by Gary Zimmerman | Jul 27, 2026 | AI, Governance
On July 16, 2026, Hugging Face detected a cyberattack powered by an autonomous AI agent. The intrusion was found by Hugging Face’s own AI. The attacker had accessed internal datasets and credentials. No passwords were stolen in the conventional sense. No malware was...
by Gary Zimmerman | Jul 20, 2026 | AI, Governance
Federal agencies have AI policies. Far fewer have AI evidence. That distinction separates organizations that can survive an audit, an OMB review, or a congressional inquiry from those that can only describe good intentions. For CISOs and technical architects, the...
by Gary Zimmerman | Jul 13, 2026 | AI, Governance
On June 16, 2026, the European Parliament adopted the Digital Omnibus on AI by 423 votes to 57. On June 29, the Council of the European Union formally adopted it, completing the co-legislative process. The headline that most compliance teams forwarded to their...
by Gary Zimmerman | Jul 7, 2026 | AI, Cybersecurity, Governance
On December 23, 2025, the FDA cleared a software medical device called UpDoc under 510(k) number K253281. The clearance got relatively little attention when it was issued. When UpDoc announced $18 million in seed financing on June 25, 2026 — alongside initial...
by Gary Zimmerman | Jun 29, 2026 | AI, Cybersecurity, Governance
On April 17, 2026, the Federal Reserve, OCC, and FDIC issued SR 26-2 — the first rewrite of model risk management guidance since SR 11-7 in 2011. It superseded fifteen years of supervisory expectations. It clarified scope. It introduced a risk-based, proportional...
by Gary Zimmerman | Jun 22, 2026 | AI, Governance, Identity
The CISO role has always carried accountability that outpaced authority. What changed in 2026 is that the accountability became legally enforceable, personally, and the regulatory mechanisms to enforce it are no longer on the horizon. They are active. Splunk’s 2026...
by Gary Zimmerman | Jun 8, 2026 | AI, Cybersecurity, Governance
Here is the problem with banning shadow AI: the people most likely to ignore the ban are your most senior decision-makers. According to TrustedTech’s Shadow AI in the Workplace report, published in May 2026, 65% of decision-makers use unapproved AI tools — compared...
by Gary Zimmerman | Apr 10, 2026 | Cybersecurity, Governance, Identity
Most M&A teams move fast on financial, legal, and operational due diligence—but overlook one of the biggest post-close failure points: identity. When you buy a company, you are also acquiring every account, role, entitlement, and backdoor they have in place. Yet...
by Gary Zimmerman | Apr 3, 2026 | Cybersecurity, Governance
Two CISOs. Same security program. Same budget. Same risk posture. One walks out of the board meeting with full investment approval and a standing agenda slot. The other spends 45 minutes defending patch completion rates to a CFO who wanted to talk about AI risk. The...
by Gary Zimmerman | Mar 20, 2026 | AI, Cybersecurity, Governance
LLM red teaming, GenAI governance, EU AI Act timelines, and the AppSec integration most programs are missing. This week’s newsletter covers the AI security operational layer most programs haven’t built yet: how to test the LLMs already operating, how to govern GenAI...
Recent Comments