Latest insights on AI governance.
Research notes, explainers, and news from Maetra on AI agents, compliance, security controls, and the rules shaping production AI.
Industry news
61 insights
Alation adds agent lineage to AI governance and data context
Alation's AIOS expansion makes agent lineage a data-governance problem. The useful control is not another chatbot interface, but traceability from an agent to the live data, pol...
Codex sandbox escapes show why coding agents need outer controls
The reported Codex sandbox escapes were patched, but the control lesson remains current. Coding agents need inventory, version checks, untrusted-repository handling, helper isol...
US-China AI incident line turns safety talks into evidence work
The proposed US-China AI incident line is not a binding rule yet. Its governance value depends on precise incident thresholds, evidence records, escalation owners and proof that...
Decision Intelligence
1 insight
Task Guard
1 insight
AI governance and compliance
5 insights
What is AI governance? Definition, components, and frameworks
AI governance is the operating model that lets a company know which AI systems exist, what risk they carry, who owns them, and what proof shows they are controlled.
AI governance vs AI compliance: what is the difference?
AI governance is the operating system for responsible AI decisions; AI compliance is the proof that selected obligations and controls were met.
The five components of AI governance: discover, comply, govern, secure, audit
A complete AI governance program needs discovery, obligation mapping, decision workflows, runtime controls, and audit-ready evidence working together.
Interaction Guard
1 insight
AI compliance frameworks
5 insights
EU AI Act compliance checklist for AI agents
AI agent readiness for the EU AI Act starts with classification, but it becomes defensible only when tool access, oversight, logging, and evidence are tied to the agent's real b...
NIST AI RMF for generative AI: practical implementation guide
NIST AI RMF becomes practical when its governance, mapping, measurement, and management functions are translated into system-level records and controls.
ISO/IEC 42001 explained for AI governance teams
ISO/IEC 42001 is best understood as a management system for AI: policies, ownership, risk treatment, operational controls, monitoring, and improvement.
AI agent inventory
5 insights
What is an AI agent inventory?
An AI agent inventory is the live system of record for agents, owners, purposes, tools, data access, autonomy, risk, approvals, and evidence.
How to discover AI agents across your organization
AI agent discovery needs signals from code, SaaS usage, cloud logs, vendors, workflow tools, and team intake, not a single annual survey.
Why shadow AI agents create compliance risk
Shadow AI agents create risk because they can process data, call tools, and influence decisions without ownership, review, monitoring, or evidence.
AI policy and approvals
5 insights
How to create an AI approval workflow
A good AI approval workflow routes systems by actual risk, leaves a decision trail, and gives teams a clear path to launch without bypassing governance.
What approvals should high-risk AI agents require?
High-risk AI agents should require approvals from business, technical, security, privacy, legal, compliance, and risk owners before production use.
Human-in-the-loop controls for AI agents
Human-in-the-loop control is effective only when the reviewer has authority, context, time, and a clear decision point before meaningful action occurs.
AI security and runtime controls
5 insights
Prompt injection controls for AI agents
Prompt injection risk is reduced through layered controls: instruction boundaries, tool limits, retrieval hygiene, output validation, human review, and incident evidence.
OWASP LLM Top 10 checklist for production AI systems
The OWASP LLM Top 10 becomes operational when each risk is mapped to controls, monitoring, owners, and evidence for specific AI systems.
How to prevent excessive agency in AI agents
Preventing excessive agency means limiting tools, permissions, action scope, autonomy, and fallback behavior before an agent reaches production.
AI audit evidence
5 insights
What AI audit evidence should teams collect?
AI audit evidence should show what the system is, why it was approved, how it is controlled, what changed, and what happened in production.
How to prove AI governance controls are working
To prove AI governance controls work, teams need design evidence, operating evidence, exceptions, incidents, and review records tied to each system.
AI audit logs: what to capture for compliance
AI audit logs should capture system context, user action, model interaction, tool use, policy decisions, human review, and incident links without over-collecting sensitive content.
AI governance comparisons
5 insights
AI GRC vs AI governance platform: what is the difference?
AI GRC coordinates policies, controls, evidence, and assurance. An AI governance platform keeps system-level facts about AI inventory, risk, runtime behavior, and accountable de...
Maetra vs manual AI governance spreadsheets
Spreadsheets can start an AI inventory, but they break down when teams need discovery, approvals, runtime evidence, change tracking, and audit retrieval.
AI agent governance vs model governance
Model governance focuses on the model lifecycle; AI agent governance focuses on systems that use models, tools, data, autonomy, and runtime decisions.
AI governance templates
1 insight