Field reports, technical deep-dives, and policy commentary from the team building enterprise AI controls.

OpenAI, Anthropic, and every major model provider now price AI by the token. As that becomes the industry standard, the token economy is reshaping how the enterprise budgets, scales, and secures AI - here is what is driving it and how to stay in control.

Browsers are getting AI agents that can act on a user's behalf. We adopted the new WebMCP standard from Google early - and gated every agent action behind a human, by design.
Governance that lives in a document can't be enforced. Here's how we designed a declarative language so a control is the runtime, not a recommendation.
Sending every request to an LLM-judge is slow, expensive, and non-deterministic. A layered pipeline resolves most requests without a model at all.
Shipping a new control to production blind is how you take down a customer workflow. Replay real and synthetic traffic against a candidate policy first.

Enterprises don't have an AI observability problem. They have a runtime enforcement problem. Here's what changes when governance becomes infrastructure.
How a customer support agent quietly egressed PII across three subsystems - and the four enforcement points that would have stopped it.