< ciso
brief />
Tag Banner

All news with #ai governance tag

404 articles · page 10 of 21

CISA's AI SBOM Guidance Expands Supply‑Chain Oversight

🔍 The US Cybersecurity and Infrastructure Security Agency (CISA), working with G7 cyber partners, released supplemental minimum elements for an AI software bill of materials to document models, datasets, software components, providers, licenses, and other dependencies. The guidance extends traditional SBOM concepts into AI and is positioned to support procurement and vendor-risk assessments while remaining non‑exhaustive and non‑mandatory. Security teams should press vendors for model provenance, training and update practices, and runtime controls, but must recognize AI SBOMs provide visibility rather than assurance.
read more →

AWS Approach to Enabling AI Sovereignty in Cloud Globally

🔒 AWS outlines its approach to AI sovereignty, emphasizing customer control over data, deployment location, and access across the AI stack. It highlights infrastructure choices—AWS AI Factories, Outposts, Local Zones, Dedicated Local Zones, and the AWS European Sovereign Cloud—to meet regulatory and operational needs. AWS emphasizes technical protections like the AWS Nitro System, identity controls (IAM and Amazon Bedrock AgentCore Identity), and certifications such as ISO/IEC 42001 to reinforce transparency and trust.
read more →

Agentic AI: The Next Blindspot for Security Teams and Risk

🔐 Agentic AI is already operating across enterprises, executing tasks and taking actions often without meaningful security involvement. Security teams must develop hands‑on fluency — build and test agents, understand integrations like the Model Context Protocol, and enforce scoped configurations — because policy alone won't close the gap. The piece distinguishes three agent classes (productivity, MCP‑connected vendor agents, and custom user agents) and emphasizes configuration, access scoping, and training such as SANS SEC545 to reduce exposure.
read more →

CISOs Step into AI Spotlight: Risk, Governance and Trust

🔒 CISOs are shifting from a primarily technical control function to strategic business partners as AI reshapes risk, operations, and product delivery. Leaders such as Barry Hensley, Shaun Khalfan, and Jeff Trudeau stress publishing AI security frameworks, embedding security early in development, and aligning controls to business outcomes. They warn of AI-enabled threats — including advanced phishing, voice/video impersonation, and automated vulnerability discovery — and call for continuous controls, stronger identity and data governance, and near-real-time patching. Growing board engagement and changing reporting lines reflect the elevated role of security in enterprise strategy.
read more →

Architecting Resilient Foundations for the Agentic Era

🔐 At Google Cloud Next, Google outlined a resilient, scalable, and secure foundation to accelerate public sector adoption of the agentic era, highlighting infrastructure, data, and security innovations. Key infrastructure announcements include the AI Hypercomputer with eighth-generation TPUs (TPU 8t for training, TPU 8i for inference) and Virgo Networking, plus Google Distributed Cloud bringing Gemini to where data resides. On data, an AI-native architecture features Knowledge Catalog (FedRAMP High, DoD IL4 & IL5) and a cross-cloud Lakehouse to ground agents in trusted context. Security advances combine Google Threat Intelligence with Wiz, authorize Cloud Armor and Model Armor, and add defensive agents to protect models and sensitive data.
read more →

Eight Principles for Reskilling the SOC for Agentic AI

🤖 DXC Technology, Accenture, and other organizations are actively retraining SOC teams to integrate agentic AI by embedding vendor experts and building secure sandboxes. CISOs emphasize top-down leadership, rapid experimentation, and formal learning tracks to shift mindsets and roles. Governance, humans-in-the-loop, and clear escalation and audit paths are required while agents take on L1/L2 tasks.
read more →

BASF's AlphaEvolve builds digital twin for supply chain

🔁 BASF created a digital twin of its complex two‑year agricultural supply chain using AlphaEvolve on Google Cloud. The evolutionary AI began from a seeded planning program and ingested three years of historical production, inventory, and demand data to autonomously evolve planning logic. Resulting algorithms closely mirrored historical inventory and production behavior, improving accuracy by over 80% versus the seed and producing human‑readable rules to support planners.
read more →

New ISO/IEC 42001:2023 Compliance Guide for AIMS on AWS

🔒 AWS published a practical compliance guide, ISO/IEC 42001:2023 on AWS, to help organizations design and operate an Artificial Intelligence Management System (AIMS) using AWS services. The guide maps ISO 42001 clauses 4–10 and the Annex A controls to AWS services and architectural patterns, and it explains scoping, shared responsibility, and audit readiness. It highlights automation, evidence collection, monitoring, and responsible AI features to reduce effort in preparing for certification.
read more →

Five Guides to Production-Ready AI Agents at Scale

🤖 At Google Cloud Next '26, Google introduced the Gemini Enterprise Agent Platform to help teams build, deploy, scale, govern, and optimize autonomous AI agents in production. The series highlights long-running state management in Agent Runtime, a layered Agent Governance Stack, orchestration patterns in the Agent Development Kit (ADK), integration standards, and prebuilt blueprints in Agent Garden.
read more →

AI Adoption Outpaces Safety Policies, Raising Systemic Risk

🛡️ New ISACA research finds AI tools are widely used in organizations, but governance is lagging. Ninety percent of digital trust professionals say employees use AI, yet only 38% report a formal, comprehensive AI policy while 25% have none at all. The poll highlights rising Shadow AI risks, with 56% unsure how long it would take to halt an AI system and only 20% having shutdown procedures, increasing exposure to data breaches and privacy failures.
read more →

White House Weighs Pre-Release Checks for High-Risk AI

🛡️ The White House is privately discussing whether advanced AI models that could enable cyberattacks should undergo government-led or formal pre-release reviews before public deployment. The talks were prompted by Anthropic’s Mythos, which the company says has identified thousands of high-severity vulnerabilities, and by comparable capabilities from other labs. Officials are weighing options including formal vetting and targeted testing for higher-risk systems. No policy has been finalized and no timeline has been set.
read more →

Agencies Set Clear Limits on Agentic AI Deployments

🔒 A joint advisory from CISA and international partners urges organizations to treat agentic AI cautiously, enforcing strong authentication, Secure by Design principles, and staged rollouts. The guidance stresses least privilege, inventories of agent capabilities, and protections against prompt injection and data exposure. It also recommends continuous monitoring with human-in-the-loop controls, DevSecOps practices, and regular incident-response testing to reduce privilege creep, tool misuse, and other emergent risks.
read more →

Guide: Secure Adoption of Agentic AI — CISA and Partners

🔒 CISA, the Australian Signals Directorate’s Australian Cyber Security Centre (ASD ACSC), and U.S. and international partners published Careful Adoption of Agentic Artificial Intelligence Services, a joint guide describing cybersecurity challenges and mitigations for agentic AI. The document warns that agentic AI can expand attack surface, cause privilege creep, produce behavioral misalignment, and obscure event records while offering automation benefits to critical infrastructure and defense sectors. It targets developers, vendors, and operators with actionable recommendations — including avoiding broad or unrestricted access to sensitive data and systems, beginning with low‑risk, non‑sensitive use cases, and explicitly accounting for agentic AI in organizational security models and risk posture.
read more →

Re-permissioning to curb excessive AI agent autonomy

⚖️ Re-permissioning aligns AI agents' access with clear operational needs so they execute tasks safely rather than accumulate unnecessary powers that enable unauthorized actions. As agents evolve from responders into execution engines, interoperability standards like MCP and agent-to-agent flows expand reach but also multiply where things can go wrong. Organizations should enforce continuous permission audits, mandatory human-in-the-loop checks for sensitive operations, strict least-privilege context sharing, and vet integrations, libraries and third parties while running tabletop prompt-injection exercises to validate controls and prevent data exposure or integrity-impacting changes.
read more →

Securing and Governing AI Agents Through an AI Gateway

🔒 Palo Alto Networks announced its intent to acquire Portkey and integrate Portkey’s AI Gateway into Prisma AIRS to provide a centralized control plane for agentic AI. The combined platform will offer a unified API to thousands of LLMs, an agent registry, semantic routing, caching and runtime protections such as Agent Artifact scanning and automated red teaming. Integration with CyberArk is intended to enforce agent identity and least‑privilege controls. The goal is to enable enterprises to move autonomous workloads from development to production with consistent governance and minimal performance tradeoffs.
read more →

Designing Trust and Safety for Amazon Bedrock Apps

🛡️ This article outlines AWS guidance for integrating trust, safety, and responsible-AI practices into applications built on Amazon Bedrock. It defines core responsible AI dimensions—such as safety, controllability, fairness, explainability, security and privacy, robustness, governance, and transparency—and maps them to lifecycle stages: design, deployment, and operations. It recommends observability and guardrail tools like Amazon CloudWatch and Bedrock Guardrails for monitoring, abuse detection, configurable content filters, and hallucination controls, and describes an abuse response process for coordination with AWS Trust & Safety.
read more →

SageMaker AI introduces automated inference recommendations

🔧 Amazon SageMaker AI now provides inference recommendations that automate optimization and benchmarking to deliver validated, deployment-ready configurations. Customers supply their own generative models, define expected traffic patterns, and set a performance objective — optimize for cost, minimize latency, or maximize throughput. SageMaker analyzes model architecture, benchmarks across multiple instance types using NVIDIA AIPerf, and returns metrics such as time to first token, inter-token latency, request latency percentiles, throughput, and cost projections. The capability is available today in seven AWS Regions.
read more →

Building the AI Foundation for Public Sector Partners

🚀 Google Public Sector is launching coordinated initiatives to help partners build, certify, and bring AI solutions to government customers faster. The program includes a federal startup accelerator in collaboration with NVIDIA for AI-focused ISVs, an expanded ISV ATO Accelerator offering up to $1M in funding, and a new Distributor Channel Private Offer with Carahsoft. These efforts target procurement, compliance, and legacy environment barriers to speed deployment of mission-critical AI.
read more →

Unchecked AI Agents Drive Widespread Enterprise Incidents

⚠️ Research from the Cloud Security Alliance (CSA) and Token Security warns that unchecked AI agents have caused widespread cybersecurity incidents across enterprises in the past year. The report finds many organizations overestimate agent visibility — 68% claim high visibility while 82% discovered unknown agents — leading to data exposure, operational disruption and financial losses. It highlights weak lifecycle governance, particularly around decommissioning, and calls for unified controls across discovery, policy, monitoring and decommissioning.
read more →

Why AI Projects Stall After the Demo: Operational Gaps

🔍 Demos often hide the operational friction that causes many AI initiatives to stall once they move into production. What succeeds in a controlled presentation—clean data, crafted prompts, and fast isolated responses—rarely maps to fragmented security and IT environments with noisy inputs, latency constraints, and numerous edge cases. Teams that validate tools against real workflows, measure accuracy and latency under load, prioritize deep integration, clarify cost models, and embed governance early are far more likely to turn a promising demo into sustained production value.
read more →