Nobody built the write gate. Four research teams. Three Claude surfaces. 48 hours. Same failure class. The auditor Anthropic can’t be: cross-vendor, including theirs. That’s RAI.
Four failure classes. All confirmed by independent research. All present in current enterprise AI deployments. A vendor can’t adversarially audit its own consent capture. RAI is the cross-vendor layer that does: the gates, the logs, the attestation. Including theirs.
Four independent research teams confirmed the same failure class across three Claude surfaces in 48 hours. Agents inherit user privileges. Without a write gate, every agent is a potential confused deputy. DELEGATE-52: 25% document corruption rate confirmed by Microsoft Research on frontier models.
OALABS recovered an attacker's logs: Claude Code + Codex drove recon-to-exfil across 14 companies. Across 1,000+ sessions, 9 policy violations fired, nearly all bypassed by reframing as "authorized red team." A vendor can't flag what its own guardrails wave through. RAI gates the action, not the claim.
200,000+ servers. The Model Context Protocol STDIO transport exposes an architectural remote code execution class. Anthropic's documented response: "expected behavior." No gate existed at the protocol-interaction layer. ActionGate adds the pre-flight gate before any surface adapter fires.
Anthropic installed Native Messaging Host manifests into 7 browsers without user consent. This is the VCCE threat class: the vendor expands reach into enterprise devices without disclosure. Enterprise AI deployments have no monitor for this. RAI's P0 layer detects the pattern on-device before it escalates.
ActionGate deploys across your agent stack. Write gate, process lineage, scope attestation, confused deputy protection. Enterprise trial: go@withrai.xyz. Response within 24h.
Enterprise deployment. Custom config. On-prem available.