Open standard We steward AgentHook, the open runtime evidence standard for AI agents.
Read the spec →
Agentic Thinking Limited
⚠ Regulated AI needs runtime evidence · EU AI Act, ISO 42001, SOC 2, DORA, NIS2

Runtime governance for AI agents and coding assistants in regulated enterprises.

We steward AgentHook, the open runtime evidence standard for AI agents. We build HookBus, the open-source reference bus that implements it. HookBus Enterprise packages the compliance subscriber bundle, dashboard, and support regulated enterprises need as AI governance obligations harden.

Built for organisations with a CISO, a DPO, and regulators watching. Financial services. Insurance. Healthcare. Defence. Public sector. Internal IT departments where Claude Code, Cursor, Amp, and Copilot already touch regulated codebases. Anywhere agents or assistants now hold the keys.

The Agent in the Loop.

When there is no human watching, CRE is the Agent in the Loop. It governs every action your agents take. Only when absolutely necessary does it escalate to a human with Ask.

Deny

L1 deterministic rules catch known-bad actions before they run. Malicious shell commands, unauthorised data access, policy violations — blocked in sub-10ms. No LLM required.

Approve

L2 semantic review clears borderline actions that pass L1 but need intent verification. Safe actions proceed without human delay. The agent keeps working.

Ask

When L2 is uncertain, HookBus Workflow pauses the agent and notifies the human — via CLI prompt, email, or Slack. The human approves or denies. The agent resumes. Human back in the loop, only when needed.

Self-learning: every L2 decision and human override feeds back into L1 patterns. The agent gets smarter at governing itself.

Watch CRE block a dangerous action.

A Claude Code agent calls a destructive shell command. CRE-AgentProtect runs through L1 deterministic rules and L2 semantic review, returns deny, and the action is stopped before it reaches production. One minute, start to finish.

CRE FLOW · CLICK TO PLAY WITH SOUND

Agents and coding assistants are drifting in production.

AI agents run tool calls, write to production, handle customer data. Your developers have Claude Code, Cursor, Amp, and Copilot against regulated codebases. Your IT team runs coding assistants with access to secrets and infrastructure. They forget the rules. They skip policy. They act without review. Auditors and regulators now want the logs your stack is not producing. If you provide high-risk AI systems, your Article 12 event-logging obligation takes effect 2 August 2026.

Article 12
EU AI Act record-keeping obligations
In force 2 Aug 2026
SOC 2
Auditable agent decision trail required
Enterprise procurement gate
ISO 42001
AI management system standard
Published December 2023

One platform. Two editions.

HookBus is the agent event bus that captures lifecycle evidence from AI agents and coding assistants in your stack. The free edition ships with production-ready policy and spend-tracking subscribers. HookBus Enterprise adds the compliance subscriber bundle, dashboard, and support for regulated deployments.

Free · Apache 2.0

HookBus

The agent event bus.

Self-host the bus and get two production subscribers out of the box. Build your own subscribers for governance, audit, cost tracking, memory, DLP, or anything else you need. Vendor-neutral: works with Claude Code, Cursor, Amp, GitHub Copilot, Hermes, OpenClaw, Codex, Anthropic Agent SDK, OpenAI Agents SDK, and any HTTP-capable runtime.

  • CRE-AgentProtect: Our governance engine. L1 deterministic policy gate backed by Microsoft Agent Governance Toolkit (AGT). Blocks dangerous actions before they run.
  • AgentSpend: Track token usage and spend across every agent runtime in one place.
  • Build custom subscribers in any language. Open protocol, versioned, documented.
Commercial

HookBus Enterprise

The compliance subscriber bundle for regulated enterprises.

Everything in HookBus, plus the Enterprise dashboard, advanced subscribers, commercial-use licence, SLA, support, and regulatory update packs. Built to produce runtime evidence for regulated AI deployments. On-premise, VPC, or air-gap deployment.

  • CRE-AgentProtect Enterprise: Policy gate for agent actions. L1 deterministic controls block known-bad actions before execution. L2 semantic intent verification reviews borderline cases using your approved inference path, including local Granite, Azure, Bedrock, or other LiteLLM-compatible providers.
  • Human approval workflow: When the decision is Ask, HookBus Workflow pauses the action, notifies the right human through CLI, email, or Slack, and records the approval or denial as runtime evidence.
  • Compliance subscriber bundle: Auditor, DLP Filter, KB Injector, Session Memory, Workflow, Compliance Notifier, and enterprise policy packs.
  • Enterprise dashboard: Real-time bus monitoring, subscriber health, policy management, audit exports, and role-based access.
  • Commercial licence, SLA support, implementation support, and regulatory update packs as EU AI Act, DORA, NIS2, and customer obligations evolve.

Who this is for.

Agentic Thinking speaks to the people responsible for the agent-in-production problem. Every block below maps to a real deliverable in the product, not a marketing line.

CISO

Know every action every agent takes.

Hash-chained audit trail across every agent runtime. Evidence your incident response team can actually subpoena.

DPO

Stop PII leaving the agent boundary.

DLP Filter subscriber redacts secrets and regulated data at envelope entry. GDPR / HIPAA / PCI scopes configurable.

Head of AI Governance

One governance layer across every LLM vendor.

Rules written once, enforced across Claude, GPT, Gemini, open-weights. Vendor portability built in.

Internal Audit

Evidence on demand.

Every decision, every override, every deny-wins consolidation, timestamped and exportable for the auditor.

Compliance

Map policy to the enforcement layer.

Regulation language translates to deterministic rules. L1 blocks before the tool call, no LLM discretion.

Finance

Agents at predictable cost.

AgentSpend tracks token usage per team, per agent, per session. Budget limits enforceable at the bus layer.

Bring your own LLM.

HookBus sits at the hook layer, not the inference layer. Governance runs at the bus; your models keep running wherever your enterprise has already standardised.

Private cloud

AWS Bedrock, Azure OpenAI, Google Vertex AI, IBM watsonx.ai

Self-hosted

Ollama, vLLM, llama.cpp, NVIDIA NIM

Provider-direct

Anthropic, OpenAI, Google, Mistral, Moonshot

1.
HookBus runs with no LLM in the enforcement path. The free edition uses Microsoft AGT deterministic rules only. No LLM required. Fast, air-gap friendly. HookBus Enterprise adds L2 semantic review when you need it.
2.
Only the governance engine ever calls the LLM. The LLM adapter is a separate, isolated service. Your agents hold no LLM keys, open no outbound HTTPS to a provider. Your compliance team keeps one perimeter, not many.
3.
Every LLM call the governance layer makes is itself audited on the bus. PreLLMCall, PostLLMCall, reasoning content where exposed, model, provider, token counts. Hash-chained and exportable runtime evidence for regulated audit programmes.

Built and tested on IBM Granite 4 3B. HookBus Enterprise was developed end-to-end against Granite 4 3B so the governance layer works at the smallest enterprise-friendly model sizes regulated teams actually want to self-host. HookBus-LLM, powered by LiteLLM, lets you swap in your own model if Granite 4 is not your default.

Publishers emit. The bus routes. Subscribers enforce.

Every AI agent and every coding assistant fires lifecycle events. HookBus captures them and routes to subscribers in parallel. Sync subscribers return verdicts (allow / deny / ask) and context. The publisher injects the consolidated result into the next turn. Deny wins.

Publishers
Claude, Amp, Hermes, OpenClaw, SDKs
HOOKBUS
Agent event bus
Subscribers
Policy engine, Auditor, DLP, KB, Memory

Full protocol specification, install commands, subscriber gallery, and developer documentation at hookbus.com.

The platform in under two minutes.

Publishers. Bus. Subscribers. One bus captures every agent action and routes it to the subscribers that govern, enrich, protect, and audit.

1 min 45 sec · click to play with sound

Open to licensing HookBus Enterprise to AI companies.

If you build an AI runtime, coding assistant, or agent framework and need a governance story your enterprise customers can buy, Agentic Thinking licenses HookBus Enterprise for embedding or resale. White-label, OEM, per-seat, per-deployment models available.

White-label embedding

Your product ships with HookBus Enterprise bundled under your brand. We supply the protocol, the bus, the subscribers, and the policy packs. You supply the distribution.

OEM relicensing

Relicense HookBus Enterprise to your enterprise customers as part of your own paid tier. Revenue share or flat licence. Audit-ready compliance evidence included.

Joint engineering

Co-develop a publisher shim for your runtime. Your events become HookBus events. Enterprise customers who standardise on HookBus get your runtime for free.

Licensing enquiries: partnerships@agenticthinking.uk

Agentic Thinking Limited.

A UK company building the runtime-governance infrastructure regulated enterprises need to adopt AI agents safely. One platform, two editions, patent-pending architecture, pilot-ready.

Founded by Leo Ruocco, with 27 years across UK financial services, insurance, and defence, building the controls layers auditors actually read.

Company
Agentic Thinking Ltd
Patent: HookBus
GB2608069.7
Patent: CRE
GB2604445.3
Trademark
HookBus™

Works with the tools enterprise AI teams already run.

HookBus connects on the ingress side via publisher shims, and on the enforcement side via the policy engine subscriber. Publisher integrations are public and documented under Apache 2.0. Enterprise policy integrations are available in HookBus Enterprise and use each vendor's supported APIs.

Publisher integrations · runtime adapters

Ingress adapters that translate native AI runtime lifecycle events into canonical HookBus envelopes. All public, all Apache 2.0.

Anthropic Claude Code
hook adapter

Publisher shim via the Claude Code native hook API. All four lifecycle events covered.

Sourcegraph Amp
plugin adapter

TypeScript plugin for Amp's lifecycle plugin API. Full five-event coverage.

Nous Research Hermes
plugin adapter

Python plugin for Hermes-agent. Pre-tool-call, post-tool-call, post-API-request hooks.

OpenClaw
extension adapter

Node.js plugin for OpenClaw's extension API.

OpenAI Agents SDK
SDK shim

Wraps HookBusRunHooks(RunHooksBase). Tool start / tool end / LLM end / agent end.

Anthropic Agent SDK
SDK shim

Pre- and post-tool events for the Anthropic Agent SDK.

Enterprise policy stack

The policy engine subscriber consumes HookBus events and enforces decisions. The policy stack uses two industry-standard engines, both running locally inside your network.

Microsoft AGT
L1 deterministic policy

The policy engine uses Microsoft Agent Governance Toolkit as its deterministic pattern engine. Sub-10ms policy decisions.

IBM Granite 4
L2 semantic intent

Granite 4 3B runs locally for semantic intent verification on borderline cases. No cloud LLM calls at decision time.

Designed for organisations whose procurement starts with a questionnaire.

HookBus Enterprise is built for deployments where a CISO signs a DPIA before the tool goes live. Regulated AI programmes increasingly need runtime evidence: prompts, model calls, tool calls, policy decisions, human approvals, denials, and audit trails. HookBus Enterprise is engineered to produce that evidence inside your own environment.

EU AI Act Article 12

Supports your audit-trail obligation

If you are a provider of a high-risk AI system, Article 12 introduces automatic event-logging obligations from 2 August 2026. HookBus helps produce the runtime evidence those programmes need: chained, exportable, and tied to agent actions.

SOC 2

Evidence for Type II audits

Produces the event-level audit trail your SOC 2 Type II assessor expects. Built to slot into your assurance programme.

ISO / IEC 42001

Aligned to AIMS controls

Deployment, operation, incident-response, and review features map to ISO 42001 clauses. Built to support customers running an AI management system.

GDPR · HIPAA · PCI

Boundary-level data protection

DLP Filter redacts API keys, PII, financial identifiers, and infrastructure strings at the envelope. Regulated data never leaves the agent boundary.

No cloud dependencies

On-prem, VPC, air-gap

The policy engine runs locally, CPU-only. No external API calls at decision time. Deploy where your DPIA allows.

Agentic Thinking Limited does not currently hold third-party compliance certifications. The products generate runtime evidence that can support SOC 2, ISO/IEC 42001, EU AI Act, and internal audit programmes, but do not certify compliance on their own. Security posture documentation is available under NDA — see the Trust Center.

On-premise VPC Air-gap No cloud dependency

Book 30 minutes. Walk out knowing whether we fit.

Built for organisations running AI agents in production or coding assistants across internal IT, targeting regulated-industry deployment. Call for details. Not the right price point for a hobby project, exactly the right price point for a bank.