< ciso
brief />
Tag Banner

All news with #ai governance tag

352 articles · page 5 of 18

US Government's Expanding Use of AI Raises Oversight Questions

📰 The Trump administration disclosed an inventory of 3,611 active or planned AI use cases across the federal government, a 70% increase from the Biden-era list, including controversial proposals ranging from grant screening to inmate risk assessment and nuclear reactor control. The brief disclosures lack meaningful context, public consultation, and consistent impact labeling, limiting oversight. The authors argue for rigorous transparency, public comment, and risk assessment frameworks, citing France and Canada as stronger models, while acknowledging some beneficial uses like machine translation.
read more →

Five AI Risk Frameworks to Shore Up Critical Gaps

🧭 Organizations integrating AI find legacy risk frameworks insufficient and are turning to AI-specific guidance. New standards and frameworks offer structured approaches for governance, technical controls, threat modeling, and regulatory alignment. Options include ISO/IEC 42001, NIST AI RMF, ENISA FAICP, ISO/IEC 23894, and Google’s SAIF, each addressing different priorities and maturity levels. Choosing the right framework depends on organizational needs and resource constraints.
read more →

AWS Security Agent Adds AI Threat Modeling

🔍 AWS Security Agent, now part of AWS Continuum, introduces an AI-powered threat modeling capability in public preview that automatically generates threat models from design documents or source code. The agent analyzes application architecture, data flows, and trust boundaries to identify threats across all six STRIDE categories and recommends mitigations. Developers can integrate the agent into IDEs such as Kiro and Claude Code for early design-phase assessments, while security teams can perform pre-deployment reviews. The feature is available in all regions supported by AWS Security Agent at no extra cost during the preview.
read more →

AWS streamlines Foundational Technical Review process

✅ AWS Partner Central now accepts SOC 2 Type II audit reports or AWS Well-Architected Framework Reviews (WAFR) to complete the Foundational Technical Review (FTR) in minutes. The process uses AI-powered validation to provide immediate approval or actionable feedback, accelerating access to the qualified software badge, APN program eligibility, co-selling, and funding benefits. Partners with SOC 2 can submit third-party reports; those without can submit WAFR reports from the AWS Well-Architected Tool. The service provides specific AI-generated remediation steps when issues are found, and FTR is available to all partners for solutions deployed on AWS and with AWS Partner Revenue Measurement enabled.
read more →

Experts Urge US to Reconsider Ban on Anthropic Models

🛡️ Over 50 cybersecurity professionals have urged the US government to lift its export-control directive that suspended access to Anthropic’s Mythos 5 and Fable 5 LLMs. The directive, issued on June 12, led Anthropic to suspend access to both models while it complies with the government order, which cited national security concerns tied to alleged guardrail bypass research. The signees argue the ban removes valuable defensive capabilities and call for a transparent, scientific AI risk-assessment process.
read more →

Sovereign Cloud Alone Won’t Solve AI Risk

🔒 European enterprises tested sovereign cloud under regulatory pressure and found residency alone doesn’t equal control. Vendors offer sovereignty features, but practitioners at EIC 2026 emphasized that identity governance — not just data location — determines operational sovereignty for AI workloads. Weak identity controls, especially for non-human AI agents, undermine claims of control despite customer-managed keys or regional data centers.
read more →

Public Sector Security: AI as the New Battlefield

🛡️ At Check Point Engage Public Sector 2026, leaders and practitioners convened to examine how AI is transforming cyber defense and offense for government organizations. Panels highlighted that AI enables automated, fast, and scalable attacks while also becoming core infrastructure for missions. Speakers urged a shift from reactive models to proactive, prevention-first strategies, emphasizing visibility, governance, and workforce controls to secure AI adoption.
read more →

Open Knowledge Format: Portable AI Knowledge Standard

📘 Today Google Cloud introduces the Open Knowledge Format (OKF), an open, vendor-neutral specification that formalizes the LLM-wiki pattern into a portable directory of markdown files with YAML frontmatter. OKF v0.1 defines a small set of conventions so different producers’ wikis can be consumed by agents without translation. The spec is intentionally minimal — one required type field per concept — and is accompanied by reference producer and consumer implementations and sample bundles.
read more →

Debating a Sovereign AI Wealth Fund for Public Good

📝 The authors critique Senator Bernie Sanders’s proposal for a US sovereign wealth fund that would take large equity stakes in AI firms. They agree on the need for public influence and redistribution of AI-generated wealth but warn public ownership can entangle government incentives with corporate profit. Instead, they recommend taxation (e.g., datacenter or AI token taxes) and a public AI option like Switzerland’s Apertus to promote transparency, sustainability and democratic control.
read more →

AI Reveals Cybersecurity’s Missing Health Model

🩺 The author argues that cybersecurity has operated like an emergency room—reactive and crisis-driven—while AI exposes the need for a preventative, continuous-health model. Current frameworks (NIST, MITRE) describe controls and adversaries but not organizational health; the proposed Clinical Cybersecurity Framework treats the enterprise as a living system with vital signs, continuous monitoring, and governance for new risks like AI. This shift reframes the CISO role toward reporting condition and building adaptive capacity.
read more →

Three strategic takeaways from Microsoft Build 2026

🔍 This post summarizes three business-focused takeaways from Microsoft Build 2026 for leaders evaluating AI adoption. It explains how Microsoft is shifting from standalone models to a shared enterprise intelligence layer—Microsoft IQ—that connects business data and processes across systems. The article highlights Azure’s agent platform and Foundry updates for production-grade deployment, governance, and performance, emphasizing that AI is expected to deliver measurable outcomes now.
read more →

Looker Dashboard Agents Bring Conversational BI

🔍 Looker introduces dashboard agents in preview to enable conversational, in-dashboard exploration of BI data. The agent leverages the dashboard’s filters, cross-filters, and curated tiles to provide context-aware answers and can access underlying Explores for additional detail. Analysts can configure the agent with natural-language instructions to align responses with business logic, and the system surfaces intermediate reasoning, cited tiles, and applied filters to build user trust. Admins enable the feature in Looker 26.08.11+ via the Gemini settings.
read more →

Conditions SRE Teams Require Before Trusting AI

🔍 AI agents can help SRE teams with incident response, triage and automation, but trust is granted only when agents demonstrate reliability under real-world stress. Teams need robust observability, explicit guardrails, human-in-the-loop workflows and explainability so recommendations are evidence-backed rather than speculative. Progressive autonomy, post-incident evaluation and compatibility with existing tools are essential for safe adoption.
read more →

Practical defenses for unauthorized workplace AI

🛡️ This article outlines how enterprises can detect and block unauthorized AI tools—ranging from public chatbots like ChatGPT and Claude to meeting recorders and local model runners. It recommends monitoring NGFW/web-filter logs, EDR/EPP and MDM tools, browser policies, DNS reroutes, and application allowlists. The guidance covers detection indicators (domains, executables, SNI, calendar invites) and concrete lockdown steps (category blocks, policy toggles, OAuth restrictions). Emphasis is placed on offering approved alternatives and using layered controls rather than outright bans.
read more →

Anthropic’s Claude Fable 5 and Mythos 5 Launch

🛡️ Anthropic released Claude Fable 5 publicly on June 9, pairing it with a twin, Claude Mythos 5, that retains strong cybersecurity capabilities for vetted defenders. Fable 5 routes flagged cyber, bio, chemistry, and distillation requests to the weaker Opus 4.8 using safety classifiers, while Mythos 5 keeps those abilities available under trusted access. Both models are priced per input/output tokens and included on paid plans through June 22 before moving to usage credits.
read more →

Measuring the Business Value of Generative AI

🧭 The post explains how technology and finance leaders can demonstrate the business value of generative AI to secure funding and drive adoption. It highlights the DORA: ROI of AI-assisted software development report and its findings, including the common J-curve of early adoption, causes of temporary productivity decline, and the need to budget for a learning phase. The article also describes an interactive ROI calculator and resources to build a defensible AI investment case.
read more →

Widespread AI Coding Use Outpaces Governance

🛠️ Nearly all software teams now use AI coding assistants, yet fewer than a third have formal governance in place. A UserEvidence survey for Black Duck of 831 developers and DevOps pros in March 2026 found 97% adoption but only 30% with full oversight. Popular tools include GitHub Copilot (83%) and Claude Code (63%). Teams report faster releases and an average of eight hours saved per developer weekly, but many face downstream friction in reviews, testing and rework.
read more →

White House EO Aligns AI Policy with Cybersecurity

🔒 The White House Executive Order on advanced AI seeks practical public–private coordination to address AI-driven cyber risks while preserving innovation. It prioritizes voluntary model assessments, improved federal defenses, faster vulnerability discovery and remediation, and expanded cybersecurity talent. Successful implementation will hinge on operationalizing AI-assisted defense, translating insights into timely guidance and mitigations, and supporting resource-constrained critical infrastructure operators.
read more →

Amazon Connect adds AI agent trace visibility

🔍 Amazon Connect Customer now provides AI agent traces for self-service voice interactions, letting operators inspect how AI agents reasoned, acted, and responded during conversations. The feature displays step-by-step traces alongside full transcripts in the Connect web UI so teams can confirm correct behavior, diagnose failures, or spot tool and parameter issues. It is available in all AWS Regions that support Amazon Connect Customer AI Agents and is documented in the Amazon Connect Customer Administrator Guide.
read more →

Hands-on: Microsoft’s Intelligent Terminal for Windows

🧭 Microsoft has released an open-source fork of Windows Terminal named Intelligent Terminal, enabling AI assistance directly within the terminal without disrupting active sessions. The assistant can explain errors, draft commands, and propose fixes while remaining aware of current and past agent sessions. Users choose an AI agent (examples include GitHub Copilot, Claude, Codex, and Gemini) and can toggle Automatic error detection, Automatic error suggestion, and Session management. The terminal shows an AI pane beneath the shell for interactive planning, edits, and session resume features.
read more →