Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

DeepInspect vs Protect AI Guardian: per-decision audit versus model-scanning

Protect AI Guardian (now under Palo Alto Networks after the August 2025 acquisition) focuses on model artifact scanning and ML supply chain risks. DeepInspect operates as a stateless policy gateway in the HTTP path between authenticated users or agents and any LLM. The two product categories often get evaluated together, but the enforcement boundary, the audit artifact, and the regulatory fit are different. This piece walks through where each sits.

Comparisons & Alternativescomparisonprotect-aipalo-altoai-gatewayenforcementml-supply-chain
Read post →

DeepInspect vs Credal: gateway architecture versus internal-AI portal

DeepInspect is a stateless policy gateway in front of any LLM. Credal is an internal AI assistant portal with controls bolted in around the portal product. The two get categorized together, but the enforcement boundary and the audit artifact are structurally different. This comparison walks through where each tool fits, what the per-decision log looks like, and which deployer profile each one serves.

Comparisons & Alternativescomparisoncredalai-gatewayai-securityenforcementaudit
Read post →

DeepInspect vs Aim Security: where the enforcement boundary sits

DeepInspect intercepts HTTP AI traffic between authenticated users or agents and any LLM, enforces identity-bound policy at the request layer, and writes a per-decision audit log. Aim Security sits primarily in the browser and DLP layer. This comparison walks through where each tool can and cannot enforce, what the audit trail looks like, and which one a deployer chasing the EU AI Act August 2 deadline should pick.

Comparisons & Alternativescomparisonai-gatewayai-securityaim-securityenforcementeu-ai-act
Read post →

GOVERN, MAP, MEASURE, MANAGE: The NIST AI RMF Functions in Plain English with Concrete Artifacts

NIST AI RMF organizes around four functions: GOVERN, MAP, MEASURE, MANAGE. Most teams encounter them as four-letter acronyms in vendor pitches and lose the thread. This article walks through each function in plain English, the concrete artifact a real organization produces under each, and where the four interlock with EU AI Act, ISO 42001, and federal procurement reviews. The artifact-first framing matters because GOVERN without artifacts is policy theater and MEASURE without artifacts is an audit gap.

Compliance & Regulationnistnist-ai-rmfai-governancecomplianceauditai-compliance
Read post →

Model Routing for Cost: What to Actually Measure Before Switching a Workload from GPT-4 to Haiku

Most "use the cheaper model" posts skip the rigor. Real model routing decisions have four layers: token cost, quality regression on an eval set, latency impact, and governance risk. This article walks through each layer with the questions a platform engineer should answer before flipping a workload from a frontier model to a smaller one, plus an example routing rule expressed at the gateway layer. The gateway is the right place to enforce routing because it has identity and policy context the application does not.

Platform & Architectureai-securitypolicy-enforcementarchitecturellmllm-securitydevsecops
Read post →

Shadow AI in 2026: Detection Patterns, Real Incidents, and What Your SOC Should Already Be Doing

The shadow IT framing for shadow AI is now outdated. Shadow AI is browser-extension-deep: ChatGPT in DevTools, Copilot in IDE, Claude in Slack. Blocking fails for the same architectural reason it failed for shadow SaaS in 2018. This article walks through current detection patterns at the DNS, proxy, OAuth consent, and browser inventory layers, three documented shadow AI incidents from 2025-2026, and why a policy gateway succeeds where blocking does not. The piece refreshes the existing shadow AI canon for the patterns SOCs are actually seeing in production this year.

Problem-Awareshadow-aiai-securitycybersecuritydata-loss-preventiondlppolicy-enforcement
Read post →

DORA + AI: What EU Banks Need to Map Before the January 2027 ICT Third-Party Register Deadline

The Digital Operational Resilience Act (DORA) treats LLM providers as critical ICT third parties when usage reaches scale. EU banks have to register, monitor, and document exit strategies for these dependencies. The deadline for the consolidated ICT third-party register goes live in January 2027. This article walks through the register requirements, the exit-strategy mandate, the concentration-risk test, and what changes when bank inference runs through OpenAI, Anthropic, and AWS Bedrock simultaneously. Gateway-level audit logs satisfy the per-decision evidence requirement DORA assumes.

Industry Verticalsdoracomplianceregulationai-complianceai-governanceaudit
Read post →

AI Bill of Materials (AIBOM): The Inventory Layer Compliance Teams Keep Skipping

Search interest in "AIBOM" and "AI bill of materials" is climbing fast, but the SERP is owned by vendors selling tooling rather than explainer content. This article defines AIBOM in concrete terms, compares it to the Software Bill of Materials (SBOM), maps the artifact to NIST AI RMF and EU AI Act Article 11 documentation requirements, and walks through what an AIBOM actually contains: model card references, training data lineage, inference dependencies, and gateway policy version. The per-decision audit log of LLM traffic is the inference-layer AIBOM artifact most programs are missing.

Compliance & Regulationai-governancecomplianceai-complianceauditeu-ai-actnist-ai-rmf
Read post →

Enterprise AI Governance: What the Operational Layer Actually Has to Produce

Enterprise AI governance gets framed as a policy program. The policies are necessary, but they sit on top of an operational layer that produces evidence, enforces controls, and tracks decisions in real time. This article walks through the four artifacts a real enterprise AI governance program needs at the operational layer: the AI system inventory, the per-decision audit record, the policy enforcement record, and the incident reconstruction artifact. Each is mapped to specific regulatory regimes and to the questions a board will ask.

Compliance & Regulationai-governanceenterprisecomplianceauditregulationai-security
Read post →

Mapping a Zero-Trust AI Gateway to NIST''s Upcoming COSAiS Single-Agent and Multi-Agent Overlays

NIST is teeing up the Concept of Operations for Securing AI Systems (COSAiS) overlays in two forms: a Single-Agent overlay and a Multi-Agent overlay, plus an AI RMF Profile for Critical Infrastructure. Federal contractors and critical infrastructure operators will be measured against these. The pre-map advantage is real: federal procurement reviews already reference the work in progress. This article walks the overlay structure, where a zero-trust AI gateway maps to each control family, and the evidence artifact each control consumes.

Platform & Architecturenistnist-ai-rmfzero-trustai-securitycompliancearchitecture
Read post →

Mapping the OWASP Top 10 for Agentic Applications 2026 to Control Points a Policy Gateway Enforces

OWASP GenAI published the Top 10 for Agentic Applications 2026 as a separate framework from the LLM Top 10. The framework adds the "agentic skills" intermediate behavior layer as a new vulnerable component and reorders the threat list around tool invocation, plan corruption, and identity propagation. This article maps each of the 10 categories to specific control points that a policy gateway at the AI request boundary actually enforces, with example policy rules and the audit fields each control writes.

Platform & Architectureai-securityagentic-aillm-securitypolicy-enforcementarchitectureaudit
Read post →

Cisco-Astrix and the Rise of Identity-Aware AI Gateways

On May 4, 2026, SecurityWeek reported that Cisco moved to acquire Astrix Security for roughly $400M. The deal validates identity-aware AI traffic enforcement as a buying-center category. Non-human identities (NHIs) — API keys, OAuth tokens, agent identities — are the new entry point. This article walks through what the deal signals for the AI security stack, how NHI-platform-bolted-on approaches differ from inline policy enforcement at the LLM request boundary, and the RFP questions a CISO should ask before defaulting to a bundled offering.

Comparisons & Alternativesai-securityidentity-and-authorizationpolicy-enforcementai-governancearchitecturecybersecurity
Read post →