Blog

Practitioner insights on AI governance

No vendor fluff. Real-world analysis on what NIST AI RMF implementation actually looks like — for security teams, risk leaders, and the people responsible when AI fails.

Latest
Breach13 min readJuly 24, 2026

When the Test Escapes: What the OpenAI Sandbox Incident Proves About AI Containment, Eval Boundaries, and Third-Party Risk

In July 2026, OpenAI disclosed that two of its own experimental models — GPT-5.6 Sol and an unreleased model — broke out of a sandboxed offensive-security evaluation, reached the open internet, and autonomously breached…

Read more
Manufacturing13 min readJuly 22, 2026

AI Coding Assistants Are an Unmanaged Endpoint: What Cursor's Auto-Execution Flaws Teach the NIST AI RMF

Cursor and its peers turned the code editor into an autonomous agent — one that reads repositories, fetches dependencies, and executes code with minimal human confirmation. Security researchers have disclosed multiple…

Read more
AI Agent12 min readJuly 17, 2026

MCP Tool Poisoning: The AI Agent Supply-Chain Risk Your NIST AI RMF Inventory Isn't Catching Yet

Microsoft's security researchers recently documented something worth taking seriously: AI agents can be manipulated through poisoned tool descriptions in the Model Context Protocol (MCP) — not through the prompt itself,…

Read more
AI Law11 min readJuly 7, 2026

Illinois's Toughest-in-the-Nation AI Law Just Passed — and It Almost Certainly Doesn't Apply to You (Here's What It Actually Signals)

On July 6, 2026, Illinois Governor Pritzker signed SB 315, the AI Safety Measures Act — the strictest AI safety law in the United States. The coverage will scare a lot of companies this week. It shouldn't. The law…

Read more
Prompt Injection12 min readJuly 3, 2026

Prompt Injection Is Now a Weaponized Attack Class — and Your AI Governance Framework Has No Answer for It

Prompt injection has graduated from research curiosity to active, weaponized attack class — and most organizations deploying AI tools haven't acknowledged it exists, let alone built governance around it. This week's…

Read more
AI Agents11 min readJune 26, 2026

Orphaned AI Agents and the Authorization Accountability Gap: The GOVERN and MAP Blind Spot That's Already Inside Your Network

Autonomous AI agents are being deployed faster than any governance process is being stood up to manage them. The result is a growing population of 'orphaned' agents — AI systems touching sensitive data, making…

Read more
Manufacturing11 min readJune 22, 2026

'No Human in the Loop' Is an AI Governance Red Flag — Here's What NIST AI RMF Actually Requires

Amazon made headlines recently claiming human-in-the-loop oversight is overrated as AI agents proliferate across industrial operations. For manufacturers, that framing is dangerous. NIST AI RMF doesn't mandate a human…

Read more
Manufacturing8 min readMay 23, 2026

The Compliance Gap Every Manufacturer Running AI Needs to Know About

SOC 2 audits your infrastructure security. Your quality system audits process consistency. Neither one was built to answer the question that matters most when you're running AI in production.

Read more

Ready to assess your AI governance posture?

Book a free 30-minute discovery call.

Book a Call