# ApexClaw - full index for language models Generated 2026-08-13. 85 pages. Agent-queryable. ## https://apexclawai.com/apexclaw-receipts/ ApexClaw Receipts — The Receipt Format Inside Our Governance Audit ApexClaw Receipts is the draft receipt-format schema used inside ApexClaw's own governance audit: passports, policy decisions, approvals, execution and refusal receipts, revocation and replay. Not a standalone protocol or standard. Published for use and critique. ## https://apexclawai.com/answers/ The Answer Bank — 362 Direct Answers on Agent Governance A bank of 362 direct, citable answers on AI agent governance: identity, policy gates, receipts, MCP, wallets, OWASP ASI01-ASI10, EU AI Act, cost, audits and incidents. Machine-readable at /.well-known/answers.json. ## https://apexclawai.com/ask/ Ask ApexClaw - Agent-Queryable Answers on AI Agent Governance The agent-queryable answer endpoint: 362 sourced, filterable answers on AI agent governance - identity, receipts, policy gates, MCP, wallets, OWASP, regulation. Machine index at /api/ask.json, MCP manifest at /.well-known/mcp.json. ## https://apexclawai.com/compare/ Agent Trust Layer vs Observability, Guardrails, Gateways & NHI — ApexClaw How an agent trust layer differs from AI observability, guardrails, LLM gateways, non-human identity vendors, runtime security, audit logging and GRC platforms. Plus build-vs-buy and the four questions that separate the categories. ## https://apexclawai.com/contact/ Contact — ApexClaw Three questions to get to the right starting point: what your agents can access, what consequence worries you most, and what you need next. Gap Brief, full audit, or incident response. ## https://apexclawai.com/demos/block-approve-tamper/ BLOCK / APPROVE / TAMPER — The Three-Case Control Test — ApexClaw Three cases that separate a governed agent estate from an instrumented one: an out-of-scope action refused with a signed receipt, a payload-bound approval that refuses when the payload changes, and a tampered receipt that breaks chain verification. ## https://apexclawai.com/founder/ Founder — Julian Joseph — ApexClaw ApexClaw was founded by Julian Joseph, who built and operates Omega, the governed autonomous system used as first-party evidence on this site. ## https://apexclawai.com/glossary/ AI Agent Governance Glossary — ApexClaw Definitions for agent governance: agent passport, execution receipt, assurance gateway, autonomy budget, payload-bound approval, MCP, AP2, x402, kill switch, replay and more. ## https://apexclawai.com/ ApexClaw — Govern Every AI Agent Action, Prove Every One ApexClaw is an evidence-grade agent trust layer: signed execution receipts, policy gates, human approvals, autonomy budgets, revocation and replay for autonomous AI agents. Govern every agent action before it happens. Prove every action afterward. ## https://apexclawai.com/industries/ AI Agent Governance by Industry - BFSI and Healthcare How AI agent governance is examined in banking and healthcare: the instruments, the questions examiners actually ask, and the evidence that answers them. ## https://apexclawai.com/industries/bfsi/ AI Agent Governance for Banking & Financial Services — ApexClaw DORA, OSFI E-23, SR 11-7, NYDFS Part 500, MAS FEAT, APRA CPS 230/234 and PSD2 mapped to agent governance. Why model risk management does not cover agents, and the seven questions an examiner asks. ## https://apexclawai.com/industries/healthcare/ AI Agent Governance in Healthcare — HIPAA, FDA and State Law How HIPAA, FDA device thinking and state AI laws apply to AI agents in healthcare, where the clinical boundary sits, and what evidence regulators and health systems expect. ## https://apexclawai.com/platform/ The Agent Trust Layer — ApexClaw Platform The ApexClaw platform is an evidence-grade agent trust layer: agent identity, policy enforcement, execution receipts, MCP governance, and wallet governance. The minimum trust spine for autonomous AI agents. ## https://apexclawai.com/platform/agent-identity/ Agent Identity & the Agent Passport — ApexClaw Platform Cryptographic identity, named human ownership, mission scope, tool permissions, autonomy level and lifecycle for every AI agent. Covers non-human identity, least privilege, shadow agent discovery and delegation without impersonation. ## https://apexclawai.com/platform/agent-observability/ AI Agent Observability — Beyond Traces to Governance Evidence Why agent observability differs from application observability: capturing decisions and authority rather than spans, and producing evidence that holds up in an audit. ## https://apexclawai.com/platform/agent-wallet-governance/ Agent Wallet & Payment Governance — AP2, x402 — ApexClaw Governing AI agents that hold payment capability: AP2 cryptographic mandates, x402 settlement, hard fail-closed spend ceilings, merchant scoping, payment kill switch and authorization evidence for every transaction. ## https://apexclawai.com/platform/execution-receipts/ Execution Receipts & Replay — ApexClaw Platform Signed, hash-chained execution receipts for AI agent actions: identity, policy version, payload-bound approval, outcome and chain verification. Includes replay and the BLOCK/APPROVE/TAMPER test. ## https://apexclawai.com/platform/mcp-governance/ MCP Governance — Identity, Authorization & Tool Exposure — ApexClaw Governing Model Context Protocol servers and tools: the 2026-07-28 specification, Enterprise-Managed Authorization, OAuth 2.1 resource-server model, tool-exposure assessment, and the confused-deputy and token-passthrough failure modes. ## https://apexclawai.com/platform/policy-enforcement/ Policy Enforcement & the Assurance Gateway — ApexClaw Platform Deny-by-default policy gates, payload-bound single-use expiring approvals, autonomy levels, circuit breakers and kill switches for AI agents. Why a guardrail filters and a gate authorizes. ## https://apexclawai.com/platform/post-quantum-agent-evidence/ Post-Quantum Agent Evidence — Will Your Receipts Still Verify? — ApexClaw Agent execution receipts are signed, retained for years, and mostly not quantum-safe. ML-DSA, SLH-DSA, CNSA 2.0's January 2027 deadline, the FIPS 140-2 sunset, crypto agility, and harvest-now-forge-later. ## https://apexclawai.com/platform/revocation-kill-switch/ Agent Revocation and Kill Switch — Stopping an Agent That Acts How to revoke an AI agent's authority and stop it mid-flight: revocation propagation, blast-radius scoping, in-flight action handling and proving the stop actually took effect. ## https://apexclawai.com/pricing/ AI Agent Governance Pricing - How ApexClaw Is Scoped and Priced How ApexClaw agent governance is priced: the three cost layers (platform, integration, operation), why scope precedes price, the minimum useful engagement, and where the Agent Trust Gap Brief fits. ## https://apexclawai.com/proof/omega-governed-run/ Omega: A Governed Run, With the Failures Visible — ApexClaw Omega is an autonomous system running under ApexClaw's own controls: refusals on unauthorized sends, receipts emitted, zero real external sends. Published with its limitations rather than as a case study. ## https://apexclawai.com/regions/ AI Agent Governance by Region — Seven Regulatory Regimes How AI agent governance differs across the EU, US, Middle East, Canada, APAC, Latin America and the UK — the instruments that bind, dated and sourced. ## https://apexclawai.com/regions/asia-pacific/ AI Agent Governance in Asia-Pacific — Singapore, Korea, Japan Singapore's agentic AI framework is the only major published framework addressing AI agents directly. Korea's AI Basic Act, Japan's approach and APRA's prudential expectations complete the picture. ## https://apexclawai.com/regions/canada/ AI Agent Governance in Canada — OSFI E-23 and What Replaced AIDA AIDA did not pass. OSFI Guideline E-23 applies from May 2027 and is the real Canadian agent-governance deadline for federally regulated financial institutions. ## https://apexclawai.com/regions/european-union/ AI Agent Governance in the European Union — What Applies What the EU AI Act, the Digital Omnibus deferral, DORA and national measures actually require of AI agents that take actions, and what evidence supervisors expect. ## https://apexclawai.com/regions/latin-america/ AI Agent Governance in Latin America — Brazil PL 2338 Brazil's PL 2338 is the region's most advanced AI bill and follows a risk-tiered structure familiar from the EU. What that means for AI agents, plus the data-protection regimes that bind today. ## https://apexclawai.com/regions/middle-east/ AI Agent Governance in the Middle East — DIFC, UAE, Saudi DIFC Regulation 10 enforced from January 2026, the Autonomous Systems Officer role, the UAE federal AI authority and Saudi SDAIA guidance — what binds AI agents and what does not. ## https://apexclawai.com/regions/united-kingdom/ AI Agent Governance in the United Kingdom — Regulator-Led The UK has no AI act. Governance runs through existing regulators — FCA, ICO, Ofcom — using existing powers, plus UK GDPR and sectoral rules. What that means for AI agents. ## https://apexclawai.com/regions/united-states/ AI Agent Governance in the United States — State Patchwork How Texas TRAIGA's safe harbor, Colorado SB 26-189, California transparency rules and federal sectoral supervision apply to AI agents that take actions. ## https://apexclawai.com/resources/ AI Agent Governance Resources — Articles and Reference Reference articles on AI agent governance: definitions, control checklists, non-human identity, execution receipts, AI search citation, and incident response. ## https://apexclawai.com/resources/agent-execution-receipts-explained/ Execution Receipts Explained — Evidence an AI Agent Can Produce What an execution receipt contains, why application logs are not evidence, how receipt chains provide integrity, and what replay does and does not prove. ## https://apexclawai.com/resources/agent-governance-audit-checklist/ The Agent Governance Audit Checklist — Copyable, 2026 A copyable AI agent governance audit checklist: inventory, identity, permissions, policy gates, approvals, receipts, revocation, and the evidence each control must produce to count. ## https://apexclawai.com/resources/agent-governance-cost/ What Agent Governance Actually Costs — A 2026 Breakdown What AI agent governance costs in 2026: the three budget layers, the minimum defensible deployment, what ungoverned agents cost when they fail, and why retrofitting is the expensive path. ## https://apexclawai.com/resources/agent-incident-patterns/ AI Agent Incident Patterns — What Public Post-Mortems Repeat The failure patterns public AI agent incidents repeat: excessive agency, injection-to-action chains, cascade amplification, memory poisoning, and the missing-evidence problem every post-mortem cites. ## https://apexclawai.com/resources/agent-incident-what-to-do/ An AI Agent Did Something Wrong — What To Do First The first hour after an AI agent takes a harmful action: contain, preserve evidence, establish scope, notify, and the mistake that destroys your ability to explain what happened. ## https://apexclawai.com/resources/agentic-ai-governance-statistics/ Agentic AI Governance Statistics - Sourced and Dated A sourced reference of agentic AI governance facts: regulatory deadlines (DIFC, OSFI E-23, CNSA 2.0, FIPS 140-2), adoption figures with caveats, and first-party measurements with methodology. ## https://apexclawai.com/resources/ai-agent-governance-checklist/ AI Agent Governance Checklist — 12 Controls Before Production A concrete pre-production checklist for AI agents that take actions: action inventory, least privilege, approval gates, idempotency, caps, receipts, revocation and testing. ## https://apexclawai.com/resources/choosing-agent-governance/ How to Choose an AI Agent Governance Approach - A Buyer's Guide A decision aid for choosing AI agent governance: start from the action inventory, the minimum any solution must do, build-vs-buy on total cost of evidence, and the questions that expose a weak control. ## https://apexclawai.com/resources/how-ai-search-engines-cite-sources/ How AI Search Engines Choose What to Cite Why AI answer engines cite some pages and paraphrase around others: crawler access, extractability, sourcing and off-site corroboration — the four gates in order. ## https://apexclawai.com/resources/non-human-identity-agents/ Non-Human Identity for AI Agents — NHI, Secrets and Scope Why AI agents break traditional identity models, how non-human identity applies, and what to do about credential sprawl, over-scoped service accounts and unattributable actions. ## https://apexclawai.com/resources/what-is-agent-governance/ What Is AI Agent Governance? Definition, Scope and How It Differs AI agent governance defined: the control point between an agent's decision and its effect - identity, policy gates, approvals and signed receipts - and how it differs from AI safety, guardrails and observability. ## https://apexclawai.com/resources/what-is-an-ai-agent/ What Is an AI Agent — A Definition That Survives Scrutiny An AI agent is software that pursues a goal by choosing and taking actions with real effects. The distinction that matters for governance is not autonomy, it is whether it can act. ## https://apexclawai.com/roles/ Who Owns AI Agent Governance — Roles and Accountability Which role owns AI agent governance: CISO, Chief AI Officer, model risk, compliance, platform engineering — and what each is accountable for when an agent acts. ## https://apexclawai.com/services/ Growth Services — Delivered by ThruLiquid — ApexClaw The full ThruLiquid service catalog: AI search visibility, GEO/AEO, content authority, enterprise SEM and SEO, LinkedIn ABM, outbound, GTM engineering, RevOps and attribution. Partner company to ApexClaw. ## https://apexclawai.com/services/abm/ ABM Services — Account-Based Marketing for Technical Buyers Account-based marketing built on named-account targeting, buying-committee mapping and measurement tied to pipeline rather than impressions. ## https://apexclawai.com/services/ai-search-visibility-audit/ AI Search Visibility Audit — Get Cited by AI Answer Engines A structured audit of whether AI answer engines can find, parse, trust and cite your content — covering crawler access, extractability, entity clarity and off-site consensus. ## https://apexclawai.com/services/analytics-attribution/ Attribution Engineering — Warehouse-Native Multi-Touch — ThruLiquid Services Warehouse-native multi-touch attribution: modelling built on the data warehouse connecting ad platforms, web analytics and CRM into one pipeline-attribution model finance will defend. ## https://apexclawai.com/services/content-authority/ Content & Entity Authority — Being the Cited Source — ThruLiquid Services Content and entity authority engineering: definition-first content, corroborating off-site consensus, and knowledge-graph presence that makes a brand the source AI engines cite and buyers trust. ## https://apexclawai.com/services/enterprise-sem/ Enterprise SEM, Measured in Pipeline — ThruLiquid Services Enterprise search engine marketing measured in attributed pipeline, not clicks: named-account visibility, intent capture across Google and Microsoft Ads, and attribution a finance team accepts. ## https://apexclawai.com/services/enterprise-seo-migration/ Enterprise SEO & Migration Protection — ThruLiquid Services Enterprise SEO as revenue infrastructure: technical architecture, entity consistency, and migration protection through rebrands, domain moves and platform changes without losing accumulated search equity. ## https://apexclawai.com/services/geo-aeo/ GEO and AEO Services — Generative and Answer Engine Optimisation Generative Engine Optimisation and Answer Engine Optimisation: making content extractable, sourced and corroborated so AI answer engines cite it rather than paraphrase around it. ## https://apexclawai.com/services/gtm-engineering/ GTM Engineering — Signal-Based Outbound Systems — ThruLiquid Services GTM engineering: signal-driven target detection, enrichment, routing and sequencing systems that let a small revenue team operate with the reach of a large one — governed, deliverable, and measured in meetings. ## https://apexclawai.com/services/linkedin-abm/ LinkedIn ABM — Account-Based Marketing on LinkedIn — ThruLiquid Services LinkedIn account-based marketing run against a named account list: buying-committee targeting, MAL measurement, webinar and content programs that produce marketing-accepted leads from target accounts. ## https://apexclawai.com/services/outbound/ Outbound Services — Deliverability, Sequencing and Compliance Outbound built on deliverability infrastructure, defensible targeting and lawful-basis discipline — the parts that determine whether a programme works at all. ## https://apexclawai.com/services/revops/ RevOps Services — Data, Routing and Reporting You Can Trust Revenue operations: CRM data integrity, lead routing, lifecycle definitions and reporting that survives scrutiny — the foundation every other GTM investment depends on. ## https://apexclawai.com/solutions/ Agent Governance Solutions & Assessments — ApexClaw Agent Trust Gap Brief, Agent Trust Audit, incident response, inventory and permission mapping, MCP tool-exposure assessment, evidence and replay assessment, revocation testing, and governed pilots. ## https://apexclawai.com/solutions/agent-incident-response/ AI Agent Incident Response — ApexClaw What to do when an AI agent acts outside what you intended: contain, preserve, bound the blast radius, establish whether it was authorized or merely unstopped, and reconstruct from receipts. ## https://apexclawai.com/solutions/agent-trust-audit/ Agent Trust Audit — Inventory, Controls, Evidence — ApexClaw A full assessment of your AI agent estate: inventory and permission mapping, MCP tool-exposure, evidence and replay testing, revocation and kill-switch verification, and a remediation roadmap ordered by blast radius. ## https://apexclawai.com/solutions/agent-trust-gap-brief/ Agent Trust Gap Brief — ApexClaw A short, evidence-based read of your AI agent risk surface: inventory snapshot, ranked trust gaps, evidence gaps, standards mapping, one recommended next control, and stated limitations. ## https://apexclawai.com/standards/ AI Agent Control Crosswalk — OWASP ASI, NIST AI RMF, ISO 42001, EU AI Act Twelve agent governance controls mapped across OWASP Top 10 for Agentic Applications 2026, NIST AI RMF, ISO/IEC 42001 and the EU AI Act. Published for checking, not as a compliance claim. ## https://apexclawai.com/standards/agent-assurance-frameworks/ AI Agent Assurance Frameworks — What Exists and What Certifies Which AI assurance frameworks are certifiable, which are voluntary, and which carry legal weight — ISO 42001, NIST AI RMF, SOC 2, OWASP ASI and the EU AI Act compared. ## https://apexclawai.com/standards/agent-audit-and-attestation/ AI Agent Audit, Attestation & Red Teaming — What Exists in 2026 — ApexClaw Assessment, attestation, certification and red teaming are not interchangeable. CSA STAR for AI, ISO/IEC 42001, AI-CAIQ, MITRE ATLAS, PyRIT, garak, Inspect, DeepTeam — and why no ratified agent certification exists yet. ## https://apexclawai.com/standards/eu-ai-act-ai-agents/ EU AI Act for AI Agents — What Still Applies After the Digital Omnibus The Digital Omnibus deferred Annex III high-risk obligations to December 2027 and Annex I to August 2028, but most transparency obligations took effect 2 August 2026. Article-by-article for agent operators. ## https://apexclawai.com/standards/mcp-2026-07-28/ MCP 2026-07-28 Migration & Authorization Hardening — ApexClaw The Model Context Protocol 2026-07-28 specification: stateless core, authorization hardening onto OAuth 2.1, Enterprise-Managed Authorization, and the twelve-month deprecation window closing in July 2027. ## https://apexclawai.com/standards/nist-ai-rmf-agents/ NIST AI RMF for AI Agents — and the TRAIGA Affirmative Defense NIST AI RMF read for agentic systems: GOVERN, MAP, MEASURE, MANAGE mapped to agent identity, tool inventory, execution receipts and kill switches. Plus the Texas TRAIGA affirmative defence. ## https://apexclawai.com/standards/owasp-agentic-security/ OWASP Agentic Security - Risks, Controls, Evidence OWASP agentic security explained: the Agentic Top 10 taxonomy (ASI01-ASI10), the control that answers each risk, and the evidence that proves controls actually fire. ## https://apexclawai.com/standards/owasp-agentic-top-10/ OWASP Top 10 for Agentic Applications 2026 (ASI01–ASI10) — Controls & Evidence All ten OWASP agentic risks, ASI01 through ASI10, each with how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/agent-goal-hijack/ ASI01 Agent Goal Hijack — Controls, Evidence & Limitations — ApexClaw ASI01 Agent Goal Hijack from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/agentic-supply-chain/ ASI04 Agentic Supply Chain Vulnerabilities — Controls, Evidence & Limitations — ApexClaw ASI04 Agentic Supply Chain Vulnerabilities from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/cascading-failures/ ASI08 Cascading Failures — Controls, Evidence & Limitations — ApexClaw ASI08 Cascading Failures from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/human-agent-trust-exploitation/ ASI09 Human-Agent Trust Exploitation — Controls, Evidence & Limitations — ApexClaw ASI09 Human-Agent Trust Exploitation from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/identity-and-privilege-abuse/ ASI03 Identity and Privilege Abuse — Controls, Evidence & Limitations — ApexClaw ASI03 Identity and Privilege Abuse from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/insecure-inter-agent-communication/ ASI07 Insecure Inter-Agent Communication — Controls, Evidence & Limitations — ApexClaw ASI07 Insecure Inter-Agent Communication from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/memory-and-context-poisoning/ ASI06 Memory and Context Poisoning — Controls, Evidence & Limitations — ApexClaw ASI06 Memory and Context Poisoning from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/rogue-agents/ ASI10 Rogue Agents — Controls, Evidence & Limitations — ApexClaw ASI10 Rogue Agents from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/tool-misuse-and-exploitation/ ASI02 Tool Misuse and Exploitation — Controls, Evidence & Limitations — ApexClaw ASI02 Tool Misuse and Exploitation from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/standards/owasp-agentic-top-10/unexpected-code-execution/ ASI05 Unexpected Code Execution — Controls, Evidence & Limitations — ApexClaw ASI05 Unexpected Code Execution from the OWASP Top 10 for Agentic Applications 2026: how it manifests, the controls that address it, the evidence object that proves the control fired, and the honest limitation. ## https://apexclawai.com/trust/ Trust Center — Claims Ledger, Agent Identity & Crawler Posture — ApexClaw Every ApexClaw claim with its basis, verification date and expiry. ApexClaw Receipts endpoints, RFC 9421 readiness, Web Bot Auth as a draft not a standard, and the observe-not-block crawler posture. ## https://apexclawai.com/updates/ ApexClaw Updates - What Changed and When A dated log of ApexClaw platform and content updates: new pages, standards coverage, machine-layer changes and governance guides, newest first. Machine-readable at /rss.xml. ## https://apexclawai.com/use-cases/ AI Agent Use Cases — Governed Automation by Workload How AI agent governance differs by workload — field service, healthcare, revenue and procurement — and the controls each one actually needs. ## https://apexclawai.com/use-cases/healthcare-agent-governance/ Healthcare AI Agent Governance — HIPAA, Scope and Evidence Governing AI agents in healthcare operations: scheduling, prior authorisation, patient messaging and records. Where the clinical line sits and what evidence a regulator expects. ## https://apexclawai.com/use-cases/procurement-agent-governance/ Procurement Agent Governance — RFPs, Tenders and Bids Governing AI agents across procurement and tendering: what the agent may submit, how bid integrity is preserved, and the evidence a public buyer or auditor will expect. ## https://apexclawai.com/use-cases/revenue-agent-governance/ Revenue Agent Governance — Outbound, CRM and Pipeline Governing AI agents across outbound, CRM writes and pipeline: sending limits, data-protection duties, deliverability risk and the evidence that proves what was sent to whom.