Skip to content
workspaceguardrails
  • Home
  • Open Source[4]
  • System Policies[0]
  • Git Hooks[23]
  • Anti-Patterns[310]
  • Hook Configs[19]
  • Sandbox Configs[27]
  • Tools & Scripts[14]
  • AI Governance[20]
  • LLM Gateway
  • Static Analysis
  • Playground
  • Integration Guide
  1. Home
    The Digital and AI Workspace Guardrails Platform2026 ◆ Independent AI Labs
    Skip to content
    workspaceguardrails
    • Home
    • Open Source[4]
    • System Policies[0]
    • Git Hooks[23]
    • Anti-Patterns[310]
    • Hook Configs[19]
    • Sandbox Configs[27]
    • Tools & Scripts[14]
    • AI Governance[20]
    • LLM Gateway
    • Static Analysis
    • Playground
    • Integration Guide
    1. Home

      What are the Digital and AI Workspace Guardrails?

      A curated collection of free resources and open-source research on the topics of cybersecurity, digital compliance and sovereign technology.

      SAFELY UTILISING LANGUAGE MODELS COMES WITH STRICT AUDITABLITY AND COMPLIANCE REQUIREMENTS.

      Privileged access risks

      Agents inherit the user's shell, tokens, and filesystem. One compromised session becomes a lateral movement ticket across repos, keys, and production paths.

      Browse solutions:

      Harden agent sandboxes
      ProbeProbe

      SAFELY UTILISING LANGUAGE MODELS COMES WITH STRICT AUDITABLITY AND COMPLIANCE REQUIREMENTS.

      Privileged access risks

      Agents inherit the user's shell, tokens, and filesystem. One compromised session becomes a lateral movement ticket across repos, keys, and production paths.

      Browse solutions:

      Harden agent sandboxes

      Vendor lock-in

      Routing, retention, and redaction follow the provider's platform defaults, not your documented policy. When those defaults change in a release, your effective controls change with them.

      Browse solutions:

      Provider-agnostic stack

      Opaque reasoning

      You cannot reconstruct why an agent chose a path after the fact. Opaque chains of tool calls hide privilege escalation, data reads, and exfiltration until the bill arrives.

      Browse solutions:

      Audit runtime actions

      Direct LLM access

      API keys in your toolchain send prompts and full context straight to vendor endpoints with no redaction, no spend guardrails, and no central audit log. Teams route through different providers with no shared policy, so usage and data exposure only show up in invoices and incident reviews.

      Browse solutions:

      Route LLM traffic

      Unbounded agents

      An agent with broad tool access will read secrets, write where it should not, and call outbound endpoints you never approved. Stochastic models do not fail politely; they fail at scale.

      Browse solutions:

      Enforce git hooks

      Extraterritorial inference

      Model weights and inference often run on infrastructure outside your jurisdiction and contractual control. Data passes through subprocessors you never approved, and residency assurances are hard to verify once traffic leaves your network.

      Browse solutions:

      Review AI governance

      Bavaria cancels Microsoft

      The German state of Bavaria replaced Microsoft software with open-source alternatives across public administration, part of a broader EU push for technological sovereignty and independence from US tech giants.

      Resources:

      Download PDFOfficial source

      Austria adopts Nextcloud

      Austria's Federal Ministry of Economics moved from Microsoft 365 to self-hosted Nextcloud on Austrian infrastructure. The Interoperable Europe Act mandates cross-border public-sector interoperability and reuse of open solutions.

      Resources:

      Download PDFOfficial source

      Denmark replaces Office with LibreOffice

      The Danish government is replacing Microsoft Office with LibreOffice to protect privacy and reduce dependence on US-based software. GDPR anchors data protection as a European constitutional priority.

      Resources:

      Download PDFOfficial source

      ICC phases out Microsoft for OpenDesk

      The International Criminal Court in The Hague is switching to the European OpenDesk suite. The Cyber Resilience Act recognises free and open-source software as critical infrastructure with a tailored compliance path.

      Resources:

      Download PDFOfficial source

      Schleswig-Holstein, Linux for 30,000 staff

      Schleswig-Holstein announced migration from Windows to Linux and from Microsoft Office to LibreOffice for ~30,000 employees, one of Europe's largest public-sector FOSS transitions.

      Resources:

      Download PDFOfficial source

      Mecklenburg-Vorpommern, Nextcloud and OpenProject

      Mecklenburg-Vorpommern rolls out Nextcloud and OpenProject for 50,000+ public employees, citing digital sovereignty: "The EU runs on Microsoft. The US could turn us off inside one hour." The Data Act strengthens control over industrial and cloud data on EU terms.

      Resources:

      Download PDFOfficial source

      Federal Source Code Policy

      OMB Memorandum M-16-21 (2016) requires new federal custom code to be shared across agencies and published as open source where appropriate. At least 20% of new custom-developed code must be released as OSS each year, with inventories published on code.gov.

      Resources:

      Download PDFOfficial source

      SHARE IT Act becomes law

      The Source Code Harmonization And Reuse in Information Technology Act (H.R. 9566), signed in December 2024, mandates governmentwide sharing of custom-developed code. Agencies must publish metadata and make code available to other agencies to cut duplicate contracts and vendor lock-in.

      Resources:

      Download PDFOfficial source

      Massachusetts adopts OpenDocument

      Since 2006, Massachusetts has required the OpenDocument standard across state entities, a long-standing policy ensuring public records stay accessible without dependence on a single proprietary office format.

      Resources:

      Download PDFOfficial source

      Software licensing reform

      OMB M-16-12 directs agencies to manage commercial software licenses as a portfolio: eliminate duplication, use category-management vehicles, and prefer existing federal solutions before buying or building anew.

      Resources:

      Download PDFOfficial source

      White House open government

      The 2009 Open Government Directive required agencies to publish data and embrace transparency. The White House itself migrated to Linux servers and Drupal, an early signal that federal IT could run on open platforms, not only proprietary stacks.

      Resources:

      Download PDFOfficial source

      States share software costs

      U.S. open-government policy emphasizes efficiency and innovation, not geopolitical decoupling. States jointly procure through collaboratives like the Intergovernmental Software Collaborative; Orange County, California completed an open-source migration; Oregon proposed default-to-open procurement legislation.

      Resources:

      Download PDFOfficial source
      The Digital and AI Workspace Guardrails Platform2026 ◆ Independent AI Labs