What Federal AI Governance Actually Proves: ISO 42001, NIST AI RMF, and the Audit Evidence Gap
Federal agencies have AI policies. Far fewer have AI evidence. That distinction separates organizations that can survive an audit, an OMB review, or a congressional inquiry from those that can only describe good intentions. For CISOs and technical architects, the...
December 2027 Is Not That Far Away: The EU AI Act Deadline CISOs Cannot Afford to Misread
On June 16, 2026, the European Parliament adopted the Digital Omnibus on AI by 423 votes to 57. On June 29, the Council of the European Union formally adopted it, completing the co-legislative process. The headline that most compliance teams forwarded to their...
Clinical AI in the Gray Zone: Healthcare Governance When the FDA Hasn’t Cleared Your Tools
On December 23, 2025, the FDA cleared a software medical device called UpDoc under 510(k) number K253281. The clearance got relatively little attention when it was issued. When UpDoc announced $18 million in seed financing on June 25, 2026 — alongside initial...
The SR 26-2 Gap: AI Governance in Banking When the Framework Doesn’t Cover Your AI
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued SR 26-2 — the first rewrite of model risk management guidance since SR 11-7 in 2011. It superseded fifteen years of supervisory expectations. It clarified scope. It introduced a risk-based, proportional...
© 2025 All Rights Reserved
Recent Comments