< ciso
brief />
Tag Banner

All news with #ai governance tag

403 articles · page 14 of 21

Delegation Is a Risk Decision, Not Just an Ops Choice

⚠️ Delegating authority to software and automated workflows is fundamentally a risk decision, not merely an operational efficiency. Leaders routinely hand judgment and transaction power to systems through configuration, vendor defaults, or personal agents, creating outcomes that persist beyond intent. Security teams often surface the first signals, but the exposure spans operational, financial, legal, and reputational domains. Organizations must document, bound, and assign ownership for delegated authority so tradeoffs align with enterprise risk appetite.
read more →

Four Key Problems That Hamper CISOs' Effectiveness

🔒 Many CISOs expect a major cyber incident within the next year but report their organizations are not prepared. The article identifies four primary barriers: teams not empowered to prioritize, failure to keep pace with business AI adoption, limited AI deployment in security, and a widening talent and skills gap. It recommends clear decision criteria, AI-focused governance, and targeted talent strategies to reduce bottlenecks and limit shadow AI risk.
read more →

How CISOs Can Overcome AI Fatigue and Govern Use Effectively

🤖 Many CISOs feel torn between moving quickly with AI and preventing new security risks. The article recommends breaking AI into categories by autonomy and potential impact to separate routine generative AI from higher-risk agentic systems. It stresses that data integrity is as important as data protection and proposes a tiered governance model: categorize use, apply baseline controls, assign review forums, and enforce unbreakable rules like kill switches. Practical measures such as acceptable-use policies, training, least-privilege and continuous monitoring are highlighted as table-stakes.
read more →

CISOs' 2026 Predictions: AI, Governance, and Resilience

🔐 As AI accelerates adoption and threat automation, CISOs foresee 2026 as a turning point for governance, resilience, and identity-centric defense. Leaders expect boards to elevate AI and quantum risk, vendors to deliver secure-by-design products, and SOCs to consolidate telemetry and automate responses. Small and mid-size firms will face intensified targeting, making tailored security services essential.
read more →

Webinar: How MSSPs Use AI to Double Margins and Cut Staff

🧠 This webinar explains how managed security service providers can apply AI to eliminate repetitive tasks, accelerate onboarding, and preserve margins with leaner teams. Cynomi CEO David Primor and Chad Robinson, CISO at Secure Cyber Defense, outline how automation handles assessments, benchmarking, and reporting in minutes, turning junior analysts into effective virtual CISOs and enabling consistent, repeatable CISO-grade delivery.
read more →

OpenAI rolls out ChatGPT age-prediction model globally

🛡️ OpenAI has introduced an age-prediction model in ChatGPT that analyzes conversation topics and usage patterns to infer whether a user is a teen or an adult and apply safety-related content restrictions. The system can err and may sometimes flag adults as teens; users 18+ who are mistakenly restricted can complete an age verification flow through the partner Persona, which may require a live selfie and a government-issued ID. Persona reportedly deletes verification material within seven days, and confirmed adults will have the extra safety settings removed after verification.
read more →

Four priorities for AI-powered identity and network access

🔐 Microsoft recommends four priorities for identity and network access in 2026: deploy fast, adaptive AI protection; manage and govern AI agents as first-class identities; unify identity and network controls into an Access Fabric; and strengthen identity foundations with phishing-resistant credentials and high-assurance recovery. The post cites Microsoft Entra capabilities and studies showing faster, more accurate admin workflows, and emphasizes applying Zero Trust to agents, networks, and devices.
read more →

AI Search and Advertising: Risks of Consumer Manipulation

🧭 OpenAI’s launches of ChatGPT Search and the ChatGPT Atlas browser mark a pivot toward monetizing user attention through advertising. The essay warns this trajectory risks reproducing the ad-driven incentives of search incumbents like Google, enabling conversational AI to influence purchases, opinions, and online behavior more subtly and effectively than traditional ads. Schneier urges caution, greater consumer data control, and public-policy responses to protect trust.
read more →

Gartner: AI Model Collapse Spurs Zero Trust Data Governance

🔒Gartner warns that the growing prevalence of AI-generated content could cause future LLMs to be trained on outputs from previous models, increasing risks of model degradation, hallucinations and bias. The analyst predicts up to half of organizations may adopt zero trust data governance amid rising regulatory scrutiny. Firms are urged to appoint AI governance leaders, strengthen metadata management and deploy authentication and verification controls to safeguard decision-making and financial outcomes.
read more →

AI-Powered Surveillance Deployed at Beverly Hills High

🚨 Inside Beverly Hills High School, an array of AI-driven surveillance tools is being used to monitor students and campus activity. Video cameras run facial recognition and behavior-analysis models, a smoke-detector-shaped device captures audio for distress sounds, drones stand ready for aerial intel, and license-plate readers from Flock Safety track vehicles. The deployment raises questions about privacy, oversight, and the normalization of commercial surveillance in schools.
read more →

Seven Priority Cybersecurity Projects for CISOs in 2026

🔒 As CISOs prepare for 2026, seven pragmatic projects can strengthen defenses against evolving threats. Priorities include transforming identity and access to cover human and non-human agents and reinforcing email security. Organizations should leverage AI for vulnerability discovery and security automation, enforce enterprise AI governance, adopt a zero-trust-by-default posture, and unify data governance to reduce shadow data and compliance gaps.
read more →

AI and the Corporate Capture of Public Knowledge Debate

📚 The essay links Aaron Swartz’s fight for open access to today’s large AI firms that scrape and monetize vast amounts of public and private knowledge. It argues that AI companies are effectively appropriating research and creative works, settling liabilities as a cost of business while public access and accountability erode. The piece warns this corporate capture shifts control of information from democratic institutions to private platforms.
read more →

WEF 2026: AI Drives Cybersecurity Risks and Responses

🔐 The World Economic Forum's Global Cybersecurity Outlook 2026 finds that advances in AI, geopolitical fragmentation and complex supply chains are intensifying cyber risk. Respondents named AI the top driver of change (94%) and reported rising AI-related vulnerabilities (87%), while confidence in national preparedness continued to fall. The report urges security-by-design, strong governance, and retained human oversight as organizations scale AI defenses. Notably, 64% now assess AI tools before deployment and 77% have deployed AI in security operations, though skills gaps and trust remain major obstacles.
read more →

Modernizing Vulnerability Sharing for AI Threats and Policy

🔐 The post argues that traditional vulnerability-sharing frameworks built around software flaws are inadequate for adversarial AI threats such as poisoning and inference attacks that target models and data rather than code. It recommends bridging existing cyber infrastructure — including the CVE Program, CVSS, CNAs, the NVD and CISA’s KEV Catalog — with new standards for AI artifacts like poisoned datasets and backdoored models. Palo Alto Networks supports the White House AI Action Plan and the proposed AI-ISAC to accelerate adoption, coordinate disclosure, and help operationalize AI-specific vulnerability management.
read more →

Microsoft Named Leader in IDC AI Governance Report

🔒 Microsoft was named a Leader in the 2025–2026 IDC MarketScape for Worldwide Unified AI Governance Platforms, recognizing its integrated approach to governing generative, agentic, and traditional ML across hybrid and multicloud environments. The company emphasizes centralized control, observability, and automated compliance through Microsoft Foundry, Agent 365, Purview, Entra, and Defender. Backed by the Responsible AI standard and an Office of Responsible AI, Microsoft highlights built-in transparency, fairness, explainability, and real-time security protections for regulated enterprises.
read more →

Impersonation Drives Crypto Fraud to Record $17bn in 2025

🪙 Chainalysis reports cryptocurrency-related fraud reached at least $14bn in 2025 and expects the total to rise to $17bn as more illicit wallets are identified. Impersonation scams surged in volume by 1,400% YoY and payment values jumped, while AI-linked operations now extract substantially higher revenues. The report warns of industrialized, Asia-linked networks using layered laundering to convert crypto into real-world assets and urges combined prevention and law enforcement responses.
read more →

Allianz: AI Rises to Major Global Business Risk Worldwide

🤖 Allianz Commercial's annual Risk Barometer reports that artificial intelligence has jumped from tenth to second place among global business risks, trailing only cybercrime. The insurer warns that cybercriminals increasingly harness AI for social engineering—deepfakes, cloned voices and highly tailored phishing—while legitimate internal AI use can produce erroneous or fabricated outputs that prompt litigation and reputational harm. The survey of 3,338 professionals across 97 countries also links AI risk to business interruptions and copyright exposure.
read more →

Survey: Nearly 90% of Federal Agencies Using AI Now

🔍 Google Public Sector commissioned a Government Executive survey of 250 federal IT leaders, finding nearly 90% of agencies are planning to or already using AI. Respondents cited common use cases such as document and data processing, workflow and process automation, and decision support systems. Security and adversarial risk were identified as the top adoption barrier, with reliability and workforce disruption also noted. Google highlights Gemini for Government, GSA OneGov pricing, and expanded training programs as measures to address cost, legacy, and skills constraints.
read more →

The Year of Resilience: What 2026 Requires of CISOs

🔒 Fortinet CISO Carl Windsor argues that 2026 will demand resilience as the central organizing principle for security as AI accelerates both innovation and risk. CISOs must act as de facto chief resilience officers, embedding continuity into AI-augmented operations and assuming AI-enabled failures will occur. He outlines five strategic priorities—business continuity, AI governance, hardened identity, cross‑functional collaboration, and continual adaptation—to contain and absorb disruption.
read more →

CISOs' Top Cybersecurity Priorities and AI Focus for 2026

🔐 In 2026 CISOs are balancing core security tasks with urgent AI-related challenges. Strengthening data protection, securing cloud and enterprise AI deployments, and improving identity and access management rank high. Leaders are preparing for AI-enabled attacks, rolling out AI to accelerate security operations, and addressing shadow AI and third-party risks to bolster resilience and supply-chain security.
read more →