Year
- 2026
Category
- Insights
- Product
- Engineering
- Incident
Tag| Compliance
- AI governance
- Approvals
- Audit
- Compliance
- Execution control
- Identity security
- MCP
- Privileged access
- Work Sessions
- Zero standing privilege
The AlpacaX blog—security, product thinking, and what we're learning as we build AI agent execution control.

Insights
Verification guidance exists. Turning it into a rule is still your job.
A session analysis can tell you what to tighten. Turning that into a rule is still your job today.

Insights
HIPAA day-90 audit: what session expiry misses
A HIPAA day-90 audit should review grant history, not just a session's current expiry. Here is what to pull.

Insights
EU AI Act high-risk deadline moved to 2027. What didn't?
Article 50 stayed in force. Two new bans arrive in December. Only the classification clock moved—to 2027.

Insights
Offboarding access revocation: what a departing engineer leaves running
Disabling the account ends their login. It doesn't touch what they built, or tell you what they ran.

Insights
AI vendor risk assessment in 2026: the runtime questions your questionnaire is missing
Your questionnaire covers who the vendor is and how they store data. It says nothing about what their agent executes on your servers once you authorize it.

Insights
ISO 42001 Stage 1 checklist: the documentation to have ready before your audit
Stage 1 is a documentation and readiness review—the part of ISO 42001 you can actually prepare for in advance. Here's what an auditor expects on the table before Stage 2.

Insights
ISO 42001 audit checklist: the controls a policy document can't satisfy
You can pass Stage 1 on paperwork. Stage 2 asks what your AI agents actually did in production—and three Annex A controls decide whether you have the answer.