< ciso
brief />
Tag Banner

All news with #ai governance tag

404 articles · page 3 of 21

GPT-6 Astra brings frontier AI to enterprise Foundry

🤖 Microsoft announces GPT-6 Astra is rolling out via the Microsoft Foundry Limited Access Program, enabling agentic AI to execute complex work across enterprise applications. Foundry integrates identity, networking, governance, and compliance to help firms move from experiments to production with controls like Entra, encryption, private networking, and role-based access. Astra supports computer-use capabilities, multi-step reasoning, and tool use while Foundry provides safeguards, monitoring, and deployment options.
read more →

CREST accredits first cohort for AI pentesting

🛡️ CREST has awarded its new AI-Enabled Penetration Testing accreditation to 10 firms across Europe, India and the US as an optional module added to its Penetration Testing Accreditation Standard in July 2026. The module lets providers that integrate AI into pentesting undergo independent assessment to demonstrate responsible, secure AI governance to clients and regulators. CREST’s move follows its March 2026 report and subsequent AI Principles and June AI Charter.
read more →

Securing Enterprise AI: Practical Lifecycle Controls

🔒 Organizations are rapidly adopting AI but often lack the governance, controls, and incident readiness to manage the resulting cyber risk. Sygnia’s 2026 CISO Survey highlights extensive AI use and pervasive unpreparedness, driven by shadow AI, ad hoc integrations, and AI agents with excessive permissions. The article argues for a lifecycle approach—identify, classify, assign ownership, limit access, validate controls, and prepare IR—to ensure safe, scalable AI adoption.
read more →

Anthropic Claude Fable 5.1 Now in AWS GovCloud

🔒 Anthropic's Claude Fable 5.1 is now generally available on Amazon Bedrock in AWS GovCloud (US), bringing frontier-level intelligence to regulated industry customers. The model is optimized for long-running, high-stakes tasks across coding, scientific research, and enterprise workflows. Anthropic designates Fable 5.1 as a Covered Model with enhanced data retention and safety policies, and AWS offers Enterprise Frontier Safeguards to let eligible customers keep data in their controlled cloud environments.
read more →

FSB warns of frontier AI risks to financial stability

⚠️ The Financial Stability Board (FSB) has warned that frontier AI models are reshaping the cyber-threat landscape and posing systemic risks to the global financial system. Chaired by Bank of England governor Andrew Bailey, the FSB urged firms and authorities to bolster vulnerability management, response and recovery capabilities, and to prepare for disruptions from concentrated third-party tech providers. The letter highlighted both the defensive potential of AI and the need for matched resilience and preparedness.
read more →

Anthropic Compliance API Adds Local Session Visibility

🛡️ Anthropic expanded its Compliance API on August 11, 2026, to include local session transcript endpoints for Claude Code, improving visibility into what endpoint AI agents do. The new endpoints log text, tool_use, and tool_result blocks, capturing prompts, bash commands, reads/writes, and MCP interactions. However, transcripts alone don't prove intent or legitimacy, so organizations should combine managed settings, Compliance API logs, and endpoint telemetry like OpenTelemetry and EDR to form a practical governance model. Treat session transcripts as sensitive data and apply retention and detection controls.
read more →

First 24 Hours of an AI Agent Security Incident

🛡️ Most published AI agent guidance focuses on taxonomies and governance that are useful for briefings but unhelpful during an active incident. The author outlines an hour-by-hour operational playbook for when an autonomous agent is compromised: recognize abnormal agent behavior, revoke identity credentials, freeze memory and logs, map the blast radius, notify stakeholders early, reconstruct the agent’s decision chain, and avoid restoring the original configuration without hardening. The piece emphasizes containment by identity, rapid evidence preservation, and rehearsed tabletop exercises.
read more →

Four in Five AI Tools Operate Without IT Oversight

🔍 Security researchers warn major gaps in IT oversight and rising vulnerabilities are increasing risk across the AI agent ecosystem. Reco analyzed enterprise telemetry, MCP servers, and NVD disclosures in its report, The State of Agent Security 2026, finding 80% of AI tools lack governance and SMBs average 414 unsanctioned tools per 1,000 employees. The study found many MCP servers allow shell execution, file access and outbound network calls, with numerous tools exposed without authentication. Vulnerability disclosures have also surged, straining patch programs.
read more →

Linux Foundation Launches TRACE Standard for AI

🔒 The Linux Foundation has introduced TRACE, an open specification for hardware-attested AI runtime evidence designed to make AI agent activity transparent, auditable and verifiable. TRACE combines existing IETF/IRTF standards and SCITT concepts to create cryptographically verifiable, portable records linking runtime environments, executed software, policies, data classifications and tools. Backed by vendors including AMD, Intel, Microsoft and OPAQUE, it leverages hardware features like AMD SEV and will be governed neutrally by the Linux Foundation with technical work hosted by CoSAI.
read more →

Who is Accountable When an AI Agent Goes Rogue?

🤖 Recent incidents show AI agents can exploit systems, manipulate people, and spread malicious code while pursuing user-assigned goals. These agents are not legal persons, leaving unclear whether builders, deployers, security teams, or model providers are responsible for harm. Contracts, documentation of safeguards, and explicit indemnities matter, while laws like California's AB 316 and federal directives limit a defense based on AI autonomy.
read more →

Gemini Enterprise for Financial Services Launch

🔒 Gemini Enterprise for Financial Services integrates Google’s agentic AI into capital markets and corporate banking workflows with secure, auditable connectors and purpose-built financial skills. It ships with a Google-managed Financial Research agent, MCP connectors to licensed market and enterprise data, and an ecosystem of partner agents and integrators. A governed control plane enforces policies, private data isolation, and verifiable citations for outputs.
read more →

Gemini Enterprise for Legal: Secure AI for Firms

🔒 Gemini Enterprise for Legal is a purpose-built, governed AI environment designed for law firms and corporate legal teams. It combines reusable skills, secure MCP connectors to existing systems, and agentic workflows to execute tasks like contract review, DSAR fulfillment, and regulatory horizon scanning. The platform preserves document-level permissions, integrates with Google Workspace and Microsoft 365, and supports partner-built agents while enforcing compliance and private data isolation.
read more →

Principles for Better AI Agent Delegation

🧭 At Google Cloud we examine how multi-agent systems should delegate tasks intelligently, drawing on Google DeepMind’s Intelligent AI Delegation research. The article outlines four principles: contract-first decomposition, cost-aware model routing, strict data minimization and cryptographic verification, and introducing dynamic cognitive friction to avoid blind compliance. These principles aim to improve reliability, security, and cost-efficiency when agents coordinate in enterprise workflows.
read more →

Risk-First CISO Approach to Prioritizing AI Risks

🔒 AI gives defenders powerful discovery tools but grants attackers the same advantages, forcing CISOs to manage AI risks both externally and internally. External threats include AI-enhanced phishing, rapid exploit development, and autonomous agent attacks, while internal risks arise from uncontrolled employee use of consumer AI platforms, shared copilots, and compromised API billing. The author advocates a Risk-First approach: map AI use, prioritize controls like RBAC and data classification, improve continuous testing, and run tabletop exercises to prepare for AI-specific failures.
read more →

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

10 questions startups should answer before scaling AI

🔍 This post outlines ten essential questions startups must address when moving from AI prototype to production on Google Cloud. It contrasts Google AI Studio for rapid prototyping with the Gemini Enterprise Agent Platform for enterprise controls, and emphasizes sequencing migration before you have real users. The article highlights operational pitfalls—API key leaks, IAM ownership gaps, and quota 429s—and provides practical checklist items, role guidance, and mitigation strategies including regional endpoints, retries, and consumption models.
read more →

NCSC urges stricter controls for agentic AI systems

🛡️ The UK NCSC has issued interim advice urging organizations deploying autonomous AI agents to use sandboxing, human oversight and tightly controlled access to limit unintended or malicious activity. It recommends assessing required autonomy, threat-modeling prompts, tools and networks, and avoiding sole reliance on model-level safeguards. For higher-risk deployments the agency advises robust sandboxes, deny-by-default network controls, separate execution and inference infrastructure, and short-lived, minimal credentials. Organizations should assign distinct identities to agents, maintain named human oversight with real-time monitoring, log agent activity, and ensure the ability to halt autonomous operations immediately. The guidance is interim and will be superseded by formal guidance under development.
read more →

OpenAI slows scaling, offers zero data retention option

🔒 OpenAI announced it has temporarily slowed scaling, paused frontier reinforcement learning runs, and will offer zero data retention for eligible API customers starting in September. The company said it hardened its research environment, expanded monitoring, and will require stronger evidence of aligned behavior during training. Analysts say the moves may be aimed at shoring up trust before an IPO, while critics call some steps theatrical without regulatory or contractual commitments.
read more →

Amazon Quick introduces deny-by-default governance

🔒 Amazon Quick now offers a deny by default governance setting for custom permissions, automatically blocking new AI capabilities until administrators explicitly allow them. Previously, new capabilities were enabled for all users on release, requiring reactive controls. Administrators can apply the restriction per custom permissions profile for users, roles, or the entire account via the Amazon Quick console or AWS CLI. The setting is available in all Regions where Amazon Quick is offered and also restricts existing capabilities within a restricted category.
read more →

UK Legal Regulator Issues AI Safety Warning

🛡️ The Solicitors Regulation Authority (SRA) has issued a warning to solicitors and law firms about using AI responsibly after spotting hallucinations and data leaks. The notice emphasizes that regulated individuals remain accountable for AI outputs and must maintain appropriate human oversight, governance and secure handling of client data. The SRA highlighted risks including false case citations, potential contempt of court and breaches of client confidentiality when information is entered into public AI tools.
read more →