BLOG
Shadow AI, compliance, spend and building a system of record for enterprise AI.
Frontier labs keep improving model alignment, yet enterprise AI governance keeps getting harder. A technical look at why governance lives in systems, not weights.
Mercor breached via compromised LiteLLM open-source project. AI supply chains are now attack vectors. How to detect tool tampering before it hits your org.
Delve accused of fabricating SOC 2 reports for 1,000+ customers. The $300M scandal proves checkbox compliance is dead. What real AI governance looks like.
IBM's 2025 report: shadow AI breaches cost $4.63M average — $670K more than standard incidents, with 20% of breaches involving shadow AI. The ROI math for governance. (IBM's 2026 edition has since raised both figures.)
OWASP published the MCP Top 10: tool poisoning, prompt injection, context spoofing, zero built-in auth. If your devs use AI coding tools, read this now.
Microsoft Purview, CrowdStrike Falcon AIDR, Cisco DefenseClaw — dozens of AI governance announcements at RSAC. We separate what ships from conference slides.
OpenClaw: 135K GitHub stars to security crisis in weeks. CVE-2026-25253, 341 malicious skills, 21K exposed instances. What your security team must do now.
Edge Purview DLP blocks AI prompts in real time. But Edge is 11% of desktop browsing (StatCounter, July 2026), and coding assistants, CLI tools and MCP servers never touch a browser at all. Full governance requires more.
Only 38% of organizations have a formal, comprehensive AI policy (ISACA 2026 AI Pulse Poll). Here's the template: three-tier classification, monitor-coach-enforce model, and EU AI Act alignment built in.
Auditors now ask which AI systems you run, and almost nobody can answer completely. Three discovery channels and a risk scoring framework for continuous AI inventory.
48% of security professionals rank agentic AI as 2026's top attack vector (Dark Reading reader poll, 2026). The 5-control framework to secure AI agents — before they become your biggest blind spot.
EU AI Act high-risk obligations land Aug 2. Here's the deployer checklist — mapped to concrete actions your security team can take this quarter.
EU AI Act hits Aug 2, California AI rules are live, SOC 2 added AI controls. The step-by-step checklist your security team needs — with deadline mapping.
The average organization logs 223 GenAI data policy violations a month (Netskope Cloud and Threat Report, 2026). Zero visibility. Learn why blocking fails and what actually works — the 3-pillar governance framework.
The enterprise ChatGPT invoice is not the number. Individual subscriptions, API spend inside engineering budgets and free tiers that quietly upgraded never reach it — see costs across 297 providers and 9,000+ models in one dashboard.
stop reading, start looking
A read-only workspace connection gives you the inventory these posts describe, for your organisation, in minutes.