Delete your approval rule. Did a test go red?
Two failed attempts to prove a control worked, and the difference between a control and a habit.
Seven field notes on agent controls under DORA. Written while building one — what held, what didn't, and the two hours it took to find out.
The through-line: a habit is behaviour that is currently correct; a control is behaviour that cannot silently stop being correct. Under normal engineering pressure the two are indistinguishable. They diverge under a refactor six months from now, and under a supervisor asking how you know. Most of the difference cannot be added retroactively, which is why these are questions for now rather than for renewal.
We build systems; your counsel interprets the regulation. Each post names the obligation family it belongs to so you can hand it to the right person. Read them in order, or start at the seven questions.
Two failed attempts to prove a control worked, and the difference between a control and a habit.
Durable execution stores the state. A supervisor asks about the transition. The gap cannot be closed retroactively.
“A human was in the loop” is not the same claim as “a named person with authority reviewed this”.
Every standard guard watches process. None of them ask whether the right question was answered.
“We tested it and it works” is the weakest sentence in a vendor conversation. What a test set has to contain before green means anything.
The exit clause describes what you are owed. The export determines what you actually have.
The series compressed into seven questions, each with a good, weak and failing answer — and our own scores, including the three we fail.
We build the control layer this series describes for authorised firms operating under MiCA, DORA and the EU AI Act — per-request audit trails, approval records, exit readiness. Fifteen minutes on your architecture, no deck.
Book an architecture review Or read how AI Control works →