How the Sentry Intercepts System Calls to Contain Untrusted Agent Code
The Sentry in gVisor mediates every system call from untrusted code, reducing the host attack surface. Learn how interception works and why it matters for
904 original articles by Dr. Hernani Costa, PhD, on AI strategy, EU AI Act compliance, governance, and agentic systems for European businesses. Published under CC BY 4.0 — free to read, cite, adapt, and redistribute with attribution.
The Sentry in gVisor mediates every system call from untrusted code, reducing the host attack surface. Learn how interception works and why it matters for
Apply CISA Secure by Design to AI agents: make safe configurations the out-of-the-box default, so teams ship agents that are secure before anyone touches
Framing isolation as a change in trust model clarifies why microVM or userspace kernel boundary is the load-bearing decision when running untrusted agent
OWASP Top 10 for LLM Applications v1.1: A threat checklist for agent builders covering prompt injection, insecure output, and more.
When agents run untrusted code, isolation controls spread. Compare shared-kernel containers, userspace sandboxes, microVMs to limit blast radius.
OpenAI's recent research suggests simulation based pre release testing could weaken manual review gates. Engineering leaders must scrutinize these signals.
OWASP GenAI Project hosts a half-day summit on June 4, 2026, in London, covering agentic AI risks and European regulatory strategy for CISOs and AI
Claude Code now runs across your terminal, desktop app, phone, and browser, and sessions stay in sync across all of them. If you have been managing multiple Claude Code sessions by switching terminal tabs and losing track of which agent is doing what, there are three features…
Seven questions every CFO should ask about agentic AI spend to find leaks, measure real ROI, and decide whether to extend, cut, or restructure investment.
How to set up the Codex GitHub App for automated PR reviews, auto-fix, and AGENTS.md-driven code standards. The setup top engineering teams use in 2026.
OpenCode with MiniMax M2.5 delivers 80.2% SWE-Bench at 1/15 the cost of Claude Opus. Setup guide, routing strategy, and honest comparison for power users.
Most agentic AI pilots never reach production. Here is why the implementation layer matters more than the tool, and how to fix it.
Evaluate MCP servers across eight dimensions and a 30-day approval workflow to meet EU AI Act and DORA enterprise governance needs.
Local-first AI does not equal private; map data flows, logs, and reversibility before EU AI Act and GDPR documentation obligations fire.
Learn how to map data flows in a local-first AI assistant to meet GDPR Article 30 and EU AI Act requirements with a 10-boundary framework.
European scale-ups can turn reusable skills, governed memory, and audited harnesses into a compliance layer for EU AI Act and DORA.
Tier your open-source maintainer health rubric by dependency blast radius and replaceability to meet EU AI Act and DORA conformity expectations.
A concrete 30-day pilot runbook to evaluate an open-source AI coding agent before procurement, with seven evidence dimensions and EU AI Act context.
Automate a maintainer health rubric in CI to evaluate open-source AI tools before adoption, ensuring compliance with EU AI Act and DORA.
GitHub stars measure attention, not procurement fitness. Replace them with a license, maintenance, security, and pilot evidence frame.
/index.json — catalog of all 904 articles with metadata/feed.xml — Atom feed of the 50 most-recent articles/feed.json — JSON Feed 1.1 of the 50 most-recent articles/llms.txt — LLM discovery summary/llms-full.txt — full-text corpus for bulk LLM ingestion (904 articles, ~7 MB)/llms-recent.txt — rolling 30-day window for small-context LLM ingestion/sitemap.xml — XML sitemap pointing to canonical article URLs/hernanicosta.json — Schema.org Person entity for the author