Blog

Notes from the night shift

Running agents in production: cost, approvals, identity, and what breaks.

RSS
Audit & compliance

NIST AI RMF and ISO/IEC 42001 for the agent runtime

The EU AI Act is a law with a date. US security reviews cite NIST AI RMF; certification programs cite ISO/IEC 42001. What each one asks for, and which runtime records answer it.

· Audit & compliance · 5 min

Earlier posts

  1. We rewrote the kernel in Rust — with agents writing most of the PRsEngineering · 3 min
  2. What Rust gives this control plane that Go did notEngineering · 4 min
  3. An operating model the runtime can enforceOperations · 3 min
  4. What an agent audit row should carryAudit & compliance · 9 min
  5. Why service-account permissions don't fit agentsIdentity & access · 8 min
  6. Five things that keep breaking when AI agents move into productionOperations · 8 min
  7. Policy at action time: what the gate evaluatesApprovals & policy · 10 min
  8. Sub-agent identity: inherit and narrowIdentity & access · 8 min
  9. The lethal trifecta: where it actually livesIdentity & access · 7 min
  10. Stopping a running agentOperations · 8 min
  11. Introducing DeixicCompany · 1 min
  12. What the EU AI Act means for the agent runtime: an Article-by-article readAudit & compliance · 9 min
  13. Designing approvals operators actually readApprovals & policy · 9 min
  14. Finding the agents nobody deployedOperations · 8 min
  15. Replay: reconstructing an agent action from the audit logAudit & compliance · 9 min