powers within their remits, rather than a cross-cutting AI statute.

Full page →

Then what governs an AI agent in the UK?

Your sector's regulator plus UK GDPR. In financial services that means FCA and PRA expectations on operational resilience, third-party risk and consumer outcomes, alongside individual accountability.

Full page →

Is the absence of an AI act simpler?

Usually harder. There is no single checklist to work through — you have to establish which regulator holds your remit and what their existing rules require of automated systems.

Full page →

Does UK GDPR restrict automated decisions?

It contains provisions relating to automated decision-making and rights attaching to it. Where an agent's action significantly affects a person, that is the first place to look.

Full page →

Is the AI Security Institute a regulator?

No. It is an evaluation and research body. It influences practice and government expectations but does not issue binding rules to firms.

Full page →

Is there a federal AI law in the United States?

No comprehensive statute. Governance comes from state law plus federal sectoral supervision — banking, insurance, healthcare, employment — much of which predates AI and applies anyway.

Full page →

What is the TRAIGA affirmative defence?

Texas TRAIGA provides a defence for organisations that comply with a recognised AI risk framework such as the NIST AI RMF. It gives documented framework conformance direct legal value, which is unusual for a voluntary framework.

Full page →

Which state should we design for first?

Design for the strictest requirement in your actual deployment footprint, then document per-state applicability. Designing for the loosest and patching later is how organisations end up rebuilding.

Full page →

Does NIST AI RMF certification exist?

No. There is no certification body and no certificate. Anyone offering NIST AI RMF certification is selling something that does not exist. What you can hold is documented conformance evidence.

Full page →

What does OSFI E-23 mean for AI agents in Canadian banks?

E-23 treats models and their automated decisions as model risk: inventory, validation, monitoring and explainability. An agent outside the model inventory is the finding examiners start with. Effective May 2027.

Full page →

Which US states regulate AI agents in 2026?

No state names agents; several bind automated decisions and disclosures — Texas's TRAIGA includes an affirmative-defence structure that rewards documented governance programs. Sectoral federal law binds effects throughout.

Full page →

Industries

Which industries regulate AI agents most heavily?

Banking and financial services, through model risk management regimes (SR 11-7, OSFI E-23, DORA), and healthcare, through HIPAA and device regulation. Neither names agents; both bind their effects.

Full page →

Does agent governance differ by industry?

The control set barely changes - identity, policy gates, approvals, receipts, revocation. What changes is which regulator asks, which records they expect, and how long evidence must survive.

Full page →

Where should a regulated firm start?

With the action inventory: what can each agent cause to happen that cannot be undone. Every industry regime maps onto that list, not the other way round.

Full page →

What about industries with no AI-specific rules?

Existing sectoral law still binds automated effects - consumer protection, contract, privacy. No AI statute does not mean no obligations.

Full page →

Why do you only publish two industry pages?

Because these are the two where we can cite named instruments with dates. Pages for other industries appear when there is something sourced to say, not before.

Full page →

Does SR 11-7 apply to AI agents?

In supervised institutions, expect examiners to treat decision-making agents within model risk expectations: inventory, validation, ongoing monitoring.

Full page →

What does DORA require of agent deployments?

ICT risk management, incident reporting within defined timelines, and oversight of third-party providers — which includes agent platforms touching important functions.

Full page →

What is OSFI E-23's significance?

It applies from May 2027 to federally regulated Canadian institutions with a broad model definition and lifecycle expectations.

Full page →

Are agents in scope of model inventory?

If they inform or take decisions, assume yes. Assuming exclusion because the system is called an agent is not a defensible position.

Full page →

What evidence do examiners ask for?

Inventory, risk rating with reasoning, validation, monitoring, and the ability to explain a specific decision after the fact.

Full page →

Does HIPAA prohibit AI agents?

No. It sets conditions: minimum necessary access, audit controls, and business associate agreements with vendors handling PHI. Administrative agents are deployable within those conditions.

Full page →

When does an AI agent become a medical device?

When its function crosses into clinical decision support in ways FDA frameworks reach — which depends on function and on whether a clinician can independently review the basis for the recommendation. Administrative automation generally does not.

Full page →

How do you prove an agent never gave medical advice?

Refusal receipts from an enforced classification gate. A countable record of blocks is evidence; an absence of complaints is not.

Full page →

Is a BAA needed with an AI vendor?

If the vendor creates, receives, maintains or transmits PHI on your behalf, yes. This is one of the first questions any health system security review asks.

Full page →

What slows healthcare AI deals down most?

Security review, not regulation. Health systems ask for evidence of access controls, audit trails and data handling — having those artifacts ready shortens the cycle more than any other single thing.

Full page →

Do AI agents fall under HIPAA?

When they touch PHI, yes: minimum-necessary access, auditable disclosures and retention all bind the agent's effects. The governance question is proving the boundary held, per action.

Full page →

Use cases

What determines how much governance an agent needs?

The reversibility and blast radius of its actions, not its model or its autonomy level. An agent that only reads needs very little. An agent that can send, pay, dispatch or submit needs approval gates, caps and receipts.

Full page →

Do all agents need human approval?

No. Requiring approval everywhere destroys the value of automation and trains people to approve reflexively. Approval belongs specifically on irreversible actions.

Full page →

What is the single most useful control?

Idempotency on every effect. It is unglamorous and it prevents the most common real-world incident: retries producing duplicate sends, duplicate charges and duplicate dispatches.

Full page →

How do you know a boundary is actually enforced?

Count the refusals. A boundary that has never blocked anything is either untested or not enforced. Refusal receipts turn a claim into evidence.

Full page →

Where should an organisation start?

Write down the irreversible actions. Most teams have never enumerated them, and that list determines every control that follows.

Full page →

Can an AI agent handle patient scheduling under HIPAA?

Administrative scheduling is a common and defensible use, provided access follows minimum necessary, PHI handling is controlled per channel, and the interaction is logged. The compliance work is in scoping and evidence, not in the scheduling itself.

Full page →

How do you stop a healthcare agent giving medical advice?

With an enforced policy gate on outbound content that classifies and blocks, backed by refusal receipts. A system-prompt instruction is not a control because it produces no evidence and fails silently.

Full page →

What evidence would a regulator ask for?

Who accessed what PHI and why, on what authority, and what the agent did with it. Per-action receipts answer that directly; application logs usually do not.

Full page →

Is prior authorisation automation risky?

It is a representation to a third party, so accuracy and attribution matter. Run it behind an approval gate and keep receipts binding each submission to its inputs and approver.

Full page →

How long should healthcare agent evidence be retained?

Match the longest applicable obligation in your jurisdiction and payer contracts. The common failure is infrastructure log rotation quietly deleting evidence years before the obligation ends.

Full page →

Should an AI agent submit tenders automatically?

No. Monitoring, extraction, drafting and assembly are strong uses. Submission should carry human approval, because a submitted bid binds you and the window does not reopen.

Full page →

How do you stop an agent inventing pricing?

Bind pricing fields to an approved source and disallow generation into them structurally. A model asked not to invent numbers will still occasionally invent numbers; a field that only accepts a looked-up value cannot.

Full page →

What evidence does a public buyer expect?

Consistency and attribution — that the submission reflects what your organisation approved. Receipts naming the approver and hashing the artifact answer this cleanly.

Full page →

Can agents handle clarification questions?

They can draft them. Sending should be gated, because a clarification response becomes part of the tender record and can bind you.

Full page →

What is the highest-value safe use in procurement?

Opportunity monitoring and requirement extraction. It is where the time goes, it is reversible, and it does not commit the organisation to anything.

Full page →

Should an AI agent have CRM write access?

Yes, with bulk-write thresholds, tagged writes and a reversal path. The risk is not a single wrong field — it is an unnoticed systematic error propagating through forecasting and compensation.

Full page →

What sending controls does an outbound agent need?

Volume caps, suppression enforcement, and lawful-basis checks — all enforced by the sending component rather than the agent. Plus a per-send receipt so you can answer a complaint precisely.

Full page →

How do we protect domain reputation?

Cap sending at the domain level, not per campaign, and put a breaker on repeated failures. Deliverability is shared infrastructure and recovers slowly.

Full page →

What evidence do we need for a data-subject request?

What data was processed, on what basis, and what was sent as a result. Per-send receipts tied to inputs make this a lookup instead of an investigation.

Full page →

Does this change if we use a third-party sending platform?

The controls have to live at the boundary that platform exposes. If the platform cannot enforce caps and suppression on the agent's behalf, you need a component in front of it that can.

Full page →

Solutions & services

My AI agent did something it should not have — what do I do first?

Contain before you investigate. Revoke grants, halt the class of action, then preserve receipts, logs and queue state before anything is redeployed. Most damage after the first incident comes from a rushed fix that destroys the record.

Full page →

Who delivers these services?

ThruLiquid, the commercial services arm. Engagements are scoped individually and client details are confidential.

Full page →

How do these relate to ApexClaw?

ApexClaw is the agent governance product lane. ThruLiquid delivers growth and visibility services. They are separate offers with separate outcomes.

Full page →

Which service should we start with?

The AI Search Visibility Audit if the question is whether AI answer engines can find and cite you. RevOps if reporting cannot be trusted.

Full page →

Do you publish client results?

No. Client engagements and results are confidential. Where a number appears anywhere on this site it is first-party with stated methodology, or labelled.

Full page →

Are engagements retained or project-based?

Both exist. Scope is agreed before work starts and measured against pipeline rather than activity.

Full page →

How large should an ABM list be?

Small enough that every account can receive genuinely differentiated treatment at its tier. A list that cannot be serviced at tier is a demand-gen list with an ABM label.

Full page →

What is the most common ABM mistake?

Building the list on firmographic fit alone with no disqualification rules and no observable signal. The programme then executes flawlessly against the wrong accounts.

Full page →

How is ABM measured?

Against pipeline: account engagement to opportunity creation to closed revenue. Reach and impressions are diagnostics that explain movement, not results that justify spend.

Full page →

Does ABM work for technical buyers?

It works better, because technical buying committees are larger and more identifiable. Multi-threading is not optional when six people must agree.

Full page →

How does ABM relate to outbound?

Outbound is one channel within ABM. The account strategy determines who is worth contacting; outbound is how some of that contact happens.

Full page →

How is this different from an SEO audit?

A traditional SEO audit optimises for ranking in a list of links. This audits whether an answer engine can extract a quotable answer and has enough corroboration to repeat it. The overlap is real but partial — sites rank well and go uncited routinely.

Full page →

Which engines does it cover?

The crawler and citation behaviour of the major AI answer surfaces, plus AI Overviews. Access is verified by request, not by assumption.

Full page →

What is usually the biggest problem?

Off-site consensus. Most organisations have never published anything anywhere else, so every claim is single-source. It is also the cheapest thing to fix.

Full page →

Do we need to rewrite the whole site?

Usually not. The pattern is that a small number of pages carry the commercial weight, and definition-first rewrites plus schema on those pages moves most of the result.

Full page →

How long does it take?

It is scoped to the site. The output is a prioritised fix list ordered by gate, so work can start on the highest-leverage item immediately rather than waiting for the full pass.

Full page →

What is the difference between GEO and AEO?

GEO is about being part of what a generative answer is built from. AEO is about being the source that gets named. In practice the work overlaps heavily — extractability, sourcing and corroboration serve both.

Full page →

Does GEO replace SEO?

No. Classical search still drives volume and the technical foundations are shared. GEO adds extractability and corroboration requirements that ranking alone never demanded.

Full page →

How is GEO measured?

Imperfectly, and anyone claiming otherwise is overselling. Referral parameters, grounding queries and observed citations give partial visibility. We state which parts are measured and which are inferred.

Full page →

What is the fastest improvement?

Definition-first rewrites on your top commercial pages, followed by publishing something off-site that corroborates your central claim.

Full page →

Do llms.txt files work?

They are read by some AI crawlers and ignored by Google. Publishing one is cheap and low-risk. Treating it as a ranking mechanism is a misunderstanding of what it does.

Full page →

Why is outbound underperforming when the copy is good?

Almost always deliverability or targeting. Check whether messages are actually landing, then whether the list is defensible, before rewriting anything.

Full page →

How many touches should a sequence have?

Enough to cover a realistic buying cycle without becoming noise, with clear exit conditions. The right number depends on deal size and cycle length, not on a template.

Full page →

What lawful basis is needed for EU and UK contacts?

It depends on jurisdiction and channel and it must be established before enrolment. Record the basis per contact so a data-subject request is a lookup rather than an investigation.

Full page →

Should we use separate sending domains?

Usually yes. It isolates reputation risk from your primary domain, which also carries invoices and password resets.

Full page →

What reply rate is realistic?

It varies enormously by market, list quality and offer. Any number quoted without the segment and denominator attached is not a benchmark, it is marketing.

Full page →

What is the first RevOps fix?

Written definitions for lifecycle stages and reported fields. It is the cheapest intervention and it resolves most reporting disputes permanently.

Full page →

How do you stop CRM data decay?

Validation at entry, scheduled deduplication, and enrichment with a refresh policy. Cleaning once and hoping is how the problem returns.

Full page →

Should AI agents write to the CRM?

They can, with bulk-write thresholds, tagged writes and a reversal path. The danger is systematic error propagating silently through forecasting and compensation.

Full page →

How many dashboards should exist for a metric?

One. A second source for the same number produces meetings about which is right instead of decisions based on either.

Full page →

How does RevOps relate to ABM and outbound?

It is the substrate. Account tiering, routing and measurement all depend on the definitions and data quality RevOps owns.

Full page →

What is an Agent Trust Gap Brief?

A short assessment of the distance between what your agents can currently do and what you could prove afterwards. It is the low-friction entry point.

Full page →

What is an Agent Trust Audit?

A full review of agent inventory, action surface, controls and evidence, producing a prioritised remediation plan.

Full page →

What if we already had an incident?

Start with incident response — containment and evidence preservation come before assessment.

Full page →

Do you need access to our systems?

The Gap Brief does not. Deeper work is scoped with you and read-only wherever possible.

Full page →

How long does the Gap Brief take?

It is deliberately short. The output is a specific list of gaps with evidence, not a general maturity score.

Full page →

My AI agent did something it should not have. What do I do first?

Contain before you investigate. Revoke the agent's grants and halt the class of action it took, then preserve evidence before anything is redeployed. Most damage after the first incident comes from a rushed fix that destroys the record of what happened.

Full page →

How do I find out what an AI agent actually did?

If execution receipts exist, replay the sequence: the identity, the policy version in force, the approval if any, the payload hash, the provider response, the outcome. If only application logs exist, you are reconstructing intent from side effects, which is slow and rarely conclusive.

Full page →

Can an AI agent's actions be attributed to a specific person?

Only if the agent held its own identity with a named human owner. If several agents shared one credential, attribution is impossible by construction and no amount of log analysis afterwards will recover it.

Full page →

How fast should revocation take effect?

The only meaningful specification is measured time-to-effect on a tested path. Revoking a grant that the downstream service caches for an hour is not revocation, it is a delay.

Full page →

Do we have to report an AI agent incident?

It depends on jurisdiction, sector and what the agent touched. Under the EU AI Act, serious-incident reporting obligations attach to certain systems. Sector regulators impose their own. This is a question for counsel, not for a vendor page.

Full page →

What does the audit cover?

Agent inventory, the action surface of each agent, identity and credential scoping, policy enforcement points, evidence quality, revocation, and retention against obligation.

Full page →

What is the deliverable?

A prioritised remediation plan with each finding tied to observed evidence, ordered by the irreversibility of what is currently ungoverned.

Full page →

Is it framework-mapped?

Yes — findings map to OWASP ASI01–ASI10 and to NIST AI RMF functions, so the output is usable in existing risk processes.

Full page →

Do you need production access?

Read-only wherever possible. Some findings require observing an action path, which is scoped and agreed in advance.

Full page →

What if we have no agents in production yet?

Then the audit is cheaper and far more valuable, because controls designed before deployment cost a fraction of controls retrofitted after.

Full page →

What is the Gap Brief?

A short, structured assessment of the gap between what your agents can do and what you could evidence if asked.

Full page →

What do you need from us?

A description of your agents and what they can act on. No system access is required.

Full page →

What do we get?

A written brief naming the specific gaps, ranked by the irreversibility of the ungoverned actions, with the concrete control for each.

Full page →

Is it a sales document?

It names gaps and controls. Where the control is something you can build yourself, it says so.

Full page →

What happens after?

Nothing automatically. The brief is useful on its own and is designed to be actioned by your own team if you prefer.

Full page →

Resources & cost

Where should I start reading?

With the definition of an agent, then the twelve-control checklist. Those two establish the vocabulary the rest depends on.

Full page →

Are these articles updated?

Each carries a last-verified date. Regulatory content is re-checked against primary sources when instruments change.

Full page →

Can I quote these?

Yes, with attribution to ApexClaw and a link to the source URL. The full corpus is also published at /llms-full.txt for machine use.

Full page →

Why are application logs not enough?

They are mutable, rotated on operational schedules, rarely record authority, and almost never record refusals. Evidence that only shows successes cannot demonstrate that a control exists.

Full page →

Does replay re-execute the action?

It must not. Replay re-evaluates the decision against the recorded policy and compares outcomes. Re-firing the side effect turns verification into a second incident.

Full page →

How long should receipts be retained?

Matched to your longest applicable obligation — often years. The common failure is infrastructure log rotation silently deleting governance evidence on an operational schedule.

Full page →

What is the first thing to do when an AI agent misbehaves?

Revoke its authority — not just stop the process. A stopped process holding valid credentials can resume acting the moment anything restarts.

Full page →

Why preserve evidence before fixing?

Because redeploying overwrites the configuration, prompts and policy versions that explain what happened. Once gone, every subsequent answer becomes 'we believe' rather than 'here is the record'.

Full page →

How do you scope an agent incident?

By action, not by time. Enumerate the actions attempted, which produced external effects, and who was affected. Time windows do not support a notification decision.

Full page →

When do notification duties start?

It depends on regime and effect — personal data, financial impact, and regulated decisions each carry their own clock, and several start at detection rather than at confirmation. Assess early rather than after the analysis is complete.

Full page →

Is 'the model hallucinated' an acceptable explanation?

No. It names a mechanism, not a control failure. The governance finding is that an unverified output reached an actuator without a gate — which is both more accurate and more fixable.

Full page →

Where do these numbers come from?

Every figure names its source and its date inline. Anything we could not source is not on this page. First-party figures state their methodology.

Full page →

Why publish a statistics page?

Because agent-governance claims circulate unsourced. A dated, sourced reference page is more useful to practitioners - and to AI answer engines - than another opinion piece.

Full page →

How often is it updated?

Each entry carries its own verified-on date. Entries whose source ages out are removed rather than left to rot.

Full page →

Can I cite these figures?

Yes - cite the PRIMARY source named next to each figure, not this page. This page is a map, not the territory.

Full page →

What is deliberately missing?

Vendor-marketing statistics with no methodology, projections presented as measurements, and anything whose primary source we could not locate.

Full page →

What is the minimum viable agent governance?

Action inventory, least privilege, approval on irreversible actions, idempotency, and receipts. Those five prevent most real incidents and are achievable in weeks, not quarters.

Full page →

Which control prevents the most incidents?

Idempotency. Duplicate effects from retries after timeouts are the most common agent incident in production and the cheapest to prevent.

Full page →

Do we need all twelve before launching?

No. Order them by the irreversibility of what your agent can do. An agent that only reads needs a handful; one that can pay needs all twelve.

Full page →

How do you test a kill switch safely?

In a staging environment under representative load, measuring the timestamp of the last accepted action after the stop. Then repeat in production during a maintenance window, because staging never reproduces real concurrency.

Full page →

What evidence should exist for every action?

What was attempted, which policy was evaluated and with what outcome, who approved it if approval applied, what the provider returned, and an integrity mechanism proving the record is unaltered.

Full page →

Why does my site rank well but never get cited?

Usually extractability or corroboration. Ranking rewards relevance and authority; citation additionally requires a liftable standalone answer and a claim that appears somewhere other than your own domain.

Full page →

Does llms.txt improve AI citation?

Some AI crawlers read it; Google ignores it. It is cheap and low-risk to publish. It is not a ranking mechanism and treating it as one misreads what it does.

Full page →

What is the single highest-leverage change?

A definition-first opening on your most commercially important pages — a complete standalone answer in the first 40–60 words.

Full page →

How important is off-site corroboration?

Very, and it is the most neglected. A claim that exists only on your own site gives an answer engine no independent reason to repeat it.

Full page →

Can AI citations be measured?

Only partially. Referral parameters, grounding queries and observed citations help. Complete attribution is not currently available and should not be promised.

Full page →

What is non-human identity?

Identity for software rather than people — service accounts, workloads, and now AI agents. It matters more for agents because they make unpredictable calls at machine speed, which is exactly what traditional service-account scoping assumes will not happen.

Full page →

Should each agent have its own credential?

Yes. Shared credentials make actions unattributable and prevent revoking one agent without breaking others.

Full page →

What is the biggest non-human identity risk with agents?

Over-scoping. Because nobody can predict which calls the agent needs, it is granted broad access, which combines badly with unpredictable behaviour.

Full page →

How do we start?

Inventory. Enumerate every non-human identity, its scope, its owner and its credential lifetime. You cannot right-size what you have not listed.

Full page →

What makes something an AI agent rather than a chatbot?

The ability to take an action with a real effect. A chatbot produces text a human acts on. An agent acts. The model can be identical; the actuator is what changes the risk profile.

Full page →

Is an AI agent the same as agentic AI?

The terms are used interchangeably. 'Agentic' usually emphasises planning and multi-step execution, but for governance purposes the operative question is the same: can it act without a human in between?

Full page →

Do regulations mention AI agents?

Rarely by name. Obligations attach to effects — automated decisions, personal data processing, financial actions — regardless of the label on the software. Singapore's agentic framework and DIFC Regulation 10 are the main exceptions.

Full page →

Does more autonomy mean more risk?

Not directly. A very autonomous read-only agent is low-risk; a barely autonomous agent with payment access is not. Irreversibility drives risk far more than autonomy does.

Full page →

How do I know if we have agents in production?

Look for credentials issued to non-human identities that can write, send or pay. If a service account can email customers or move money on a schedule nobody approves individually, you have an agent regardless of what the team calls it.

Full page →

What does AI agent governance cost in 2026?

Three layers: platform licensing, integration engineering to place gates in the effect path, and operations (policy, approvals, evidence review). Integration usually dominates. The bounded start is governing one irreversible action class end to end.

Full page →

What is the cheapest way to start governing AI agents?

Govern one irreversible action class — typically sending or paying — with deny-by-default policy, payload-bound approval and signed receipts. It produces defensible evidence immediately at minimum integration cost.

Full page →

How long does implementing agent governance take?

Governing a first action class typically takes weeks, not quarters: the work is placing enforcement where the credential lives and wiring receipts. Full estate coverage then proceeds action class by action class.

Full page →

How long does an AI agent audit take?

A structured self-assessment takes about a day per business unit; third-party audits with evidence sampling run two to four weeks. Without an agent inventory, the audit's first finding is the missing inventory.

Full page →

What should an AI agent audit checklist include?

Ten checks in dependency order: inventory, identity, ownership, least privilege, policy gate, payload-bound approval, signed receipts, revocation drill, boundary tests, and retention mapped to obligations.

Full page →

What evidence proves an AI agent control works?

Two artifacts: proof the control fires — including recorded refusals — and proof its records resist silent alteration. A control with zero recorded refusals is unproven.

Full page →

What are the most common AI agent failure patterns?

Five recur in public incidents: excessive agency, injection-to-action chains, cascade amplification across agents, memory poisoning, and missing evidence at incident-review time.

Full page →

What single control prevents most agent incidents?

A deny-by-default gate on consequential actions with payload-bound human approval. Most public incidents involved an action no evaluated policy would have permitted.

Full page →

Why do AI agent post-mortems take so long?

Because logs are not receipts: they can be incomplete or editable, so reconstructing what an agent actually did becomes forensic work. Signed, hash-chained receipts make replay a query.

Full page →

Who should own AI agent governance in an enterprise?

Whoever owns model or technology risk, with security, compliance and each agent's business owner in the loop. The observed failure mode is ownership by nobody.

Full page →

How should agent evidence retention be set?

Match each evidence class to the longest obligation it answers — regulatory, contractual or dispute-driven — and verify old receipts still cryptographically verify across the whole window.

Full page →

Machine surface: answers.json · Last verified 2026-08-11.