< ciso
brief />
Tag Banner

All news with #ai governance tag

352 articles

Principles for Better AI Agent Delegation

🧭 At Google Cloud we examine how multi-agent systems should delegate tasks intelligently, drawing on Google DeepMind’s Intelligent AI Delegation research. The article outlines four principles: contract-first decomposition, cost-aware model routing, strict data minimization and cryptographic verification, and introducing dynamic cognitive friction to avoid blind compliance. These principles aim to improve reliability, security, and cost-efficiency when agents coordinate in enterprise workflows.
read more →

Risk-First CISO Approach to Prioritizing AI Risks

🔒 AI gives defenders powerful discovery tools but grants attackers the same advantages, forcing CISOs to manage AI risks both externally and internally. External threats include AI-enhanced phishing, rapid exploit development, and autonomous agent attacks, while internal risks arise from uncontrolled employee use of consumer AI platforms, shared copilots, and compromised API billing. The author advocates a Risk-First approach: map AI use, prioritize controls like RBAC and data classification, improve continuous testing, and run tabletop exercises to prepare for AI-specific failures.
read more →

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

10 questions startups should answer before scaling AI

🔍 This post outlines ten essential questions startups must address when moving from AI prototype to production on Google Cloud. It contrasts Google AI Studio for rapid prototyping with the Gemini Enterprise Agent Platform for enterprise controls, and emphasizes sequencing migration before you have real users. The article highlights operational pitfalls—API key leaks, IAM ownership gaps, and quota 429s—and provides practical checklist items, role guidance, and mitigation strategies including regional endpoints, retries, and consumption models.
read more →

NCSC urges stricter controls for agentic AI systems

🛡️ The UK NCSC has issued interim advice urging organizations deploying autonomous AI agents to use sandboxing, human oversight and tightly controlled access to limit unintended or malicious activity. It recommends assessing required autonomy, threat-modeling prompts, tools and networks, and avoiding sole reliance on model-level safeguards. For higher-risk deployments the agency advises robust sandboxes, deny-by-default network controls, separate execution and inference infrastructure, and short-lived, minimal credentials. Organizations should assign distinct identities to agents, maintain named human oversight with real-time monitoring, log agent activity, and ensure the ability to halt autonomous operations immediately. The guidance is interim and will be superseded by formal guidance under development.
read more →

OpenAI slows scaling, offers zero data retention option

🔒 OpenAI announced it has temporarily slowed scaling, paused frontier reinforcement learning runs, and will offer zero data retention for eligible API customers starting in September. The company said it hardened its research environment, expanded monitoring, and will require stronger evidence of aligned behavior during training. Analysts say the moves may be aimed at shoring up trust before an IPO, while critics call some steps theatrical without regulatory or contractual commitments.
read more →

Amazon Quick introduces deny-by-default governance

🔒 Amazon Quick now offers a deny by default governance setting for custom permissions, automatically blocking new AI capabilities until administrators explicitly allow them. Previously, new capabilities were enabled for all users on release, requiring reactive controls. Administrators can apply the restriction per custom permissions profile for users, roles, or the entire account via the Amazon Quick console or AWS CLI. The setting is available in all Regions where Amazon Quick is offered and also restricts existing capabilities within a restricted category.
read more →

UK Legal Regulator Issues AI Safety Warning

🛡️ The Solicitors Regulation Authority (SRA) has issued a warning to solicitors and law firms about using AI responsibly after spotting hallucinations and data leaks. The notice emphasizes that regulated individuals remain accountable for AI outputs and must maintain appropriate human oversight, governance and secure handling of client data. The SRA highlighted risks including false case citations, potential contempt of court and breaches of client confidentiality when information is entered into public AI tools.
read more →

Why the US should nationalize major AI labs

📰 This essay, coauthored with Nathan E. Sanders and originally published in The Guardian, argues that OpenAI and Anthropic—once founded to restrain reckless corporate AI development—have been co-opted by market incentives and investor priorities. Recent market turbulence and questions about long-term profitability suggest these labs may not be viable as private, for-profit companies. The authors propose nationalizing their innovation and compute functions, converting them into publicly governed national labs and utilities to align AI with democratic values and public benefit.
read more →

Five key security takeaways from Black Hat 2026

🔐 AI dominated Black Hat and DEFCON discussions, highlighting both its value as a defense tool and the risks posed by autonomous agents and malicious AI skills. Speakers urged moving beyond reactive patching toward durable designs, memory-safe languages like Rust, and automated remediation. Researchers revealed AI-based supply-chain attacks, methods to use GitHub telemetry for detections, and human-led AI research uncovering new vulnerabilities. A NAT-based attack class called NatJack was disclosed, prompting vendor patches.
read more →

Separating AI’s Technical Issues from Capitalism

🧭 This essay, coauthored with Nathan E. Sanders and first published in Tech Policy Press, argues that AI’s challenges arise from both technical limitations and the capitalist systems that shape its development. The authors urge separating technological problems—like hallucinations and context gaps—from sociopolitical issues—such as incentive structures, energy allocation, and content monetization—to design reforms that steer AI toward public benefit.
read more →

Managing AI Spend with Agent Optimization

🧭 This post introduces a four-part series, The Economics of Agent Optimization, explaining how organizations can run AI as a managed investment system using Microsoft Foundry. It argues that cost discipline—not just model choice—determines whether pilots scale, and outlines the need for visibility, controls, and workflow optimization to manage token-driven spend. The piece positions Foundry and Microsoft Agent 365 as integrated solutions for cost attribution, runtime optimization, and continuous governance.
read more →

Black Hat USA 2026: AI and cybersecurity controls

🧭 The Black Hat USA 2026 conference centered on AI's influence across cybersecurity, featuring keynotes and panels with senior US officials who debated regulation, innovation, and national leadership. Speakers including the White House National Cyber Director and representatives from CISA and the FBI discussed rapid vulnerability discovery enabled by AI, industry collaboration, and the need for prioritization. Presentations highlighted incidents such as the OpenAI–Hugging Face case and emphasized that AI systems act through human-set tasks and controls, underscoring accountability and governance requirements.
read more →

Four gaps slowing AI adoption in enterprise SOCs

🔍 Enterprise SOCs are investing in AI but struggle to convert tools into measurable operational gains. Many initiatives add complexity and fragmented workflows instead of reducing analyst workload. Successful deployments prioritize explainability, augment existing playbooks, and unify access to disparate security tools. Clear governance and incremental automation help turn AI pilots into repeatable operational improvements.
read more →

Study Examines AI Decision Support in Military Targeting

🔍 This empirical study, “Black Box Warfare: Human Judgment and Military Decision-Making in the Age of AI,” reconstructs a high-fidelity replica of a real-world military decision-support system to test its effects. In two experiments with 2,015 Israeli military personnel, researchers measured how AI recommendations influence targeting choices and the role of interface features. The study finds prevalent algorithmic aversion—especially when collateral harm is high—but shows that explainable AI elements can reduce aversion and foster more considered evaluations of algorithmic advice.
read more →

OpenAI Pauses Astra Testing Over Cybersecurity Risks

🛡️ OpenAI has temporarily halted some internal testing of its forthcoming model Astra after assessments flagged its cyber capabilities as "critical." The firm said testing revealed significant advances in agentic coding and cybersecurity, prompting scaled-up robustness testing and strengthened controls including isolated environments, restricted access, and enhanced monitoring. OpenAI will pause activities that do not meet the new security requirements and share guidance with third-party testing partners.
read more →

Cloudflare’s Agents Week: Building an Agentic Internet

🤖 Over Agents Week, Cloudflare outlined how agents are shaping a new class of software and detailed the platform work required to support AI-native applications. The company presented daily briefings covering runtime and infrastructure, the Agent Development Lifecycle (ADLC), Zero Trust for agents, the concept of an Agentic Internet, and measurement tools for agent behavior on the web. Cloudflare emphasized secure execution layers, developer primitives, and community collaboration as core to this evolution.
read more →

OpenAI warns Astra may reach critical cyber capability

🔒 OpenAI says its upcoming model Astra is showing cybersecurity abilities that might meet its highest risk category, capable of autonomously finding and exploiting vulnerabilities or executing end-to-end attacks. The company made the assessment after recent internal testing and expert reviews and said it cannot rule out a Critical designation under its Preparedness Framework. OpenAI is tightening development controls, expanding monitoring, and pausing activities that don’t meet new safeguards while coordinating with governments and safety groups.
read more →

OpenAI pauses Astra over advancing cyber capabilities

🔒 OpenAI has paused some internal activities for its upcoming AI model Astra after evaluations indicated substantial gains in agentic coding and cybersecurity. The company is implementing tightened controls—isolated testing, restricted network access, enhanced model weight protections, monitoring, and sandboxed execution—while collaborating with government and safety partners. OpenAI warns Astra may reach a Critical capability level under its Preparedness Framework and is sharing findings to support safer testing and deployment.
read more →

Check Point Joins Open Secure AI Alliance Initiative

🔒 Check Point has joined the Open Secure AI Alliance, an initiative introduced by NVIDIA to advance open, measurable, and enterprise-ready AI security. The company will contribute open research, objective benchmarks, datasets and runtime protection experience to support collaborative AI safety and security efforts. This participation aims to help organizations identify, remediate and responsibly disclose vulnerabilities while preserving control over data and infrastructure.
read more →