Research & Insights

Architecting Verifiable AI Governance

Technical deep dives, cryptographic receipt specifications, and strategies for moving enterprise AI from policy theater to execution-layer proof.

Featured ResearchForensic Review

Your AI Agent May Have Access. Does It Have Authority?

A forensic review and counterfactual governance analysis of the July 2026 OpenAI–Hugging Face autonomous-agent security incident — and why possession of a credential should never be treated as sufficient authority to act.

Download Full PDF
Category

Agent-Governance

Runtime-Authorization

Position Paper

AI-Enabled GRC and Internal Control Assurance

A governance architecture for agentic workflows, financial-control integrity, and verifiable evidence — arguing that an AI-enabled process must not become self-validating, and proposing a layered assurance model spanning business process, AI system, and independent governance.

By James GreenwoodPDF
Research Paper

Can You Prove an AI Output Has Not Been Altered?

This paper examines whether organizations can credibly prove that a material AI output, decision, or agent action has not been altered since execution, proposing a risk-based approach to tamper-evident AI event records.

By James GreenwoodPDF
Shadow AI

Detecting and Taming Unmanaged LLM Usage

Building non-intrusive network and gateway telemetry to bring shadow AI into your enterprise risk perimeter.

By James Greenwood5 min read