AI Governance
What a system is allowed to own, who approved it, and what evidence exists afterwards.
11 pieces
The Token Tax
The Hidden Cost of Giving AI the Wrong Responsibility
AUG 24, 2026
You Are Deploying AI Faster Than You Can Prove What It Did
Companies describe agentic AI as a capability in their marketing and as an exposure in their SEC filings. The filings are the more informative document.
JUL 9, 2026
$25 Million. One Real Person on the Call.
A finance worker checked the request, joined a video conference, recognized his colleagues and approved the transfers. The colleagues were generated.
JUN 18, 2026
You Use 2 Percent of Your Access. Your Agent Will Use All of It.
The permissions nobody exercises were harmless while only people held them.
JUN 4, 2026
A Chatbot's Token Opened 700 Companies.
Nobody was phished. The attacker used a credential that belonged to an AI integration, and most organizations cannot revoke one.
MAY 21, 2026
One Email. No Click. Your Files.
A critical vulnerability in Microsoft 365 Copilot needed no user interaction at all. The model was working correctly.
MAY 7, 2026
The Exam Has Errors. The Grader Changes Its Mind.
Every AI decision you have approved rests on an evaluation. Three findings say the evaluation is shakier than the model.
APR 23, 2026
One Thousand Identical Questions. Eighty Different Answers.
Temperature zero exists to make a model repeatable. It does not, and the reason is not randomness.
APR 9, 2026
23.8 Million Secrets. Most of Them Still Work.
A leaked credential is not an incident. It is a condition, and the assistant writing your code makes more of them.
FEB 12, 2026
$670,000 for the Tools You Did Not Buy.
One in five breaches now involves AI nobody approved. The account is the problem, not the model.
JAN 29, 2026
The Scanner Flagged It. The Download Worked.
Around 100 models on a public hub carried live payloads. Loading one opened a shell on the machine that loaded it.
JAN 15, 2026