Full disclosure before we start: I live on LinkedIn. Properly live there and I pay £90 odd quid in rent per month for the privilege. Some of you have probably been unfortunate enough to receive a unsolicited message from me. I'm sat at my laptop most of the day and it's on multiple tabs, and I read a lot of what gets posted there. Some of it, genuinely, is good. AI plus human output, clearly assisted by a model somewhere in the process, that had an actual point to make. I don't mind that in the slightest, I'm writing this newsletter with exactly that kind of help, mostly to stop myself swearing at you for eight paragraphs straight. I even used to read a few newsletters, clearly LLM-assisted, that spent most of their word count righteously furious at the evils of AI companies while quietly using AI to write the fury. Bit cheeky. I rather enjoyed the irony of it. Just call me Alanis, not the worst thing I've been called.

Then Article 50 landed on Monday and, funnily enough, I don't have quite as much to read anymore. Make of that what you will. I posted about it myself, twelve words, "nice to see lots of short posts out in the world today," ninety-nine impressions, extremely modest reach for a very pointed observation. If you're the slightly tin foil hat type like me, and I say that with genuine fondness for data privacy and the principle of knowing what you're looking at, this week was a small vindication.

AI Governance 2026: The Compliance Gamble Facing Every High-Risk AI Deployer
Are you building your EU AI Act compliance strategy on a foundation that was never designed for the purpose? With harmonized standards still in draft and the high-risk provisions approaching, organisations face a strategic gamble: bet on the standard arriving in time, or accept a double compliance burden. 80-90% of requirements are common across all pathways — but the remaining 10-20% carries material consequences. You’ll learn: • Why the EU AI Act QMS is fundamentally different from ISO 9001, 27001, or 42001 • What the four compliance pathways actually require — and their different burdens • Why ISO 42001 does not lead to EU AI Act compliance • How AI governance is being confused with AI management — and why it matters • A practical 90-day readiness plan from frontline practitioners • Why directors face personal, uninsurable liability for AI decisions Key topics: EU AI Act high-risk compliance • Quality Management Systems • PREN18286 • Harmonized standards • AI sovereignty • Shadow AI • Automation bias • Data integrity • AI literacy training • Director liability • Conformity assessment • Role-based competency Essential viewing for CISOs, CIOs, CFOs, Chief Legal Officers, and board members responsible for AI strategy, regulatory compliance, and risk management.

The EU AI Act's Article 50 rules are now live

Article 50 of the EU AI Act entered into force on 2 August, bringing new transparency obligations for anyone providing or deploying generative AI systems across the bloc. The headline requirement: people must be told when they're interacting with an AI system, unless it would already be self-evident to a sensible, attentive person paying reasonable attention to the context. Law enforcement systems used for detecting or investigating crime are exempt, provided third-party safeguards are in place.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

The week AI agents started freelancing in cybercrime

UK AISI's incident report is the one to read. Agents built fake online identities and used them to socially engineer a human GitHub maintainer into approving malicious code. Seventeen of the nineteen unsanctioned actions came from Anthropic's Mythos 5, two from OpenAI's GPT-5.6-Sol.

OpenAI, for its part, published its own account clarifying that its model reused an exposed GitHub token and set up a DNS server loaded with exploit payloads that, mercifully, didn't work. Then Meta turned up to the party, saying essentially "us too," attributing its own incident to the same evaluation-environment misconfiguration that Anthropic had already flagged, via the same third-party tester, Irregular. At this point Irregular ought to just publish the postmortem as a standing weekly column. Any Irregular reading this is more than welcome to get in touch, we will publish!

None of this happened in production. All of it happened because internet access and safety classifiers were deliberately switched off to stress-test capability. Fine. But it's the same pattern every time: permissive test conditions, an agent doing whatever it takes to hit its objective, and human vigilance being the only thing standing between "unsuccessful attempt" and something considerably worse. WPP's Daniel Hulme put it well on the Today programme: these models aren't being devious, they're just relentlessly goal-seeking in ways nobody fully anticipated. That's not comforting, it's just more precise.

Meanwhile, the Open Secure AI Alliance, now past 120 members including NVIDIA, Cisco, CrowdStrike and Hugging Face, used Black Hat Vegas to publish a Request for Comments on something called SAFE, a proposed framework for sharing AI incident findings across the industry before they become everyone's problem individually. Sensible. Overdue. We'll see if it has teeth.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

A word on the conversations behind the scenes

Between the news stories, I've had three interviews this week that deserve a mention here, partly because the content's genuinely good, partly because these people gave up their time for nothing more than a chat with me, and that's worth acknowledging properly rather than just mining it for content and moving on.

Sabarinathan "Sabri" Govindaraj, fraud leader with a run through Discover Financial Services, NetSpend and now Vanguard Investment Group, talked me through how synthetic identities actually get built. It's not some sophisticated fabrication exercise, it's a declined application, recycled and reapplied elsewhere, declined again, repeated until consortium data sharing starts treating the fabricated identity as real. The main defence is eCBSV, the Social Security Administration's verification service, currently catching around 80% of synthetic fraud with room to improve as data sharing gets better. He was straight with me that first-party fraud, the messier human disputes and verification work, still needs an actual person, which cuts against most vendor claims that AI replaces the lot. Thank you, Sabri, for the time given a packed schedule that day.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

Fabrizio Degni, AI & Data Governance Managers at Webuild , made the case that deterministic systems belong in critical infrastructure, dams, tunnels, metros, and generative AI, with its capacity for an unreliable result, does not, not where safety is non-negotiable. He was equally sharp on benchmarks, comparing them to an open-book exam where vendors publish only the results that flatter them. His closing line has stuck with me since: AI is the last mile, not the magic wizard at the beginning of anything. Thank you, Fabrizio, for such a considered and genuinely useful conversation.

And Elsa Sklavounou, creator of the Authority Instrumentation™ framework, alongside Njål Solland, creator of the REHT Protocol, gave me an 80 minutes on runtime governance for AI agents, the shift from asking what a model said to asking whether an agent's action was legitimate, admissible and provable before, during and after it happens. Given everything above about agents freelancing during testing, this conversation feels considerably more urgent than it did when we recorded it. Thank you both, Elsa and Njål, for such generous and sharp thinking.

All three conversations will be finding their way into fuller pieces and onto the BrightTalk channel shortly. Watch this space.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

Claude and the 30-year-old DNA problem

Sticking with the theme, Thermo Fisher has issued a high-severity bulletin (CVSS 8.2) after researchers found that DNA analysis files from its Applied Biosystems instruments, used in forensic labs since 1995, can be tampered with undetectably. The kicker, per the Wall Street Journal, is that a systems engineer used Claude to help write proof-of-concept code and had a working exploit inside 45 minutes. Files have been quietly falsifiable for three decades and it took an LLM lowering the barrier to entry for anyone to notice properly.

There are more than 200 forensic labs in the US running this software with no single national regulator overseeing security practices. Digital signatures are now rolling out as a fix, though anything end-of-life won't get one. I don't think this undermines DNA evidence generally, most convictions don't hinge on it alone, but defence lawyers already love picking at chain-of-custody arguments and this hands them a genuinely substantive one.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

AISI's viruses and everyone else's viruses

Unrelated but sitting uncomfortably close together this week, Stanford researchers used AI models called Evo1 and Evo2 to design 16 fully functional, replicating bacteriophage viruses from scratch, the first time a whole genome has been AI-designed. Genuinely significant science, potentially useful against antibiotic-resistant infections. Also, per Johns Hopkins biosecurity researchers writing in Science, genuinely alarming, because the same capability that designs a helpful phage doesn't stop at helpful. The Stanford team excluded anything capable of infecting complex organisms from training and worked exclusively in a secure lab on bacteria-only phages, which is the right call, but "we did the responsible version" doesn't un-invent the capability for everyone else.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

Open weights, open source, and the widening gap

Stanford HAI's James Landay is making the argument that open-weight models are not open source models. You can download the weights, you still can't see the training data, the code, or why the thing behaves the way it does. He wants alignment with the Linux Foundation's top "Open Science" tier as the actual bar. Worth reading in full if you're wading through the open-weight-versus-closed debate, which given China's Kimi K3 and Qwen3.8-Max are now closing the gap fast, you probably are.

The money and the hardware

OpenAI's Sarah Friar published a piece on what she's calling "abundant intelligence": GPT-5.6 Luna down 80% in price, Terra down 20%, plus efficiency gains that reportedly took GPT-5.6 Sol's ARC-AGI-3 score from 13.3% to 38.3% using six times fewer tokens. Whatever you think of the framing, the direction of travel, cheaper and faster intelligence, is going to keep reshaping what's commercially viable to automate.

OpenAI also published a genuinely interesting post on GPT-Live, its new full-duplex voice architecture that ditches the old "turn detector" approach entirely, apparently getting session startup down to a single UDP packet via a new protocol called WARP. If you build anything voice-adjacent, it's worth your time.

xAI shipped Imagine Video 1.5 updates, adding image and voice reference consistency and native 1080p, up to seven reference images per generation. And Mistral released Shieldstral, a 3B open-weights safety classifier that reportedly punches well above its size, notable mainly because it's part of the same Open Secure AI Alliance push mentioned above; everyone's suddenly very keen to be seen contributing to collective AI defence this week.

Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.

Salesforce goes to war, sort of

Salesforce announced Agentforce now has Impact Level 5 authorisation for the Department of War, with US Army HRC first through the door, deploying AI agents for 9.2 million soldiers, veterans and families. Big numbers in the press release, $6m in projected savings, 55 million projected monthly conversations at scale, all of it from Salesforce's own release and none of it independently verified. For that you would need a proper journalist, rather than a slowly reforming salesman.

And finally, Apple v OpenAI

OpenAI published a pointed rebuttal to Apple's trade secrets lawsuit, disputing Apple's timeline and defending two former Apple employees now working for OpenAI. It's OpenAI's own account of active litigation, so obviously one-sided, but the email screenshots showing Apple's outside counsel emailing the wrong person are a genuinely good bit of corporate pettiness to end the week on.

That's your lot. As ever, if any of this affects how you're thinking about AI governance, security or procurement in your own organisation, that's precisely what we cover on the AI-360 BrightTalk channel.


Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.
Share this post
The link has been copied!