Blog

Technical insights on AI security from the Shrike team.

Guides & Reference
Posts
August 27, 2026

Five Attacks, Five Verdicts: Inside the NemoClaw Action-Governance Recipe

A case study of the Shrike recipe that cleared NVIDIA maintainer security review — the architecture, the five live validation cases it ships, and what the review demanded before it could merge.

August 14, 2026

When Google's Agent Calls Your Agent

Google's agentic booking now calls businesses — and what answers is increasingly the business's own AI, with authority to commit it. The phone line just became an agent-governance surface.

August 13, 2026

Does DLP Stop Shadow AI? What It Catches — and What Agents Slip Past

Partially. DLP stops the patterns it recognizes on the channels it monitors — but shadow AI fails both conditions, and AI agents add a question DLP was never designed to answer.

August 12, 2026

How Do You Prove AI-Agent Governance to an Auditor?

Auditors don't accept "we have a policy" — they accept evidence. The gap between claiming AI-agent governance and proving it, and what an assessor actually wants to see.

August 11, 2026

Securing NemoClaw Agents with Shrike

A drop-in recipe that adds runtime governance to NemoClaw agents — checking tool calls, MCP calls, and responses against policy before they run.

April 9, 2026

Why AI Agents Need Independent Governance

The model vendor can't audit itself. Why independent governance is a structural requirement for AI agent security.

April 9, 2026

Shadow AI: The Security Gap Your DLP Can't See

A majority of developers use AI tools daily. Traditional DLP doesn't scan AI prompts. Here's how to close the gap.

April 9, 2026

What Happens When AI Agents Spawn Sub-Agents

Delegation chains, blast-radius containment, and scope inheritance — governing the agent tree.