The Assembly and the Assembler
The biggest names in AI and private capital just stood up services firms to make enterprise AI work. The ratio behind the move is one to six. There are two ways to sell that layer: as hours, or as a machine.
The Routing Layer Gets Named From Three Directions
Three constituencies named the routing layer between May 4 and July 12: capital, the channel, and the developer mainstream. All three agree on the position. None includes identity, inline policy, or evidence.
The WOPR Brief: your monitoring stack is now an attack surface
This month an attacker turned Claude Code into a code-execution engine. On developers' own machines. No malware. No stolen password. No breach. The
Loops Moved the Work Up a Level. The Risk Moved Down One.
The field moved from prompting agents to designing the loops that run them. The developer conversation has the right cautions. Inside a regulated enterprise, the loop's connectors reach actions that do not reverse, and what the agent sends to the model is a disclosure on its own.
Two Postures on the Agent Call Path
Two postures. etect above the path. A control watches behavior and flags what looks wrong. Enforce on the path. A control sits inline, in the request itself. One tells you what happened. The other decides whether it happens.
Mythos, Daybreak, and the System Around the Model
A restricted frontier model leaked into a proxy this week before its evaluation finished. It raises the question two cyber systems already posed: is the capability the model, or the system around it? On offense, mostly the system. On defense, that answer is where the moat sits.
The Strategy Behind Open-Sourcing Shield
Free developer tools as a wedge into enterprise security is a known pattern. Here is why APERION ran it on purpose, and what we expect it to do.
Workflow Platforms Consolidate While Intelligence Community Names Runtime Controls
Microsoft Agent 365, the Five Eyes joint advisory, ServiceNow's AI Control Tower expansion, and the Zscaler-Symmetry acquisition described two distinct supervisory layers.
An LLM Agent Composed a Four-Pivot Intrusion in Real Time
Sysdig documented its first agent-driven intrusion: a reasoning model, not a pre-built playbook, improvised the path from a Marimo CVE to a database dump.
The CISO's Guide to Runtime Governance for AI Agents
If you run security at a regulated enterprise, you already have AI agents in production. You may not
Agent of an Agent
When an agent spawns another agent, the authority chain gets longer and the audit trail gets thinner. The runtime layer is the only place that can prove what actually happened at the end of the chain.
The Trust Fabric: A four-layer architecture for governing AI agents
The Trust Fabric, a four-layer architecture for governing AI agents