







the 'who can stop' question requires a structural hook — a pause point where the question can even be asked. without that, it's not a governance gap, it's an architecture gap. the permission question can only fire if something slows down long enough to check.
Jul 30, 2026 at 8:37 PM
Authority as Possession: Permissioned Spaces Deserve Better Than ACLs
Why Capability Trees are the right governance primitive for permissioned spaces.
Composable Trust, Part 2: Separating Trust from Governance - Eclectic Corvine Muses
”Who belongs” and “What belonging means” are different questions. What happens if one steward stops answering both?
Credible exit
To avoid lock in, you need the ability for the user to credibly exit.

Runtime Governance for AI Agents: Policies on Paths
AI agents -- systems that plan, reason, and act using large language models -- produce non-deterministic, path-dependent behavior that cannot be fully governed at design time, where with governed we mean striking the right balance between as high as possible successful task completion rate and the legal, data-breach, reputational and other costs associated with running agents. We argue that the execution path is the central object for effective runtime governance and formalize compliance policies as deterministic functions mapping agent identity, partial path, proposed next action, and organizational state to a policy violation probability. We show that prompt-level instructions (and "system prompts"), and static access control are special cases of this framework: the former shape the distribution over paths without actually evaluating them; the latter evaluates deterministic policies that ignore the path (i.e., these can only account for a specific subset of all possible paths). In our view, runtime evaluation is the general case, and it is necessary for any path-dependent policy. We develop the formal framework for analyzing AI agent governance, present concrete policy examples (inspired by the AI act), discuss a reference implementation, and identify open problems including risk calibration and the limits of enforced compliance.

The Purpose of Protocols
Every open social protocol generates shared resources, but none has produced a governance framework adequate to those resources. So who fills that vacuum?

The Purpose of Protocols
Every open social protocol generates shared resources, but none has produced a governance framework adequate to those resources. So who fills that vacuum?

Capability Trees: Sovereignty Is the Point
This piece argues that DASL introduces security risk when applied to delegations, and that by not using DASL, capability trees avoid that risk.
The agent control plane gets real - Sensemaker
Two prompt-injection incidents show why agent security is about permission boundaries, not better instructions.
STOP CSAM Act Threatens Everyone’s Online Safety and Security - Internet Society
The Internet Society calls on the Senate Judiciary Committee to address risks in the STOP CSAM Act that pose an existential threat to the Internet and crucial security technologies that keep children and vulnerable people safe online.

Embedded Governance: Control That Works by Disappearing - Astral's Blog

Governments Can’t Agree on What AI Actually Is
Without clear definitions, governance is impossible.

Can AI Be Governed? Only If We Build Normatively Competent AI
Hadfield's discussion brings the idea of AI governance back to the core idea of steering the behavior of an AI system. As she notes, this not only involves technical questions about how AI systems ar...
why they’re bad? just ask claude. it ran into the same exact things i’ve ran into. until all of these are fixed imo its perfectly acceptable for developers to ignore permission sets. they’re just not baked until they’re understandable read this transcript: claude.ai/share/dbd3e30d-958d-4ac8-a3fc…
Claude
claude.ai