From the airlock team.
Walkthroughs, deep-dives, and product updates. More articles on the way.

MCP goes stateless on July 28. Your existing connections don't have to wait.
The biggest MCP spec revision since launch finalizes July 28, 2026: no more sessions, a new server/discover handshake, hardened OAuth, and a first-class extensions framework. airlock's org-wide endpoint already speaks it — so every MCP server you've already connected inherits it on day one.
Read article →
The future of AI security is more than another PDF
AI security climbs four levels: no controls, policy, traceability, gatekeeping. Aikido's 2026 data shows most companies sit at the start of level 2, on native per-vendor logs, thinking they are done. What a system of record for AI activity adds.
Read article →
Shadow AI is not your employees' fault. You have not written the rules. (free AI policy generator inside)
Shadow AI is not shadow IT. Tools rotate every quarter, share nothing with each other, and act on your systems. Why the employer is accountable, and a free generator for the seven-clause AI Acceptable Use Policy you can ship this week.
Read article →Skills and agents are infrastructure: the two-audience problem
Builders need versioned infrastructure. Users need it to just work in their AI tool. Most teams in 2026 solve neither side. A map of the gap and a three-month plan to close both.
Read article →
8 minA quick tour of airlock
An 8-minute walkthrough of the Control Room: connect an integration, set read-only and approval policy, then watch the same rules hold across Claude, ChatGPT, Cursor and VS Code.
Watch the tour →
MCP governance: what it is and how to do it right
MCP governance decides which servers AI agents can use, what they can do, and what gets logged. The risks, the frameworks worth aligning to, and a practical checklist.
Read article →