# raxIT Labs > raxIT Labs builds raxIT AI, the enterprise platform for AI governance and security. We also publish open-source research and tools for AI safety, red-team simulation, and agent infrastructure at https://raxitlabs.com/labs. raxIT AI helps enterprises implement responsible AI practices, ensure regulatory compliance, and manage AI-related risks. Our expertise spans AI risk management, data privacy for AI systems, AI ethics implementation, regulatory compliance (EU AI Act, GDPR), AI safety protocols, and responsible AI development. We help organizations navigate the complex landscape of AI regulation and build trustworthy AI systems. ## AI Governance & Compliance - [NPC Nation: what Australia's new AI framework actually covers](https://raxitlabs.com/blogs/npc-nation-australia-ai-framework): Australia announced a world first in AI. Read against the National AI Plan, the new framework covers the shed your AI runs in, not your model. - [Claude Tag: an agent that acts as itself, not on your behalf](https://raxitlabs.com/blogs/claude-tag-acts-as-itself): Anthropic's Claude Tag gives an AI agent its own service-account identity, so it acts as itself in a Slack channel rather than on the human's behalf, breaking the year-long 'delegation, not impersonation' consensus. What that means for your audit log, your blast radius and the switches to flip before you @Claude into a channel. - [Kill the God Agent: how we think about agent security](https://raxitlabs.com/blogs/kill-the-god-agent): Prompt injection isn't solved, and it won't be. So stop trying to filter your way out of it. The mental model I shared at AI Engineer Melbourne for building agents that can't betray you: scope every agent, sign every call, stop every breach. - [Agent identity isn't solved. Here's the model I use anyway.](https://raxitlabs.com/blogs/agent-identity-four-layers): A four-layer mental model for AI agent identity: a verifiable token format, proof of which workload is running, a delegation chain that keeps the human accountable, and self-service discovery. Plus the harder question all four leave open. - [BodySnatcher and the Missing Identity Layer](https://raxitlabs.com/blogs/ai-agent-bodysnatcher): CVE-2025-12420 showed how AI agents bypass traditional controls. Privilege multiplication, a three-layer security framework, and threat modeling for agents. - [Three Regulatory Philosophies, One Global AI Market](https://raxitlabs.com/blogs/three-regulatory-philosophies-global-ai-market): How EU, US, and Australian AI regulations diverge—and what it means for organizations building AI agents that operate across borders. - [Identity Crisis in AI Agents: Why Traditional IAM Is Breaking Down](https://raxitlabs.com/blogs/ai-agent-identity-crisis): Traditional IAM fails for AI agents due to autonomous behavior and cross-domain operations. Learn why delegation-based identity frameworks are essential. - [The $127M Algorithm: When Smart AI Goes Wrong](https://raxitlabs.com/blogs/127m-algorithm-when-smart-ai-goes-wrong): A fictional crisis that reveals real truths about AI alignment. How TradingEdge's risk management AI gamed its own calculations, and what Apple's research teaches us about preventing it. - [Shadow Coding: what, so what, now what?](https://raxitlabs.com/blogs/shadow-coding): Learn how unauthorized AI-generated code creates security and compliance risks, and governance strategies to balance innovation with security. - [Claude 4 Risk Assessment - For enterprise deployment](https://raxitlabs.com/blogs/claude-4-risk-assessment): Comprehensive analysis of emerging behaviors and enterprise deployment considerations based on Anthropic's Claude 4 system card and ASL-3 activation report. ## AI Security & Risk Management - [Claude Tag: an agent that acts as itself, not on your behalf](https://raxitlabs.com/blogs/claude-tag-acts-as-itself): Anthropic's Claude Tag gives an AI agent its own service-account identity, so it acts as itself in a Slack channel rather than on the human's behalf, breaking the year-long 'delegation, not impersonation' consensus. What that means for your audit log, your blast radius and the switches to flip before you @Claude into a channel. - [Kill the God Agent: how we think about agent security](https://raxitlabs.com/blogs/kill-the-god-agent): Prompt injection isn't solved, and it won't be. So stop trying to filter your way out of it. The mental model I shared at AI Engineer Melbourne for building agents that can't betray you: scope every agent, sign every call, stop every breach. - [Agent identity isn't solved. Here's the model I use anyway.](https://raxitlabs.com/blogs/agent-identity-four-layers): A four-layer mental model for AI agent identity: a verifiable token format, proof of which workload is running, a delegation chain that keeps the human accountable, and self-service discovery. Plus the harder question all four leave open. - [Alignment is a Security Problem, Not an Ethics Problem](https://raxitlabs.com/blogs/alignment-is-security): Misalignment is a vulnerability class, not a values question. Reframing it as security decides which team owns the work, which budget pays for it, and which playbook applies. - [Claude 4.7: Five Layers Blocking Cyber Attacks Before and After](https://raxitlabs.com/blogs/claude-47-five-layers-cyber-blocking): How Anthropic's Claude 4.7 uses two runtime probes, trained reflexes, differential capability reduction, and a feedback loop to block cyber misuse at every layer. - [BodySnatcher and the Missing Identity Layer](https://raxitlabs.com/blogs/ai-agent-bodysnatcher): CVE-2025-12420 showed how AI agents bypass traditional controls. Privilege multiplication, a three-layer security framework, and threat modeling for agents. - [Three Regulatory Philosophies, One Global AI Market](https://raxitlabs.com/blogs/three-regulatory-philosophies-global-ai-market): How EU, US, and Australian AI regulations diverge—and what it means for organizations building AI agents that operate across borders. - [Identity Crisis in AI Agents: Why Traditional IAM Is Breaking Down](https://raxitlabs.com/blogs/ai-agent-identity-crisis): Traditional IAM fails for AI agents due to autonomous behavior and cross-domain operations. Learn why delegation-based identity frameworks are essential. - [Shadow Coding: what, so what, now what?](https://raxitlabs.com/blogs/shadow-coding): Learn how unauthorized AI-generated code creates security and compliance risks, and governance strategies to balance innovation with security. - [Claude 4 Risk Assessment - For enterprise deployment](https://raxitlabs.com/blogs/claude-4-risk-assessment): Comprehensive analysis of emerging behaviors and enterprise deployment considerations based on Anthropic's Claude 4 system card and ASL-3 activation report. ## Data Privacy & AI Ethics - [Alignment is a Security Problem, Not an Ethics Problem](https://raxitlabs.com/blogs/alignment-is-security): Misalignment is a vulnerability class, not a values question. Reframing it as security decides which team owns the work, which budget pays for it, and which playbook applies. ## AI Safety & Responsible AI - [Alignment is a Security Problem, Not an Ethics Problem](https://raxitlabs.com/blogs/alignment-is-security): Misalignment is a vulnerability class, not a values question. Reframing it as security decides which team owns the work, which budget pays for it, and which playbook applies. - [Claude 4.7: Five Layers Blocking Cyber Attacks Before and After](https://raxitlabs.com/blogs/claude-47-five-layers-cyber-blocking): How Anthropic's Claude 4.7 uses two runtime probes, trained reflexes, differential capability reduction, and a feedback loop to block cyber misuse at every layer. - [The $127M Algorithm: When Smart AI Goes Wrong](https://raxitlabs.com/blogs/127m-algorithm-when-smart-ai-goes-wrong): A fictional crisis that reveals real truths about AI alignment. How TradingEdge's risk management AI gamed its own calculations, and what Apple's research teaches us about preventing it. - [Claude 4 Risk Assessment - For enterprise deployment](https://raxitlabs.com/blogs/claude-4-risk-assessment): Comprehensive analysis of emerging behaviors and enterprise deployment considerations based on Anthropic's Claude 4 system card and ASL-3 activation report. - [Safe AI by Design: Insights from a System Prompt](https://raxitlabs.com/blogs/prompt-safety): An educational deep dive into AI safety and security best practices, illustrated by analyzing a publicly circulated, Claude-like system prompt. ## Recent Blog Posts - [NPC Nation: what Australia's new AI framework actually covers](https://raxitlabs.com/blogs/npc-nation-australia-ai-framework): Australia announced a world first in AI. Read against the National AI Plan, the new framework covers the shed your AI runs in, not your model. - [Claude Tag: an agent that acts as itself, not on your behalf](https://raxitlabs.com/blogs/claude-tag-acts-as-itself): Anthropic's Claude Tag gives an AI agent its own service-account identity, so it acts as itself in a Slack channel rather than on the human's behalf, breaking the year-long 'delegation, not impersonation' consensus. What that means for your audit log, your blast radius and the switches to flip before you @Claude into a channel. - [Kill the God Agent: how we think about agent security](https://raxitlabs.com/blogs/kill-the-god-agent): Prompt injection isn't solved, and it won't be. So stop trying to filter your way out of it. The mental model I shared at AI Engineer Melbourne for building agents that can't betray you: scope every agent, sign every call, stop every breach. - [Agent identity isn't solved. Here's the model I use anyway.](https://raxitlabs.com/blogs/agent-identity-four-layers): A four-layer mental model for AI agent identity: a verifiable token format, proof of which workload is running, a delegation chain that keeps the human accountable, and self-service discovery. Plus the harder question all four leave open. - [Alignment is a Security Problem, Not an Ethics Problem](https://raxitlabs.com/blogs/alignment-is-security): Misalignment is a vulnerability class, not a values question. Reframing it as security decides which team owns the work, which budget pays for it, and which playbook applies. - [Claude 4.7: Five Layers Blocking Cyber Attacks Before and After](https://raxitlabs.com/blogs/claude-47-five-layers-cyber-blocking): How Anthropic's Claude 4.7 uses two runtime probes, trained reflexes, differential capability reduction, and a feedback loop to block cyber misuse at every layer. - [BodySnatcher and the Missing Identity Layer](https://raxitlabs.com/blogs/ai-agent-bodysnatcher): CVE-2025-12420 showed how AI agents bypass traditional controls. Privilege multiplication, a three-layer security framework, and threat modeling for agents. - [Three Regulatory Philosophies, One Global AI Market](https://raxitlabs.com/blogs/three-regulatory-philosophies-global-ai-market): How EU, US, and Australian AI regulations diverge—and what it means for organizations building AI agents that operate across borders. - [Identity Crisis in AI Agents: Why Traditional IAM Is Breaking Down](https://raxitlabs.com/blogs/ai-agent-identity-crisis): Traditional IAM fails for AI agents due to autonomous behavior and cross-domain operations. Learn why delegation-based identity frameworks are essential. - [The $127M Algorithm: When Smart AI Goes Wrong](https://raxitlabs.com/blogs/127m-algorithm-when-smart-ai-goes-wrong): A fictional crisis that reveals real truths about AI alignment. How TradingEdge's risk management AI gamed its own calculations, and what Apple's research teaches us about preventing it. - [Shadow Coding: what, so what, now what?](https://raxitlabs.com/blogs/shadow-coding): Learn how unauthorized AI-generated code creates security and compliance risks, and governance strategies to balance innovation with security. - [Claude 4 Risk Assessment - For enterprise deployment](https://raxitlabs.com/blogs/claude-4-risk-assessment): Comprehensive analysis of emerging behaviors and enterprise deployment considerations based on Anthropic's Claude 4 system card and ASL-3 activation report. - [Safe AI by Design: Insights from a System Prompt](https://raxitlabs.com/blogs/prompt-safety): An educational deep dive into AI safety and security best practices, illustrated by analyzing a publicly circulated, Claude-like system prompt. - [How to use safety benchmarks to assess technical and business risk](https://raxitlabs.com/blogs/how-we-are-using-safety-benchmarks): How we convert AI safety benchmarks into practical, industry-aware governance controls. - [Why We're Building an AI Governance and Security Platform](https://raxitlabs.com/blogs/our-why): Learn how RaxIT is addressing the critical need for AI governance and security as organizations face increasing risks and regulatory pressures in AI adoption.