Blog

Governing AI you did not build

Notes on running AI agents inside companies that will never standardize on one platform. Written for whoever is accountable the day an agent does something nobody approved.

Latest
/5 min read
Where it runs is not who decides

"Runs on your infrastructure" is about to become a claim almost every AI vendor can make, and it will mean four different things. The question that separates them is not where the work executes. It is which plane still belongs to the vendor.

Read
A gateway only governs what routes through it
/5 min read

An AI gateway is real enforcement, and it is strong at exactly the traffic that reaches it. The problem is not the gateway. It is that routing through one is a configuration choice, and the agents that most need governing are the ones nobody configured.

The endpoint knows which binary ran. It does not know what the agent did.
/5 min read

Endpoint security is excellent at the question it was built for, which is what software is running on this machine. An AI agent's risk is not the binary, it is the action that arrives at a system somewhere else, and three of the places agents run have no endpoint at all.

If it reads your prompts, it is a data processor
/5 min read

Most AI agent security works by having a model read the agent's prompts, responses and reasoning and judge whether the intent looks acceptable. That is a real product with a real consequence: the vendor is now processing whatever your agents touch. There is another way to decide, and it never sees the content at all.

The invoice nobody could explain
/5 min read

The first AI bill that makes someone flinch is rarely the biggest one. It is the one where nobody in the room can say which agent spent it, on whose behalf, doing what. That is not an accounting problem. It is the same governance gap, arriving with a number attached.

Six questions to ask any AI agent security vendor, including us
/5 min read

A short evaluation checklist for anyone buying AI agent governance. Every question is one we answer in writing, and two of them end most demos.

Detected is not observed. Observed is not gated. Gated is not contained.
/5 min read

Four words the AI security market uses interchangeably, what each one actually means, and the exact ceiling of what damn.dev enforces on every surface we ship.

No company is going to standardize on one AI platform
/5 min read

Every AI governance product assumes your company will eventually pick one platform and route everything through it. That assumption is structurally wrong, and it is why the agents that most need governing are the ones that will never move.

A camera, a lock, and a notarized logbook are three different objects
/6 min read

Almost everything sold as AI agent security is a camera. Cameras are genuinely useful and they have never stopped anything. Here is what the other two objects are, why vendors collapse all three into the word "control", and the test that tells them apart in a demo.

Why we're building damn.dev
/5 min read

We set out to build a workspace where AI agents do real work alongside a team. The hard part was never making them capable. It was that the moment an agent holds a real credential on a real system, nobody in the company can answer three very ordinary questions about it.