#ai-governance
Tagged “ai-governance”
6 articles'Governance is a developer experience problem': a Docker Captain reframes AI-agent trust
A Docker Captain argues in a new post that AI-agent governance stalls on trust, not capability, and that the platforms which win will be the ones that draw clear boundaries so developers do not have to reason about controls each time they ship. The DX framing is mostly right; the invisible-controls part is where the next incident hides.
Aug 9, 2026 · Tomás VegaPlatform engineeringGitHub Copilot's enterprise managed-settings.json is now GA
GitHub Enterprise Cloud can now pin five Copilot behaviours from a single managed-settings.json in a .github-private repository. The file overrides local user config, is fetched on every auth, and refreshes hourly.
Jul 5, 2026 · Maya OkonkwoPlatform engineeringGitLab 19.1 makes the AI Catalog event-driven and gives admins the off switch
Duo Flows in the AI Catalog can now fire on merge-request and pipeline events instead of waiting for a human click, and the same release ships admin controls to disable custom agents, scope the catalog to a group hierarchy, and validate flow config at save time.
Jun 20, 2026 · Maya OkonkwoSecurity & supply chainGitLab 19.1 makes AI secret triage GA, and lets admins lock Duo on across an instance
GitLab 19.1 ships with two changes platform teams have to plan a rollout around: a generally available AI pass that scores secret-detection findings, and an always-on availability mode that lets administrators force Duo on for an entire instance or top-level group.
Jun 19, 2026 · Maya OkonkwoSecurity & supply chainGitLab 19.1 pulls third-party scanners into one vulnerability view, SARIF and all
GitLab 19.1 lets any SARIF-emitting scanner file findings into the same vulnerability view as its native results, routed through the platform's auto-remediation and false-positive workflow. The interesting part isn't the integration, it's the governance lever it hands platform teams.
Jun 19, 2026 · Tomás VegaSecurity & supply chainGitHub gives enterprises a kill switch for Copilot's yolo mode
Enterprise-managed settings can now block GitHub Copilot CLI and VS Code from running in bypass-permission mode, the first governance control to land in that configuration plane.
Jun 17, 2026 · Tomás Vega