< ciso
brief />
Tag Banner

All news with #ai governance tag

403 articles

AI-driven infrastructure across lifecycle stages

🤖 Microsoft describes how AI is being applied across the full hardware lifecycle—from design and supply chain to deployment and fleet operations—to accelerate learning and improve decision making. The company emphasizes a “Lean before AI” approach that simplifies processes, builds a governed data foundation, and preserves human judgment. Early results include dramatic reductions in planning cycle time, decreased manual effort, and fewer VM interruptions from disk failures.
read more →

Anthropic expands tiered AI access for vetted security teams

🛡️ Anthropic has expanded its Cyber Verification Program to give vetted security teams tiered access to advanced AI models with reduced safeguards. The program now includes Defense, Red Team, and Specialized Access tiers for progressively broader cybersecurity testing and defensive work. Anthropic tested tiers using CyScenarioBench and says results demonstrate why authorization, scope, and external controls matter.
read more →

Five-Year CISO Trends Shift Security to Workflows

🛡️ The 2026 Voice of the CISO report reveals a multi-year shift: resilience, AI governance, human risk, and board scrutiny are converging where work actually happens. While some metrics improved year-over-year, longer-term trends show fluctuating attack expectations, persistent human risk, and AI evolving from experiment to mandate. CISOs face resource gaps as governance demands outpace budgets and expertise.
read more →

Pacing the AI frontier won’t fix agentic risks

🔐 The article examines calls by Anthropic CEO Dario Amodei and other tech leaders to slow development of frontier AI, weighing sensational extinction scenarios against practical cybersecurity concerns. It highlights resignations from researchers and political pushback while arguing that the real danger is rushed deployment of untested agentic systems into production. The piece urges measured oversight, rigorous testing, and clear responsibility for infrastructure and security providers.
read more →

Anthropic prompts Claude users to share voice data

🎙️ Anthropic now prompts Claude voice users to voluntarily allow their audio recordings and voice chat data to be used to improve its AI models. The prompt appears when using voice features and the option is off by default, with a dedicated toggle in Settings > Privacy. Voice training is handled separately from chat and code training, and users can toggle permission or delete stored voice data at any time.
read more →

Google Gemini may gain broad macOS access soon

🛡️ Google is testing a hidden "Additional sandbox options" in the Gemini Desktop app that could let Gemini read, create, modify, or delete files anywhere on a Mac and interact with native apps and the web. The feature is not live and unconfirmed by Google, but the hidden interface warns that enabling it may allow Gemini to act without asking permission for some actions. Sensitive operations like purchases or account creation would still require explicit confirmation.
read more →

Google launches Gemini 4 Argon with limited access

🟦 Google has introduced Gemini 4 Argon, a frontier AI model aimed at complex, long-horizon tasks across software engineering, legal and financial analysis, and cybersecurity. Access is restricted to a set of trusted cyber defenders via the Fairwind Program to allow safety testing under a US voluntary early-access process. Argon increases token capacity to support 1 million-token outputs and is being priced at an introductory rate of $2/$10 per million tokens for input/output, rising later to $4/$20.
read more →

Sovereign AI Choice: One Year Later

🎉 Cloudflare announces two public models—EuroLLM and Apertus—now available via Workers AI, plus hands-on workshops to help government cyber agencies build model-agnostic AI defenses. EuroLLM covers 35 languages including all 24 EU official languages, while Apertus is Switzerland's fully open multilingual model trained on over 15 trillion tokens. The company emphasizes choice and open standards to avoid vendor lock-in and strengthen national AI resilience.
read more →

AI risk and preparedness gaps top cyber concerns

🔍 PwC's 2027 Global Digital Trust Insights report, based on a survey of 3,934 leaders across 71 countries, finds adversarial AI is viewed as the largest cyber preparedness gap, with 52% flagging it as the top concern. Governance remains fragmented—ownership of AI risk is split across CIO/CTO, dedicated AI leaders, and CISOs—while only a third have appointed a chief AI officer. Data protection lags with around half implementing classification and DLP, yet 84% expect budgets to rise and many prioritize AI for detection, governance, and platform hardening.
read more →

White House secures voluntary AI safety accord

📄 The White House has obtained a voluntary safety commitment from six leading AI firms, who agreed to internal controls, independent audits and board-level oversight for frontier models. President Trump and the executives signed the White House Accord on Super Intelligence on September 29. Signatories include leaders from Google, Anthropic, Meta, OpenAI, xAI and NVIDIA. The accord outlines four layers of controls and calls for regular meetings to develop standards and best practices.
read more →

Google Cloud Data Agent Kit reaches general availability

🛠️ Today Google Cloud announces the general availability of Data Agent Kit, a free set of Model Context Protocol (MCP) tools and Google-authored agent skills that let coding agents access and act on Google Cloud data products. The GA release adds support for BigQuery Graph, Bigtable, and Managed Service for Apache Spark in Lakehouse workflows, plus numerous quality-of-life and performance improvements. The kit integrates with IDEs, Antigravity, Claude Code, Codex, Cloud Shell, and Cloud Workstations, enabling agents to inspect schemas, run queries, read job logs, and orchestrate pipelines using customers' IAM permissions.
read more →

AI Expands SOC Capacity but Raises Skills Concerns

🔍 A Swimlane study finds AI increases SOC analyst capacity, freeing time for complex investigations and strategic work while reducing repetitive tasks. Respondents reported high confidence in spotting incorrect AI recommendations, yet many worry automation limits on-the-job skills development. The report urges formal AI oversight, redesigned training and clearer career paths to preserve investigative judgment.
read more →

Security Roadmaps Shift to Continuous, Quarterly Review

🛡️ Security leaders are moving away from static three-year roadmaps toward a two-speed approach: long-term principles and architecture planned annually while tactical tools and controls are reassessed quarterly (or more frequently). Organizations must treat governance as ongoing communication, adapt to rapid AI-driven change, and retain long-range commitments only when tied to enduring business outcomes. Success depends on cross-functional coordination, visible metrics for boards, and flexible execution.
read more →

Cloudflare’s AI-Driven Cryptography Discovery Effort

🔍 Cloudflare describes its internal effort to achieve full post-quantum (PQ) readiness by 2029, focusing on discovering and classifying cryptographic uses across its centralized codebase. The company developed an AI-assisted tool, CryptoLabe, to map repositories, identify cryptography in source, configs, and docs, and generate actionable reports for product and engineering teams. CryptoLabe runs two-stage scans—discovery and analysis—assigning cautious classifications and surfacing prerequisites when ecosystem support is lacking. The system runs on Cloudflare Workers, Durable Objects, Workflows, and an AI Gateway to manage model requests and resource limits.
read more →

Microsoft advances Fabric, Copilot, and data apps

🔔 Microsoft showcased Fabric and SQL innovations at FabCon and SQLCon 2026 in Barcelona, highlighting integrations across Microsoft Copilot, Fabric IQ, Power BI agentic apps, and OneLake. The announcements include Fabric IQ in Copilot, agentic app creation in Power BI Desktop, Fabric Apps enhancements for developers, and IQ sharing for governed data collaboration. These updates aim to ground AI in trusted business context and speed production-ready app development.
read more →

MCP Servers Create Significant Governance Gaps

🛡️ New research from Ox Security warns that Model Context Protocol (MCP) servers are creating an enterprise governance gap as AI adoption grows. MCP standardizes connections between AI models and external tools or data, but in doing so can bypass residency controls, zero trust boundaries and granular IAM policies. Analysis of public registries found many hosts outside the US and some unregistered, while permission models like “always-allow” enabled unauthorized data access in tested scenarios.
read more →

Cloudflare founders outline 2026 vision for the Internet

🌐 Cloudflare marks its 16th anniversary with a founders' letter describing major shifts in the Internet driven by AI. The company highlights a resurgence in web growth since 2025, fueled by new creators using low-code tools and Cloudflare's developer platform. It warns that agent-driven automated traffic, now rising rapidly, could disadvantage small businesses and new entrants unless the ecosystem adapts. Cloudflare says it's introducing measures to reduce crawler load and enable creators to be compensated as agents access their content.
read more →

Anthropic’s Claude Opus 5.5 Writes Differently

📰 Arena’s benchmarking shows Anthropic’s Claude Opus 5.5 produces fewer telltale AI writing patterns, using shorter sentences and simpler wording compared with Opus 5. The analysis found a dramatic drop in em dash use and reduced semicolon frequency, while overall response length increased. Opus 5.5 scored better on most writing measures in Arena’s August–September 2026 Text Arena data.
read more →

Zero Trust for AI Agents Begins with Visibility

🔍 Organizations racing to deploy AI agents face critical visibility gaps that undermine governance. Research shows many AI workflows touch sensitive data without oversight, and Shadow AI complicates discovery. The SANS cheat sheet emphasizes inventory before enforcement: you cannot govern what you cannot see. Practical steps include treating agent spend and API keys as discovery signals, correlating network, endpoint, browser, and SaaS telemetry, and giving each agent a distinct identity for logging and authorization.
read more →

Controlling AI Agents Before They Become Privileged Insiders

🔒 AI agents are evolving into autonomous enterprise workers that do more than generate content: they read email, access SaaS, call APIs, modify records and execute workflows. This shift introduces insider-like risk because agents can act with high autonomy and broad access. Leaders must move beyond traditional IAM to enforce action-level and runtime controls, assign human owners, and apply lifecycle governance to ensure agents are discovered, monitored, and constrained.
read more →