57% of employees use AI without formal approval. Learn what to do in this practitioner's guide
August 18, 2026
Three agents with modest permissions can compose an action nobody authorized. Governing a chain differs from governing an agent.
No EU AI Act standard has been cited yet, and ISO 42001 was not adopted for the purpose. What Article 17 requires while you wait.
August 17, 2026
Fourth-party dependencies invalidate simple diversification. The four types of concentration, and what to do when switching is not possible.
Human identity governance works because HR emits events. Agent identities emit none. How to manufacture the missing lifecycle.
An AI assessment starts expiring immediately, because the system changes without you touching it. The three mechanisms behind that.
August 16, 2026
Investment framing asks whether a control is worth fixing. Accrual framing asks what the delay costs, and reorders the queue.
OpenTelemetry now gives AI interactions a standard shape. What its conventions record, and where judgment has to be added on top.
August 15, 2026
A median is not a forecast, better security can mean higher exposure, and aggregate is less than the sum of the scenarios.
A dashboard stores the latest value. An audit asks about a date. The trail properties governance tools most often underdeliver on.
August 14, 2026
Silent AI ended in January 2026. Where an AI incident lands across policies, and why sublimits matter more than exclusions.
Three organizations were compromised during AI evaluations and none noticed. What the disclosures show about enforcing agent scope.
August 13, 2026
Valid account abuse carries roughly a quarter of modeled loss and phishing sits sixth. What that says about where controls belong.
Two stages, predictable evidence requests, and findings that cluster tightly. What an AI audit examines and where points get lost.
Twelve AI governance platforms compared side by side. Analyst positions, runtime enforcement, deployment, and buyer fit for 2026.
August 12, 2026
Security budget cases fail on arithmetic rather than argument. The calculation, the inputs that make it defensible, and its limits.
AI-SPM inherited cloud assumptions that hold for infrastructure and fail for a browser tab. What the term covers, and what it does not.
Revised model risk guidance excludes generative and agentic AI while leaving accountability in place. What defensible governance requires.
August 11, 2026
DORA gives four hours for an initial notification. Why overlapping reporting clocks break annual-cycle GRC, and what closes the difference.
Oversight failure is personally actionable for directors. What belongs in an AI board pack, what to cut, and the cadence that holds up.
One is a certifiable management system, the other an operational risk playbook. How to choose, and why most enterprises run both.
August 10, 2026
DORA moved concentration assessment before the contract. Why criticality tiering misranks vendors and what to do when one fails.
Authentication secures the login and goes blind afterward. What identity-based browser controls require, and where the approach breaks down.
Discovery answers a question once. Monitoring keeps the answer true as tools appear, vendors ship AI features, and agents change access.
August 9, 2026
Most appetite statements cannot be violated by any real event. The four terms, testable thresholds, and the breach procedure.
One paste into a consumer assistant, traced end to end. What leaves, why nothing fires, and the six places it could have stopped.
August 8, 2026
An annual assessment evidences one day out of 365. Which controls close that interval, and which stay manual regardless of tooling.
The Digital Omnibus moved high-risk obligations to December 2027 & left Article 50 transparency live on August 2, 2026. Here's the sequence.
August 7, 2026
Three frameworks, one security program. Which crosswalks already exist, how to pick a spine, and where mapping genuinely breaks.
When an autonomous AI agent makes a wrong call, accountability fractures across deployer, developer, and human operator.
August 6, 2026
Prioritize cyber risks with quantified financial exposure, residual risk ranking, and the mitigate-transfer-avoid-accept response framework.