California's 2027 AI opt-out rule will push companies toward less transparent models
The ADMT Act's notice and opt-out requirements create a perverse incentive: opaque models are easier to claim are exempt than auditable ones.
191 free articles on AI governance and AI risk management: EU AI Act, NIST AI RMF, ISO 42001, incidents, deadlines and practical controls. New posts daily. Subscribe by RSS.
The ADMT Act's notice and opt-out requirements create a perverse incentive: opaque models are easier to claim are exempt than auditable ones.
Schools are now teaching students to spot chatbot errors, which is the same accountability gap that cost Air Canada in 2024 and that your support bot still has today.
Zero reported stories on environmental harm and robustness does not mean zero risk. It means the news is structurally blind to those failures.
What a recent fairness case reveals about AI risk management — the failure mode and the controls that contain it.
California's 2027 AI rules will push enterprises to hide internal failure reports, not improve them.
A family lost money to a deepfake impersonating an immigration attorney. The failure pattern is authorizing sensitive actions on one unverified channel.
Security researchers write about what is being exploited today. Governance teams write about what regulators will demand in 2027. The gap is not a lag, it is a misalignment.
A class action over recorded conversations highlights the gap between what AI transcription tools capture and what users actually consented to, and the same gap exists in your own systems.
Attackers are hiding instructions inside web pages, documents, and emails that AI agents read, and those hidden commands can make your system take actions it was never supposed to take.
The updated OWASP list highlights how LLM outputs that are not grounded in verified sources can lead to real-world harm, and what risk teams should do about it.
Canada's OSFI Guideline E-23 turns AI models into regulated models, but the specialized talent to validate them is scarce and about to get far more expensive.
A Michigan township warned residents about AI-generated robocalls impersonating officials and demanding property tax payments. The scam shows how cheap generative AI tools make impersonation fraud easy, and why governance teams need to treat synthetic media as a fraud vector, not just a content problem.
A drop in reported AI incidents looks like progress, but the data shows organizations are re-labeling failures as compliance issues to dodge liability.
The OWASP Top 10 for LLMs focused on vulnerabilities; the next wave of regulation and enforcement will focus on whether you can prove you managed the risk of AI outputs that are simply wrong.
Governance teams focus on privacy and fraud, but security teams track prompt crafting and evasion as the real threats.
A stolen API token let attackers hijack an AI assistant's identity, showing that identity controls, not just prompt filters, are the first line of defense.
The drop in reported governance incidents signals a shift to private legal channels ahead of enforceable deadlines.
The 2026 OWASP list shifts from prompt injection to agentic security, where the model's actions, not just its outputs, become the risk surface.
A security story worth a second look — and the AI governance moves it should prompt.
The 2026 OWASP Top 10 for LLM applications puts excessive agency at number one, replacing prompt injection as the biggest systemic risk, and it changes what your risk team should be monitoring.
The trade press that feeds AI incident databases is skewed toward legal and security stories, hiding overreliance and environmental harm from risk teams.
The poster sessions at the 2026 Berkeley RDI summit show where agentic AI research is heading, and why governance teams need to catch up before these systems reach production.
The EU AI Act's NCII/CSAM ban will force developers to over-filter, suppressing legitimate use cases and driving innovation offshore by 2027.
Behind the fairness news: the AI risk management gaps it exposes, and how to close them.