< ciso
brief />
Tag Banner

All news with #ai governance tag

352 articles · page 3 of 18

Open Secure AI Alliance launches without OpenAI

🔒 The Open Secure AI Alliance, spearheaded by Nvidia and backed by more than 30 major AI vendors and users, aims to promote open-source defensive AI tools after an incident revealed limitations of closed commercial models. Hugging Face’s forensic work was blocked by safety guardrails on hosted models, forcing it to use an open-weight model on its own infrastructure. The alliance emphasizes that open models and harnesses democratize defense, increase transparency, and allow localized control. OpenAI has not commented on whether it will join the initiative.
read more →

Co-operative time‑slicing for RL to boost GPU use

🧭 This post introduces co-operative time-slicing from the llm-d project to reduce accelerator idle time during reinforcement learning (RL) post-training for large language models. By treating sampling and training steps as schedulable phases, the platform interleaves independent RL jobs on shared hardware, increasing aggregate GPU duty cycles from ~40% to 70% without harming convergence. The system uses a client library, a cluster orchestrator, and a node-level snapshot agent to checkpoint and restore device state, enabling fast context switches and improved price-performance for RL workloads.
read more →

AI agent identities create a new enterprise attack surface

🛡️ The Sophos AI Security 2026 Report warns that rapid enterprise adoption of AI tools has created a growing attack surface as AI agents and assistants gain privileged access to systems. Threat actors are targeting OAuth tokens, service credentials and exposed AI infrastructure because governance has not kept pace. The report urges treating AI agents like human users, enforcing least privilege, manual verification for new access and setting alerts for suspicious AI behavior.
read more →

MIT expands AI video surveillance across campus

🔍 MIT is deploying over 500 AI-equipped surveillance cameras across academic buildings, residence halls, and outdoor areas, a program costing more than $3 million and installing from November 2025 through September 2026. The cameras, largely Hanwha Wisenet AI models monitored with Ai-RGUS software, can classify faces and objects in real time and detect behaviors such as loitering and crowds, with data retained for up to 30 days unless exceptions apply. Technical specs include 2MP–4K resolution, PTZ capabilities, and classification up to 11 meters.
read more →

AI Adoption Shifts Expectations for Risk Management

🛡️ As AI becomes embedded across products, workflows, and supply chains, security leaders are being asked to enable faster, safer business decisions. Existing governance programs lag behind AI adoption, widening gaps in visibility and control. Fragmented risk views across security, procurement, privacy, and IT create blind spots that expand the blast radius when AI systems connect to enterprise data and workflows. CISOs must move from periodic risk review to continuous assurance and risk decisioning to prioritize what can move forward, what needs guardrails, and what must stop.
read more →

Senior executives driving shadow AI risk in enterprises

🔒 Senior leaders increasingly use unapproved AI tools despite clear security and privacy concerns, creating major headaches for CISOs and IT teams. TrustedTech’s survey found nearly two-thirds of senior decision-makers use shadow AI, often because sanctioned tools are slower or inadequate. Experts say this is a culture and usability problem rather than simple ignorance, and that governance must be modeled from the top while offering secure, usable alternatives.
read more →

Accelerating foundation model upgrades for teams

🔎 Upgrading foundation models is slow and costly for engineering teams, often requiring months of manual testing and evaluation. Google Cloud Applied ML built an agentic workflow that reduces migration time from months to hours using the Gemini Enterprise Agent Platform and Google Antigravity. The blog outlines three lessons and practical steps—deploying Autoraters, building an agentic loop, and automating orchestration—to replace manual toil with intelligent automation.
read more →

Regulating Corporate Responsibility for AI Privacy

🛡️ Daniel Solove argues in the Wall Street Journal that individual control over personal data is insufficient to protect privacy in the AI era. He urges shifting regulatory focus to hold companies accountable—similar to food and drug oversight—through measures like data minimization, fiduciary duties, and liability for negligent design. Solove also recommends liability for harmful algorithms and multi-stakeholder review of technologies to ensure safer outcomes.
read more →

SANS warns of growing AI governance gap

🛡️ The SANS Institute’s 2026 AI Survey Insights shows rapid AI adoption in security, with 78% of organizations using AI versus 50% in 2025, yet confidence and effectiveness lag. The survey of 536 practitioners and 57 leaders found rising shortcomings in detection and response and increased AI-enabled attacks, including deepfakes and adversarial exploits. SANS highlights a governance shortfall—half of leaders report formal programs while many remain in early policy stages—and urges investment in validation infrastructure, operational governance, and immediate workforce upskilling.
read more →

Analyze and Govern Gemini Enterprise with BigQuery

🔎 Google Cloud outlines how to integrate Gemini Enterprise telemetry into BigQuery to enable scalable analytics and governance. The article explains pre-computed dashboards, streaming log sinks, and five partitioned telemetry tables for prompts, model responses, user activity, and audit logs. It highlights BigQuery Conversational Analytics, auto-generated schema documentation, and techniques to build executive dashboards and compliance workflows.
read more →

Continuous AI Red Teaming as Ongoing Security

🔍 AI security cannot be treated as a one-time certification; it requires an ongoing cycle of adversarial discovery, hardening, and operational resilience. NIST research shows no finite set of guardrails can guarantee permanent robustness, so teams must continuously test, remediate, and monitor systems as models, prompts, and integrations evolve. Effective programs tie red teaming to runtime protection and governance so findings become durable improvements.
read more →

Build an AI incident response playbook now

🔍 Organizations increasingly deploy AI in production yet lack effective governance and IR playbooks tailored for AI. The author, drawing on 14 years in security and recent AI risk work, argues traditional IR frameworks don’t cover model-originated failures like hallucinations or degradation. He recommends practical pre-incident steps: an AI Bill of Materials, actionable model cards, a named data scientist on call, and defined rollback thresholds to improve detection, containment and legal readiness.
read more →

AI Data Centers and Concentration of Corporate Power

📰 Local opposition to AI data centers reflects real concerns about land use, energy costs, environmental impact, and few local jobs, especially in lower-income communities. The authors warn this focus can distract from the broader threat: the concentration of power and wealth in AI companies and their political influence. They argue that policy responses should target corporate power, taxation of AI computation, public AI alternatives, and stronger regulation rather than only blocking data centers.
read more →

AI Risk Registers Are Not Incident Response Plans

🛡️ Organizations are documenting AI risks but often lack an operational response when those risks materialize. A risk register can list potential failures—like inaccurate outputs or data exposures—but it does not define who can pause systems, preserve evidence, or lead an investigation. Security teams must translate governance artifacts into executable playbooks that include ownership, evidence requirements, triage, escalation and pause authority proportional to risk.
read more →

AI Surveillance Threatens Social Freedom and Progress

🔍 AI-powered surveillance will soon monitor and penalize public and private behavior in real time, combining advanced facial recognition, mass databases, and personalized enforcement. These systems, already widespread in China and being trialed globally, can produce chilling effects on personal freedoms, democracy, and social progress by encouraging conformity and self-censorship. Policy interventions like bans, privacy protections, and AI regulation are proposed to prevent such outcomes.
read more →

Redefining the CISO Contract for AI Adoption

🔐 The article argues that CISOs must shift from merely securing the business to enabling secure business operations with AI. It emphasizes focusing on intent, governance, and scope rather than assigning blame to AI agents, and recommends partnering with engineering, prioritizing high-risk exposures, and embedding continuous assurance into CI/CD. The piece frames AI security as a strategic enabler that preserves speed and mitigates risk.
read more →

CREST launches AI charter for cybersecurity use

🔒 Over 70 cybersecurity organisations have signed the new CREST AI Charter, launched on July 9, committing to nine principles governing AI-enabled cybersecurity activities. The charter covers accountability and governance, transparency of use, documentation and auditability, boundaries and control, data handling and sovereignty, security and confidentiality, secure development, supply chain assurance and resilience. Signatories will maintain human oversight, document AI use, disclose data practices and implement secure development and supply chain controls. CREST intends the charter as a self-regulatory foundation to drive standards and harmonisation across industry and regulators.
read more →

Gemini Enterprise for Education Named a Commander

🚀 Gemini Enterprise for Education has been named a Commander in the Tambellini StarChart™: 2026 AI Agents for Administrative Efficiency—Agent Platforms, ranking first in innovation and usability. The platform unifies Gemini models, agent-building tools, enterprise search, governance controls, and Google Cloud infrastructure to help institutions automate administrative workflows, support students, and enable research. Customers such as UC Riverside and Purdue report measurable operational and educational benefits from the integrated, governed agentic solution.
read more →

The modern CISO is becoming the next CFO

🛡️ The role of the CISO is evolving from a technical operator into a broad, enterprise-level executive responsible for cyber resilience, regulatory compliance, AI governance and business risk. As cyber risk becomes business risk, organizations are expanding security leadership—adding deputy CISOs and specialized teams—while keeping centralized accountability. The author argues the CISO should report independently (e.g., to the CEO, COO or CRO) and that AI increases the need for clear human accountability.
read more →

Agentic AI Exposes Zero Trust Blind Spots

🤖 Stephen Wilson of HashiCorp describes agentic AI as “really smart kindergartners” — capable of execution but lacking judgment. This mismatch strains traditional zero trust models that authenticate humans and grant privileges gradually, because agents can be created and destroyed rapidly. Organizations often respond by lowering controls, risking incidents such as accidental deletion of production data. Wilson argues this will force necessary long-term improvements like zero standing privilege and dynamic credentials while keeping humans "on the loop."
read more →