AI Governance

Dutch Privacy Regulator Draws GDPR Guardrails for Generative AI

The Dutch Data Protection Authority has published two documents on Monday. One provides GDPR guidance for developers of generative AI models. The other offers a practical checklist for organizations that want to purchase, implement and use the technology.

The Next Competitive Advantage in GRC Is No Longer Software

For much of the past twenty-five years, the GRC technology market rewarded providers for building broader platforms. New modules became competitive advantages. More configurable workflows became competitive advantages. Larger control libraries, deeper reporting, additional dashboards, more sophisticated risk quantification, and expanded third-party capabilities, with every release cycle promising another collection of features designed to distinguish one platform from another. Buyers responded in kind, and procurement teams assembled exhaustive requirements, while consultants developed detailed evaluation methodologies. Analysts compared products capability by capability until selection often resembled an exercise in accounting rather than strategy.

European Financial Regulators Back ESRB Warning on Frontier AI Cyber Risks

On Tuesday, Europe's three financial supervisory authorities publicly endorsed the European Systemic Risk Board's warning that frontier artificial intelligence models are creating systemic cyber risks for the financial sector, lending the combined authority of the continent's banking, insurance, and securities regulators to a concern that has been gathering force for months. Their message was not that artificial intelligence introduces a new category of risk. It was that the pace at which the technology is changing offensive cyber capabilities is beginning to test assumptions that were reasonable only yesterday.

FCA Says AI Will Fundamentally Reshape Retail Financial Services by 2030

Artificial intelligence is poised to become one of the defining forces in retail financial services over the next decade, according to a review published Monday by the UK's Financial Conduct Authority, which argues that regulators, industry and government must begin preparing now for a financial system increasingly shaped by autonomous AI.

Italian Competition Authority Investigates Microsoft Over Microsoft 365 AI-Linked Price Increase

The Italian Competition Authority has opened an investigation into Microsoft Ireland Operations and Microsoft, arguing that the company may have crossed that line when it increased the price of Microsoft 365 after incorporating its Copilot and Designer artificial intelligence services into the subscription.

From Static Checklists to Decision Systems: How AI Is Changing Compliance Work

Compliance is becoming too dynamic, evidence-heavy, and operationally connected to cybersecurity to be managed as a static documentation exercise. The opportunity for AI is not to replace governance judgment, but to help organizations turn evidence into defensible decisions faster.

The Future of Agentic AI Depends on Context

Recently, I asked buyers to inspect the machinery. This week, I am asking vendors to open the hood. The conversation about AI in GRC has reached a turning point. The market has heard the vision. It has seen the demos. It has absorbed the language of orchestration, agentic intelligence, autonomous assurance, and dynamic decision support. The frameworks have been published. The white papers have circulated. The analyst briefings have been given. The conference keynotes have landed.