·1090 words·6 mins
The Council named future technology and AI innovation in its request for comments. Here’s how the RFC process works and what happens next.
·1162 words·6 mins
Anthropic disabled two frontier models worldwide to comply with an export directive. The practitioner takeaways on dual-use AI and availability risk.
·1182 words·6 mins
The first publicly available Mythos-class model. A look at capability gating, the two-tier release model, and what it signals for defenders.
·1677 words·8 mins
What Careful Adoption of Agentic AI Services means for non-human identity, privilege design, and compliance programs that haven’t caught up.
·1054 words·5 mins
Reduced offensive capability, automated request blocking, and a verification path for legitimate practitioners. What it changes for security work.
·1453 words·7 mins
PCI DSS v4.x wasn’t written with AI in mind. Here’s where the framework holds up, where there’s room to grow, and how the Council is engaging.
·1730 words·9 mins
AI agents call APIs, execute code, and make decisions with real consequences. The OWASP Agentic Top 10 is the first framework for that attack surface.
·2803 words·14 mins
A follow-up on OpenClaw’s remediation, what actually improved, and the questions raised when Peter Steinberger joined OpenAI.
·2138 words·11 mins
OpenClaw is a case study in how fast AI agent deployment outran the governance meant to contain it. The vulnerabilities and what they teach.