< ciso
brief />
Tag Banner

All news with #ai governance tag

404 articles · page 5 of 21

Why enterprises must deploy an AI agent kill switch

🛡️ Recent high-profile rogue agent incidents involving OpenAI and Anthropic show that organizations cannot assume AI guardrails are sufficient. Purpose Legal requires a kill switch for manual disablement, paired with monitoring, token limits, QA, and human oversight. Vendors often lack built-in kill switches, prompting calls for observability and controls as Congress considers requiring kill switches for AI platforms.
read more →

Cloudflare Codex for Enforcing Engineering Standards

🔎 Over four months, Cloudflare’s AI code reviewer flagged nearly 230,000 deviations from internal engineering standards and blocked almost 16,000 merges. The company consolidated dispersed guidance into the Cloudflare Codex, a governed RFC-based repository of SHOULD and MUST requirements that agents can consume across the engineering lifecycle. Codex-driven agents now review code, specs, and incident reports, improving consistency and surfacing issues earlier while leaving final judgment to engineers.
read more →

Black Hat 2026: AI-driven security products emerge

🛡️ Black Hat 2026 showcased a wave of AI-integrated security products that go beyond copilots to embed automation into operational workflows. Vendors emphasized attack path analysis, threat intelligence integration, and purpose-built AI agents to accelerate investigations while preserving existing infrastructure. Announcements included vulnerability remediation agents, AI observability, recovery validation, identity exposure intelligence, sovereign AI SOC agents, and expanded autonomous security platforms.
read more →

AI Agents Gain Access to Financial Workflows

🤖 Pathlock’s 2026 AI Governance Gap Report reveals many enterprises now give AI agents the ability to create records, execute workflows, and approve transactions across finance, procurement, HR, and supply chain systems. The survey found 79% of organizations lack a dedicated AI governance team and over half cannot fully verify AI-driven actions. Only 19% report complete, real-time visibility into agent activity, leaving tracing and investigation capabilities largely immature.
read more →

Sysadmin AI Expectations Fall Short by 2026

🔍 Action1 surveyed over 1,000 sysadmins worldwide to compare 2024 expectations of AI and automation against the state of adoption in 2026. The report finds substantial shortfalls in areas such as patch management, monitoring, vulnerability prioritization and incident remediation, with predicted full automation far exceeding current implementation. Adoption is, however, growing selectively: many admins use AI for analysis and recommendations under supervised models while retaining authority over critical decisions. Concerns remain around privacy, accuracy, cost and job impact.
read more →

Work versus Gym: A Simple Rule for Using AI

🧭 This essay discusses a practical rule for deciding when to use AI: treat tasks as either "work" (where only the outcome matters) or "gym" (where the process builds skills). The author, a public policy instructor, argues students should avoid AI for gym tasks like writing assignments because the struggle of composing develops critical thinking. Once AI is reliable and secure, it should handle work tasks, while humans preserve learning activities for skill retention.
read more →

Better Security Begins With Better Questions

🔒 Organizations moving beyond AI experimentation must combine intelligence with trust to secure innovation. Security should be an enabler that protects data, governs AI, and builds resilience by asking the right questions about risks, controls, and outcomes. Teams need systems thinking, layered defenses, and human oversight to validate AI outputs and make decisions under uncertainty.
read more →

Platform Engineering 2.0: Closing AI Security Gaps

🔐 Security teams built controls around human-driven code, but AI agents now operate autonomously, exposing new attack surfaces that developer-side tooling misses. The shift-left model fails for runtime threats like prompt injection, model poisoning, inference data leaks, and shadow AI sprawl. A platform-level response — Platform Engineering 2.0 — introduces model governance, prompt security, data isolation, and inference audit as mandatory control surfaces. CSOs must engage platform leadership to embed these controls and treat agent identities as first-class non-human identities.
read more →

Google Cloud Conversational Analytics Expanded in Q3

🗂️ Google Cloud has advanced Conversational Analytics from experiments into enterprise-ready offerings across BigQuery, Looker, and preview support for AlloyDB, Cloud SQL, and Spanner. The platform supports querying data across clouds, Lakehouse and Iceberg catalogs, and integrates into tools like BigQuery Studio, Looker, and Gemini Enterprise. Enterprises gain governance features such as CMEK, VPC, DRZ, and row- and column-level access controls, plus cost and observability tools via OpenTelemetry. Agentic Workflows, anomaly detection, and APIs/SDKs enable embedding conversational agents across applications and workflows.
read more →

Ensure AI Governance Survives Model Changes

🔒 Organizations must ensure governance stays consistent when AI models or providers change. Portable governance anchors controls to the use case—covering identity, permitted purpose, data boundaries, output/action limits, and evidence—so policy follows the activity across models. An AI Gateway or control plane helps observe and enforce requirements across tools, teams, and deployments.
read more →

Why AI safety certificates fail at runtime

🔒 Enterprises are treating AI safety as a static certification instead of a continuous runtime problem. On-paper model certifications like SOC 2 or ISO do not address the unpredictable behaviours that arise when models operate as autonomous agents with API access. The article highlights runtime risks—dynamic tool chaining, state-dependent cascades, and multi-agent feedback loops—and urges continuous monitoring, identity controls, and process-level firewalls to manage agentic threats.
read more →

CREST launches AI module for pentesting accreditation

🛡️ CREST has introduced optional AI-Enabled Penetration Testing requirements as an add-on to its existing Penetration Testing Accreditation Standard. Launched on July 28, the module lets providers that integrate AI undergo independent assessment to demonstrate responsible AI governance to clients and regulators. Applications are open to existing CREST members and accredited service providers seeking extra assurance for AI use.
read more →

Open Secure AI Alliance launches without OpenAI

🔒 The Open Secure AI Alliance, spearheaded by Nvidia and backed by more than 30 major AI vendors and users, aims to promote open-source defensive AI tools after an incident revealed limitations of closed commercial models. Hugging Face’s forensic work was blocked by safety guardrails on hosted models, forcing it to use an open-weight model on its own infrastructure. The alliance emphasizes that open models and harnesses democratize defense, increase transparency, and allow localized control. OpenAI has not commented on whether it will join the initiative.
read more →

Co-operative time‑slicing for RL to boost GPU use

🧭 This post introduces co-operative time-slicing from the llm-d project to reduce accelerator idle time during reinforcement learning (RL) post-training for large language models. By treating sampling and training steps as schedulable phases, the platform interleaves independent RL jobs on shared hardware, increasing aggregate GPU duty cycles from ~40% to 70% without harming convergence. The system uses a client library, a cluster orchestrator, and a node-level snapshot agent to checkpoint and restore device state, enabling fast context switches and improved price-performance for RL workloads.
read more →

AI agent identities create a new enterprise attack surface

🛡️ The Sophos AI Security 2026 Report warns that rapid enterprise adoption of AI tools has created a growing attack surface as AI agents and assistants gain privileged access to systems. Threat actors are targeting OAuth tokens, service credentials and exposed AI infrastructure because governance has not kept pace. The report urges treating AI agents like human users, enforcing least privilege, manual verification for new access and setting alerts for suspicious AI behavior.
read more →

MIT expands AI video surveillance across campus

🔍 MIT is deploying over 500 AI-equipped surveillance cameras across academic buildings, residence halls, and outdoor areas, a program costing more than $3 million and installing from November 2025 through September 2026. The cameras, largely Hanwha Wisenet AI models monitored with Ai-RGUS software, can classify faces and objects in real time and detect behaviors such as loitering and crowds, with data retained for up to 30 days unless exceptions apply. Technical specs include 2MP–4K resolution, PTZ capabilities, and classification up to 11 meters.
read more →

AI Adoption Shifts Expectations for Risk Management

🛡️ As AI becomes embedded across products, workflows, and supply chains, security leaders are being asked to enable faster, safer business decisions. Existing governance programs lag behind AI adoption, widening gaps in visibility and control. Fragmented risk views across security, procurement, privacy, and IT create blind spots that expand the blast radius when AI systems connect to enterprise data and workflows. CISOs must move from periodic risk review to continuous assurance and risk decisioning to prioritize what can move forward, what needs guardrails, and what must stop.
read more →

Senior executives driving shadow AI risk in enterprises

🔒 Senior leaders increasingly use unapproved AI tools despite clear security and privacy concerns, creating major headaches for CISOs and IT teams. TrustedTech’s survey found nearly two-thirds of senior decision-makers use shadow AI, often because sanctioned tools are slower or inadequate. Experts say this is a culture and usability problem rather than simple ignorance, and that governance must be modeled from the top while offering secure, usable alternatives.
read more →

Accelerating foundation model upgrades for teams

🔎 Upgrading foundation models is slow and costly for engineering teams, often requiring months of manual testing and evaluation. Google Cloud Applied ML built an agentic workflow that reduces migration time from months to hours using the Gemini Enterprise Agent Platform and Google Antigravity. The blog outlines three lessons and practical steps—deploying Autoraters, building an agentic loop, and automating orchestration—to replace manual toil with intelligent automation.
read more →

Regulating Corporate Responsibility for AI Privacy

🛡️ Daniel Solove argues in the Wall Street Journal that individual control over personal data is insufficient to protect privacy in the AI era. He urges shifting regulatory focus to hold companies accountable—similar to food and drug oversight—through measures like data minimization, fiduciary duties, and liability for negligent design. Solove also recommends liability for harmful algorithms and multi-stakeholder review of technologies to ensure safer outcomes.
read more →