Notes on governed agents
Working notes on autonomy policy, audit trails and what the EU AI Act asks of a company running AI agents.
An autonomy policy is a file, not a PDF
A governance document that cannot be executed stops nothing. Here is what an autonomy policy looks like when it is configuration that a gate reads.
2026-09-10What a tamper-evident decision log actually is
Hash chains without the cryptographic jargon: what they give you, what they do not, and why a plain database table is not enough for agent actions.
2026-09-10Three questions before you let an agent send a message
A five-minute test to run before any agent gets access to a mailbox or a phone line.
2026-09-10