Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

AI Governance

Denmark Sends Revised Public-Sector AI Authorization Law for Consultation

Denmark has returned to a difficult question in its plans for public-sector AI, sending a revised bill for consultation that would give public authorities a general legal basis to process personal data when developing and using AI systems.

Governing AI Between the Checkpoints

A few weeks ago, I wrote about a question that had followed me from a computer room in Milwaukee thirty years ago into today's conversations about agentic AI, "Where is the big red button?"

HelmGuard Raises $7.3 Million to Build Continuous Risk Assurance With AI Agents

HelmGuard has raised $7.3 million in seed funding to expand its AI-driven approach to governance, risk and compliance, as the company looks to replace some of the questionnaires and periodic document reviews that still underpin corporate risk assurance with agents capable of examining evidence directly.

When Seeing Is No Longer Believing: Deepfakes Are Becoming a Governance Problem

For a long time, seeing someone or hearing their voice gave us a reasonable level of confidence that we knew who we were dealing with. If your manager called, you recognized their voice. If a senior executive joined a video meeting, you could see them on the screen. There was usually little reason to question whether the person you were speaking to was actually who they claimed to be.

The “AI Employee” Is a Governance Failure Waiting to Happen

Corporate America has found a new way to signal its ambition: hiring software. Companies are giving artificial intelligence (AI) agents names, titles, and places on the organizational chart, and press releases celebrate the arrival of the “first AI employee” as though a person had walked through the door. According to MIT Technology Review’s James O’Donnell, nearly a third of the 1,261 managers surveyed in a recent Boston University study said their companies already frame AI agents as employees, and 23 percent list them on org charts.

South Korea Opens a New Route to Personal Data for AI Development

For South Korean AI developers, some useful data has come with an awkward choice. Get fresh consent from the people behind it, strip away enough identifying information to satisfy privacy requirements, or find another legal basis for using information that may have been collected for an entirely different reason. None is especially convenient when the object is to train an AI model on large and varied datasets.

Stop Treating AI Risk as an Assurance Silo

In a recent LinkedIn post, I asked why so many organizations are trying to assess AI as a standalone risk. I think that question gets to the heart of what is going wrong with much of the discussion around AI governance. There is no shortage of people trying to work out how organizations should govern AI. New frameworks are appearing, risk taxonomies are being built, internal audit teams are developing programs, and familiar questions are being asked about bias, security, compliance, privacy, and hallucinations.