Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

Gemini Enterprise Security: What VPC-SC, CMEK, and IAM Leave Open

VPC Service Controls, CMEK, and IAM cover three real but separate jobs inside Gemini Enterprise: network perimeter, encryption material control, and coarse role-based access. None of the three evaluates whether a specific authenticated caller, sending a specific prompt, should reach the model right now. This piece maps what each control secures and the request-level gap between them.

Platform & Architectureai-securitycloud-securityllm-securityidentity-and-authorizationarchitecturezero-trust
Read post →

Google Gemini Enterprise Audit Logs at the AI Request Boundary

Gemini Enterprise routes a Workspace user prompt through Vertex AI-backed model endpoints, and Google records that activity in two places: Cloud Audit Logs and the Workspace Admin console. This article separates what those two systems capture from the identity-bound, per-request policy record a security review actually needs.

Platform & Architectureai-securityllm-securityauditinline-enforcementpolicy-enforcement
Read post →

GitHub Copilot Security: What the Request Path to the Model Covers

GitHub Copilot completions, chat, and agent-mode requests leave the IDE as HTTP calls to GitHub Copilot API endpoints that route to OpenAI and Anthropic models. Org and enterprise policy, content exclusion, and telemetry settings shape what leaves the editor, but none of them evaluate a specific request against the developer sending it. This piece maps the controls and the gap between them.

Platform & Architectureai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

AI Security Posture Management Tools: The Categories That Matter and How to Choose

The AI-SPM market splits into five architectural categories: discovery-first scanners, CNAPP-bundled posture, runtime enforcement gateways, agent governance platforms, and AI-aware DLP. This guide describes where each sits in the stack, what to verify before buying, and how to sequence a purchase so visibility and enforcement reinforce each other instead of overlapping.

Comparisons & Alternativesai-securityai-governancearchitecturepolicy-enforcementcompliance
Read post →

AI Compliance Audit Checklist: The Evidence a Reviewer Will Actually Request

An AI compliance audit fails on the evidence you cannot produce, not the policy documents you can. This checklist walks through what a reviewer requests for a high-risk AI system: the inventory, the identity mapping, the per-decision records, the retention proof, and the vendor-AI coverage, with the EU AI Act and Fannie Mae as the reference deadlines.

Compliance & Regulationai-complianceauditcomplianceeu-ai-actai-governanceregulation
Read post →

AI Security Posture Management (AI-SPM): What It Covers and Where Runtime Enforcement Fits

AI security posture management (AI-SPM) inventories where AI runs, scores how each deployment is configured, and tracks the data those deployments reach. This guide covers the four capability areas of AI-SPM, where its point-in-time visibility ends, and why the per-request decision and per-decision audit record belong to a runtime enforcement layer at the AI request boundary.

AI Security Solutionsai-securityai-governancearchitecturepolicy-enforcementcloud-security
Read post →

What Is an AI Control Plane? Control Plane vs Data Plane for AI Traffic

An AI control plane is the layer that decides policy, identity, routing, and audit for AI requests, kept separate from the data plane that carries the actual prompt and completion. This explainer borrows the control-plane and data-plane split from networking, applies it to LLM traffic, names the four components, and shows why separating the two produces deterministic policy and an independent audit record.

Platform & Architecturearchitectureai-securitypolicy-enforcementllmzero-trust
Read post →

Google Agentspace Security: The Enterprise Answer Boundary

Google Agentspace security requires an access review that follows enterprise retrieval context into the model route used for an answer. This article separates source and identity administration from the HTTP request boundary where policy can inspect model egress and create independent decision evidence.

Platform & Architectureai-securityllm-securityzero-trustpolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Google Agentspace Audit Logs: Evidence for Agent Answers

Google Agentspace audit logs should join the originating employee or agent, retrieved enterprise sources, model route, and authorization decision for one answer. This article maps provider and source events to the independent HTTP request record needed to reconstruct model egress during a security review.

Platform & Architectureauditforensic-auditllm-securitypolicy-enforcementidentity-and-authorizationarchitecture
Read post →

Glean Audit Logs: Reconstructing an Enterprise AI Answer

Glean audit logs need to join the person who asked, the retrieved enterprise sources, the model route, and the policy decision that governed egress. This article separates source and administration events from a per-decision HTTP record that can reconstruct one AI answer during a security review.

Platform & Architectureauditforensic-auditllm-securitypolicy-enforcementidentity-and-authorizationarchitecture
Read post →