·970 words·5 mins
What the new mapping actually buys you, where teams misread it as control equivalence, and how much rework that mistake creates.
·1090 words·6 mins
The Council named future technology and AI innovation in its request for comments. Here’s how the RFC process works and what happens next.
·1162 words·6 mins
Anthropic disabled two frontier models worldwide to comply with an export directive. The practitioner takeaways on dual-use AI and availability risk.
·1677 words·8 mins
What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven’t caught up.
·1872 words·9 mins
Two weeks after writing about the structural problems with compliance platforms, the allegations landed. What assessors already knew.
·1414 words·7 mins
A reality check on compliance automation platforms, the gap between generated evidence and assessed controls, and the questions to ask.