Posts

Showing posts with the label Governance

AI Governance Has a Control Problem, Not a Policy Problem

Image
We’re getting good at writing policies about how AI should be used. Responsible AI principles. Acceptable-use policies. AI risk frameworks. Approval processes. Governance committees. All of these have a place. But there is a harder question that I think organisations need to start asking: What evidence proves those controls actually work? Because AI is changing the nature of the control problem. We are moving from AI that simply provides information to AI that can increasingly access data, make decisions, call tools, trigger workflows and take actions. And much of our traditional assurance thinking still assumes there is a human sitting somewhere in the process. That assumption is becoming increasingly uncomfortable.  Autonomy is scaling faster than assurance Consider a relatively simple AI agent. It might be able to: Read information from internal systems  Search documents and databases  Make decisions based on predefined criteria  Trigger workflows  Create or...

What the Anthropic Decision Reveals About the Future of AI Security

Image
The recent decision by the U.S. administration to lift restrictions on Anthropic’s frontier AI models has generated plenty of debate. Some have questioned whether the original restrictions were justified, while others argue they reflected legitimate concerns about the cybersecurity capabilities of increasingly powerful AI systems. Regardless of where you stand, I believe the real story lies elsewhere. This is one of the clearest examples yet of governments treating AI models as technologies with potential national security implications rather than simply another software product. That should make every cybersecurity leader take notice. AI Security Is Different For decades, cybersecurity has focused on protecting systems from attack. Today, we are entering an era where AI itself can influence the speed, scale and sophistication of those attacks. Modern frontier models can assist with code analysis, vulnerability discovery, malware understanding and offensive research. While t...