Developer builds open-source tool to expose gaps between AI policy rules and enforcement
A developer has released an open-source AI governance project after discovering that the so-called guardrails in their own AI coding setup were largely unenforced prose rather than real controls. The tool compiles written policies into actual enforcement mechanisms, such as pre-execution hooks for agents like Claude Code and Cursor that block commands before they run. A tiered reporting system distinguishes between policies that are truly enforced, those checked at commit time, and those that are merely advisory prompts, so dashboards reflect reality rather than the existence of a config file. The project includes install witnesses and a lockfile that hashes compiled artifacts to prevent deleted gates from falsely reporting compliance. Policies ship with eval suites that replay compiled gates against test repositories, and the catalog maps installable policies to frameworks including OWASP Agentic Top 10, MITRE ATLAS, NIST AI RMF, and the EU AI Act.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in