Year
- 2026
Category
- Insights
- Engineering
- Incident
- Product
Tag| AI governance
- AI governance
- Approvals
- Audit
- Compliance
- Execution control
- Identity security
- MCP
- Privileged access
- Work Sessions
- Zero standing privilege
The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Insights
Why AI governance pilots don't survive scale
The policy wasn't wrong. It just wasn't sized for agents your other teams stood up without telling you.

Insights
EU AI Act high-risk deadline moved to 2027. What didn't?
Article 50 stayed in force. Two new bans arrive in December. Only the classification clock moved—to 2027.

Insights
ISO 42001 Stage 1 checklist: the documentation to have ready before your audit
Stage 1 is a documentation and readiness review—the part of ISO 42001 you can actually prepare for in advance. Here's what an auditor expects on the table before Stage 2.

Incident
Alignment isn't enough: containing a misaligned agent's actions takes runtime execution control
Model-level alignment lowers the odds an agent misbehaves. It can't drive the odds to zero once the agent is running on real infrastructure.

Insights
AI governance on paper vs. governance during the task
A near-miss doesn't change your policy. It changes the question leadership asks about it.

Insights
JIT access control is for humans. What should we have for AI agents?
Just-in-time access governs whether an agent gets in, and when. It says nothing about what the agent does once inside.