by Gary Zimmerman | Jul 27, 2026 | AI, Governance
On July 16, 2026, Hugging Face detected a cyberattack powered by an autonomous AI agent. The intrusion was found by Hugging Face’s own AI. The attacker had accessed internal datasets and credentials. No passwords were stolen in the conventional sense. No malware was...
by Gary Zimmerman | Jul 20, 2026 | AI, Governance
Federal agencies have AI policies. Far fewer have AI evidence. That distinction separates organizations that can survive an audit, an OMB review, or a congressional inquiry from those that can only describe good intentions. For CISOs and technical architects, the...
by Gary Zimmerman | Jul 13, 2026 | AI, Governance
On June 16, 2026, the European Parliament adopted the Digital Omnibus on AI by 423 votes to 57. On June 29, the Council of the European Union formally adopted it, completing the co-legislative process. The headline that most compliance teams forwarded to their...
by Gary Zimmerman | Jul 7, 2026 | AI, Cybersecurity, Governance
On December 23, 2025, the FDA cleared a software medical device called UpDoc under 510(k) number K253281. The clearance got relatively little attention when it was issued. When UpDoc announced $18 million in seed financing on June 25, 2026 — alongside initial...
by Gary Zimmerman | Jun 29, 2026 | AI, Cybersecurity, Governance
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued SR 26-2 — the first rewrite of model risk management guidance since SR 11-7 in 2011. It superseded fifteen years of supervisory expectations. It clarified scope. It introduced a risk-based, proportional...
by Gary Zimmerman | Jun 22, 2026 | AI, Governance, Identity
The CISO role has always carried accountability that outpaced authority. What changed in 2026 is that the accountability became legally enforceable, personally, and the regulatory mechanisms to enforce it are no longer on the horizon. They are active. Splunk’s 2026...
by Gary Zimmerman | Jun 15, 2026 | AI, Cybersecurity, Identity
Your identity governance program almost certainly has a blind spot. It is not a configuration error or a policy gap. It is architectural. The IGA platforms most enterprises run were designed when “identity” meant a person. Joiner-mover-leaver workflows, access...
by Gary Zimmerman | Jun 8, 2026 | AI, Cybersecurity, Governance
Here is the problem with banning shadow AI: the people most likely to ignore the ban are your most senior decision-makers. According to TrustedTech’s Shadow AI in the Workplace report, published in May 2026, 65% of decision-makers use unapproved AI tools — compared...
by Gary Zimmerman | Jun 2, 2026 | AI, Cybersecurity, Identity
The question we keep getting from security architects right now is some version of the same thing: “We have a zero trust program. We have identity governance. We have PAM. Why does none of it cover our AI agents?” The honest answer is that it was never designed to....
by Gary Zimmerman | Mar 20, 2026 | AI, Cybersecurity, Governance
LLM red teaming, GenAI governance, EU AI Act timelines, and the AppSec integration most programs are missing. This week’s newsletter covers the AI security operational layer most programs haven’t built yet: how to test the LLMs already operating, how to govern GenAI...
Recent Comments