Evidence, not intent.

Seven field notes on agent controls under DORA. Written while building one — what held, what didn't, and the two hours it took to find out.

The through-line: a habit is behaviour that is currently correct; a control is behaviour that cannot silently stop being correct. Under normal engineering pressure the two are indistinguishable. They diverge under a refactor six months from now, and under a supervisor asking how you know. Most of the difference cannot be added retroactively, which is why these are questions for now rather than for renewal.

We build systems; your counsel interprets the regulation. Each post names the obligation family it belongs to so you can hand it to the right person. Read them in order, or start at the seven questions.

02

A checkpoint is not evidence

Durable execution stores the state. A supervisor asks about the transition. The gap cannot be closed retroactively.

8 min read
04

The failure no guard catches

Every standard guard watches process. None of them ask whether the right question was answered.

7 min read
05

A test suite nobody has watched fail

“We tested it and it works” is the weakest sentence in a vendor conversation. What a test set has to contain before green means anything.

7 min read

Run these against your own stack.

We build the control layer this series describes for authorised firms operating under MiCA, DORA and the EU AI Act — per-request audit trails, approval records, exit readiness. Fifteen minutes on your architecture, no deck.

Book an architecture review Or read how AI Control works →